EU Regulation Active

EU Cybersecurity Act

The EU regulation establishing ENISA's permanent mandate and the European cybersecurity certification framework for ICT products, services, and processes.

Quick Facts

Status
In Force
Type
EU Regulation
Scope
ICT Certification
Effective
2019
Agency
ENISA

Overview

The EU Cybersecurity Act (Regulation 2019/881) strengthens the role of ENISA as the European Union Agency for Cybersecurity and creates a comprehensive, pan-European cybersecurity certification framework. The regulation provides a structured approach to evaluating the security of ICT products, services, and processes across the single market.

The EUCC (European Common Criteria-based) scheme is the first certification scheme adopted under the framework, enabling the certification of ICT products against internationally recognized security standards. For PKI, this means certification of CA software, hardware security modules (HSMs), and trust services becomes a tangible requirement for high-assurance environments.

Organizations can demonstrate their security posture through certified infrastructure, gaining a competitive advantage in procurement processes and building trust with partners and customers across the EU. The framework also supports sector-specific schemes for cloud, 5G, and other critical technologies.

Key Requirements

ENISA Certification Framework

ENISA oversees the development and maintenance of a pan-European cybersecurity certification framework, ensuring consistent security evaluation across member states.

EUCC Scheme (Common Criteria)

The European Common Criteria-based certification scheme evaluates ICT products against internationally recognized security standards, including CA software and HSMs.

Security Certification Levels

Three assurance levels — Basic, Substantial, and High — define the depth of security evaluation required depending on the risk profile and intended use of ICT products.

Conformity Self-Assessment

For Basic assurance level, manufacturers can perform self-assessments under the framework, reducing costs while maintaining accountability for security claims.

National Certification Authorities

Each member state designates national cybersecurity certification authorities responsible for supervising and enforcing certification schemes within their jurisdiction.

Mutual Recognition Across EU

Cybersecurity certificates issued under EU schemes are recognized in all member states, eliminating the need for repeated certifications and facilitating cross-border trade.

Key Milestones

17
2017

Proposed

The European Commission proposes the Cybersecurity Act to strengthen ENISA and establish an EU-wide cybersecurity certification framework.

19
2019

Entered into force

Regulation (EU) 2019/881 enters into force in June 2019, granting ENISA a permanent mandate and laying the groundwork for certification schemes.

20
2020

ENISA permanent mandate

ENISA assumes its expanded, permanent role as the EU Agency for Cybersecurity with enhanced operational capacity.

24
2024

EUCC scheme adopted

The European Common Criteria-based cybersecurity certification scheme (EUCC) is formally adopted for ICT products.

25
2025 Current

Sector-specific schemes

Development and adoption of sector-specific certification schemes for cloud services, 5G networks, and other critical technologies.

Impact on PKI & Certificates

The EU Cybersecurity Act has significant implications for PKI infrastructure, particularly through the EUCC certification scheme. Organizations relying on digital certificates must consider the following areas:

1

CA Software & HSM Certification

Certificate Authority software and hardware security modules can be certified under the EUCC scheme, providing formal assurance of their security properties for high-trust environments.

2

Certified PKI for High-Assurance Use Cases

Organizations in critical sectors increasingly require certified PKI components to meet procurement standards and demonstrate security posture to regulators and partners.

3

Certification Posture Maintenance

Maintaining certified status requires ongoing certificate lifecycle management — tracking validity, ensuring timely renewals, and documenting compliance continuously.

4

Trust Service Certification Alignment

PKI-based trust services must align their infrastructure with EU certification expectations, ensuring that underlying components meet the required assurance levels.

How we help

Evertrust & EU Cybersecurity Act

ANSSI-certified PKI aligned with EUCC — Stream's ANSSI-certified PKI infrastructure aligns with EUCC expectations, providing a foundation of formally evaluated security for your trust services.

Certification status tracking — Horizon tracks the certification status of all PKI components across your infrastructure, ensuring you maintain visibility over your certified assets.

Policy enforcement for certified configurations — Enforce certificate policies that ensure only certified algorithms, key sizes, and configurations are used across your infrastructure.

Audit trails for certification maintenance — Generate comprehensive audit trails and compliance reports that support ongoing certification assessments and renewals.