Cybersecurity Act

← All instruments
in forcehorizontal
Type
regulation
Layer
horizontal
Status
in force
In force
2019-06-27
Key date
revision proposed 2026-01-20
Last verified
2026-07-16

Cybersecurity Act — ENISA + the EU certification framework

Regulation (EU) 2019/881. Two jobs in one act: it gave ENISA a permanent mandate and it created the European Cybersecurity Certification Framework (ECCF) — a way to certify ICT products, services and processes once for the whole single market. A full revision (“CSA2”) was proposed on 20 January 2026 (see 20-proposals/).

Part 1 — ENISA (the EU Agency for Cybersecurity)

Made permanent and expanded. ENISA:

  • supports policy development and implementation (NIS2, CRA, DORA and more);
  • runs operational cooperation — secretariat of the CSIRTs Network, support to EU-CyCLONe, help to states during large-scale cross-border incidents;
  • builds capacity, awareness, research support, and market/certification work;
  • acts as scheme manager for the certification framework.

Part 2 — European Cybersecurity Certification Framework (ECCF)

A single legal basis for EU-wide voluntary certification schemes, each defining assurance levels:

  • basic — low risk (largely self-assessment);
  • substantial — known risks/incidents;
  • high — state-of-the-art resistance to sophisticated attacks.

A certificate issued under a scheme is recognised across all Member States, replacing the patchwork of national certifications.

Schemes adopted / in progress

  • EUCC — for ICT products (based on Common Criteria). Adopted via Implementing Reg. (EU) 2024/482; the first operational EU scheme (applies from Feb 2025).
  • EUCS — for cloud services (draft; sovereignty requirements were the main sticking point). ⚠️ VERIFY current status.
  • EU5G — for 5G networks/products (draft). ⚠️ VERIFY current status.
  • Managed security services — the 15 January 2025 amendment (Reg. 2025/37) added a legal basis for schemes covering incident response, penetration testing, security audits and consultancy.

Governance

ENISA prepares candidate schemes at the Commission’s request; the European Cybersecurity Certification Group (ECCG) (national authorities) and a Stakeholder Certification Group advise. National Cybersecurity Certification Authorities supervise and, for lower levels, conformity-assessment bodies issue certificates.

Why it matters even though it’s voluntary

  • NIS2 Art. 24 lets Member States require regulated entities to use certified ICT products/services.
  • CRA can mandate EU certification for its “critical” product class (Annex IV).
  • The CSA2 proposal would make certification a horizontal compliance tool (“cyber posture certification”) giving NIS2 entities a presumption of conformity.

The 2026 revision (CSA2) in one line

Proposed 20 Jan 2026: stronger ENISA mandate, a reformed/faster ECCF (candidate schemes within ~12 months), new ICT supply-chain security rules (high-risk supplier designation), and certification as cross-cutting proof of compliance. Full detail: 20-proposals/cybersecurity-act-2.md.

Sources