Skip to content
Nenkin

EUCC at 30 certifications: a year-one check-in

EUCC, the EU’s Common Criteria-based cybersecurity certification scheme, just crossed 30 published certificates. That milestone is worth pausing on. EUCC is the first scheme adopted under the EU Cybersecurity Act framework, and it represents the most ambitious attempt in years to coordinate Common Criteria certification across the Union under a single regulatory umbrella.

The first EUCC certificates could be delivered from 27 February 2025, when Member States, through their National Cybersecurity Certification Authorities (NCCAs), gained the operational mandate to issue. Just over fifteen months later, the public ENISA registry lists 30 published certificates. Congratulations to the scheme bodies, the labs, the conformity assessment bodies, and the vendors that got it to that mark.

What 30 certificates says about scheme maturity

Thirty certificates in fifteen months is a respectable pace for a new CC scheme. New national CC schemes have historically taken years to move from regulatory approval to a steady issuance cadence; the EUCC’s combination of an existing Common Criteria methodology, a pan-EU mandate, and Member State certification bodies that were already accredited under SOG-IS gave it a faster runway than a green-field scheme would have had.

The pace also matters as a credibility signal. Procurement teams, integrators, and security-policy authors all need to know whether a new certification framework is going to become a real publishing surface or a regulatory framework that ends up sitting unused. Thirty certificates is enough to say the framework is being used. Not yet enough to say it has displaced the existing schemes, but enough that downstream policy decisions (EU Cyber Resilience Act references, sector-specific procurement guidelines, vertical accreditation programmes) can start to lean on it.

The CAB landscape

Certificates have been issued by multiple conformity assessment bodies (CABs) operating across several Member States. That distribution matters because it confirms that EUCC is operating as designed: a pan-EU scheme run by national authorities, not a single body issuing in the name of the Union. Each CAB is accredited in its home Member State, supervised by that state’s NCCA, and free to compete on its own merits within the EUCC framework. Different vendors choose different CABs for reasons of geography, language, sector expertise, and existing relationships.

The variety also matters as a resilience story. A scheme that depends on a single CAB issuing everything is fragile. A scheme that has several CABs producing certificates, each operating under independent national oversight, can keep functioning if one of them pauses, restructures, or is taken offline for accreditation review.

What is being certified

Most early EUCC certifications fall into the categories that the wider Common Criteria community has been certifying for years: smart cards, secure microcontrollers, embedded platforms, and the toolchains that sit around them. That is exactly what one would expect from a scheme that inherits its lab and CAB base from the SOG-IS era: the bodies that were already accredited for smart-card and platform evaluations were the first to bring their accreditation across to the EUCC framework.

The interesting thing is what is starting to appear alongside those traditional categories. Recent EUCC entries include IoT-class systems certified at lower assurance levels, and a small but growing share of certificates from product categories that have not historically been a CC mainstay. EUCC is not category-bound: it supports the full EAL1 to EAL7 range and accepts product classes outside the traditional CC smart-card corpus. The presence of those non-traditional entries in the first 30 certificates is a signal that the scheme is being tested across the breadth of its remit, not just at its smart-card sweet spot.

The Common Criteria standard underneath

EUCC certificates issued from 2026 onward are largely based on CC:2022 Release 1 with the Common Evaluation Methodology CEM:2022. That is the current Common Criteria standard, and it matters that EUCC is using it. Schemes that lag the standard make it harder for vendors to plan multi-scheme certifications and for regulators to write down requirements that apply across schemes. EUCC adopting the current CC version from the start aligns it with the international corpus and reduces friction for vendors that want to certify the same product under multiple frameworks.

What it means for the wider CC ecosystem

The bigger point: EUCC is the first concrete deliverable of the EU Cybersecurity Act’s certification framework. The framework is intended to host other schemes too (cloud services, 5G network components, EU Digital Identity Wallets, eventually IoT) under a common regulatory umbrella. Whether those other schemes succeed depends partly on whether EUCC can demonstrate that the framework actually works in practice. Thirty certificates is the first real evidence that it does.

There is, of course, still work to do. Publishing practice across CC schemes still needs better coordination, which is the subject of a companion post on the silent EUCC portal reformat. The Substantial and High assurance labels are still being absorbed by procurement teams who have spent twenty years thinking in EAL packages. Cross-recognition with CCRA national schemes is still being worked out by individual Member States. None of that is settled at 30 certificates. But none of it could be settled at zero certificates either, and 30 is a meaningful start.

Congratulations to everyone who got it here. The next 30 will likely come faster.

How NenkinTracker tracks EUCC

NenkinTracker indexes the full EUCC corpus under the EUCC scheme view. Every certificate is browsable with its CAB, issuance year, assurance level, Protection Profile claim (or lack of one), and the three core documents (the Certificate PDF, the Security Target, and the Certification Report). Direct links from each cert detail page lead back to the canonical ENISA registry entries.

See also

Frequently asked questions

When did EUCC start issuing certificates?
EUCC certificates could be delivered from 27 February 2025, when Member States gained the operational mandate to issue through their National Cybersecurity Certification Authorities (NCCAs). The scheme had been adopted by the European Commission earlier under Implementing Regulation 2024/482; February 2025 was when the first certificates could appear on the ENISA registry.
How many EUCC certificates have been issued?
As of May 2026, the public ENISA EUCC registry lists 30 published certificates. The pace has been steady through the first fifteen months of operation, with a noticeable acceleration in early 2026.
Who issues EUCC certificates?
EUCC certificates are issued by accredited conformity assessment bodies (CABs) operating in EU Member States, under the supervision of each Member State's National Cybersecurity Certification Authority (NCCA). Multiple CABs are currently operating across several Member States, each with its own numeric issuing-body code on the certificates.
What kinds of products are being certified under EUCC?
The first 30 certifications span the categories that the wider Common Criteria community has long worked with (smart cards, secure microcontrollers, embedded platforms) and are beginning to include broader product classes such as IoT-class systems. EUCC supports the full EAL1 to EAL7 assurance range and is not restricted to any single product category.
How does EUCC's pace compare to other CC schemes?
Thirty certificates in fifteen months is a respectable pace for a new CC scheme. New national CC schemes have historically taken years to move from regulatory approval to steady issuance cadence; EUCC's faster runway reflects its inheritance from existing SOG-IS accredited labs and CABs that were able to transition their accreditation into the new framework.
Is EUCC replacing the CCRA?
No, not in the near term. EUCC and CCRA exist alongside each other. EUCC operates under EU regulatory authority for EU Member States; CCRA continues as the international mutual-recognition arrangement. Some Member States may eventually transition more of their domestic certification activity to EUCC, but the two frameworks are designed to coexist for the foreseeable future.