Cybersecurity Act
Cybersecurity Act — ENISA + the EU certification framework
Regulation (EU) 2019/881. Two jobs in one act: it gave ENISA a permanent mandate
and it created the European Cybersecurity Certification Framework (ECCF) — a way to
certify ICT products, services and processes once for the whole single market. A full
revision (“CSA2”) was proposed on 20 January 2026 (see 20-proposals/).
Part 1 — ENISA (the EU Agency for Cybersecurity)
Made permanent and expanded. ENISA:
- supports policy development and implementation (NIS2, CRA, DORA and more);
- runs operational cooperation — secretariat of the CSIRTs Network, support to EU-CyCLONe, help to states during large-scale cross-border incidents;
- builds capacity, awareness, research support, and market/certification work;
- acts as scheme manager for the certification framework.
Part 2 — European Cybersecurity Certification Framework (ECCF)
A single legal basis for EU-wide voluntary certification schemes, each defining assurance levels:
- basic — low risk (largely self-assessment);
- substantial — known risks/incidents;
- high — state-of-the-art resistance to sophisticated attacks.
A certificate issued under a scheme is recognised across all Member States, replacing the patchwork of national certifications.
Schemes adopted / in progress
- EUCC — for ICT products (based on Common Criteria). Adopted via Implementing Reg. (EU) 2024/482; the first operational EU scheme (applies from Feb 2025).
- EUCS — for cloud services (draft; sovereignty requirements were the main sticking point). ⚠️ VERIFY current status.
- EU5G — for 5G networks/products (draft). ⚠️ VERIFY current status.
- Managed security services — the 15 January 2025 amendment (Reg. 2025/37) added a legal basis for schemes covering incident response, penetration testing, security audits and consultancy.
Governance
ENISA prepares candidate schemes at the Commission’s request; the European Cybersecurity Certification Group (ECCG) (national authorities) and a Stakeholder Certification Group advise. National Cybersecurity Certification Authorities supervise and, for lower levels, conformity-assessment bodies issue certificates.
Why it matters even though it’s voluntary
- NIS2 Art. 24 lets Member States require regulated entities to use certified ICT products/services.
- CRA can mandate EU certification for its “critical” product class (Annex IV).
- The CSA2 proposal would make certification a horizontal compliance tool (“cyber posture certification”) giving NIS2 entities a presumption of conformity.
The 2026 revision (CSA2) in one line
Proposed 20 Jan 2026: stronger ENISA mandate, a reformed/faster ECCF (candidate schemes
within ~12 months), new ICT supply-chain security rules (high-risk supplier
designation), and certification as cross-cutting proof of compliance. Full detail:
20-proposals/cybersecurity-act-2.md.
Sources
- Text: https://eur-lex.europa.eu/eli/reg/2019/881/oj
- ENISA certification: https://certification.enisa.europa.eu
- EUCC Impl. Reg. 2024/482: https://eur-lex.europa.eu/eli/reg_impl/2024/482/oj
- Commission Cybersecurity Act page: https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act