Regulations & Standards

Compliance
Center

Benefit from a curated overview of PKI-relevant EU and global frameworks.

In Force

eIDAS 2.0

EU Regulation

The European framework for electronic identification and trust services, establishing standards for digital signatures, seals, timestamps, and website authentication certificates.

Digital Identity Trust Services Qualified Certificates
In Force

GDPR

EU Regulation

The General Data Protection Regulation mandates robust data protection measures, where PKI and certificate management play a critical role in ensuring encrypted communications and data integrity.

Data Protection Privacy Encryption
In Force

DORA

EU Regulation

The Digital Operational Resilience Act sets requirements for ICT risk management in the financial sector, including cryptographic key management and certificate governance.

Financial Services ICT Risk Operational Resilience
Upcoming

Cyber Resilience Act

EU Regulation

New horizontal cybersecurity requirements for products with digital elements, imposing secure-by-design obligations including certificate and cryptographic material management.

Product Security IoT Software Supply Chain
In Force

EU Cybersecurity Act

EU Regulation

Establishes the ENISA cybersecurity certification framework for ICT products, services, and processes. Supports certification posture management and compliance with EUCC schemes.

ENISA Certification Framework EUCC
In Force

NIS2 Directive

EU Directive

Strengthened cybersecurity obligations for essential and important entities across the EU, with expanded scope covering certificate management and PKI infrastructure.

Cybersecurity Critical Infrastructure Risk Management
In Force

PSD2

EU Directive

The Payment Services Directive mandates QWACs and Qualified Seals for payment service providers and TPPs, requiring robust PKI for secure open banking APIs.

Open Banking QWACs Payment Services
In Force

CER Directive

EU Directive

The Critical Entities Resilience Directive complements NIS2 for physical and cyber resilience of critical entities, requiring certificate-based access control for critical infrastructure.

Critical Entities Resilience Access Control
Upcoming

EU Digital Identity Wallet

EU Framework

The EUDI Wallet framework extends eIDAS 2.0, creating massive PKI demand for wallet credential issuance at scale — from qualified electronic attestations to person identification data.

Digital Identity Wallet Verifiable Credentials
In Force

RGS

National Regulation

The Referentiel General de Securite defines security requirements for French public administration information systems, mandating ANSSI-accredited certificates for government services.

France ANSSI Public Administration
In Force

LPM

National Regulation

The Loi de Programmation Militaire imposes strict security obligations on Operators of Vital Importance (OIV), including cryptographic controls and certificate management for critical national infrastructure.

France OIV National Defense
In Force

IT-Sicherheitsgesetz / BSI

National Regulation

Germany's IT Security Act and BSI standards require KRITIS operators to implement robust cryptographic controls. BSI TR-03145 governs CA operations and certificate management.

Germany BSI KRITIS
In Force

ENS

National Regulation

Spain's Esquema Nacional de Seguridad establishes digital certificate requirements for e-government services, mandating certificate inventory and lifecycle management at Medium and High assurance levels.

Spain E-Government Security Framework
In Force

Perimetro di Sicurezza Nazionale Cibernetica

National Regulation

Italy's National Cybersecurity Perimeter mandates PKI-based access control and certificate-based authentication for strategic organizations operating within the national cyber perimeter.

Italy Cyber Perimeter Strategic Infrastructure
In Force

ISO 27001:2022

International Standard

The gold standard for information security management systems, with specific controls for cryptographic key management and certificate governance across organizations.

ISMS Risk Assessment Cryptographic Controls
In Force

ISO/IEC 27099

International Standard

The dedicated PKI certificate lifecycle management standard, directly mapping to discovery, governance, and automation workflows for certificate operations.

PKI Lifecycle Certificate Management Governance
In Force

PCI DSS v4.0

Industry Standard

Payment Card Industry Data Security Standard requires strict certificate lifecycle management for securing cardholder data environments and encrypted communications.

Payment Security TLS/SSL Key Management
In Force

SOC 2 Type II

Industry Standard

Service Organization Control audit framework requiring demonstrable key lifecycle management, certificate rotation policies, HSM usage, and comprehensive audit logging.

Audit Key Rotation Trust Services Criteria
In Force

ETSI EN 319 Standards

Technical Standard

European standards (EN 319 401, 411, 412) defining general policy and security requirements for Trust Service Providers, governing PKI operations, qualified certificate issuance, and TSP compliance.

Trust Services Qualified Certificates TSP Requirements
Why it matters

PKI is at the heart of
every compliance framework

From encrypting sensitive data to authenticating digital identities, certificates are the foundational layer that enables regulatory compliance. As regulations multiply and tighten, managing your PKI infrastructure becomes a strategic imperative — not just a technical task.

47
days — new maximum TLS certificate lifespan by 2029
€10M+
potential fines under NIS2 for non‑compliance
160k+
entities newly in scope under NIS2 across the EU
100%
of these frameworks require robust certificate management

Need help navigating compliance?

Our team of PKI and compliance experts can help you understand regulatory requirements and implement the right certificate management strategy.

Get in touch