EUCC at 30 certifications: a year-one check-in
EUCC, the EU’s Common Criteria-based cybersecurity certification scheme, just crossed 30 published certificates. That milestone is worth pausing on. EUCC is the first scheme adopted under the EU Cybersecurity Act framework, and it represents the most ambitious attempt in years to coordinate Common Criteria certification across the Union under a single regulatory umbrella.
The first EUCC certificates could be delivered from 27 February 2025, when Member States, through their National Cybersecurity Certification Authorities (NCCAs), gained the operational mandate to issue. Just over fifteen months later, the public ENISA registry lists 30 published certificates. Congratulations to the scheme bodies, the labs, the conformity assessment bodies, and the vendors that got it to that mark.
What 30 certificates says about scheme maturity
Thirty certificates in fifteen months is a respectable pace for a new CC scheme. New national CC schemes have historically taken years to move from regulatory approval to a steady issuance cadence; the EUCC’s combination of an existing Common Criteria methodology, a pan-EU mandate, and Member State certification bodies that were already accredited under SOG-IS gave it a faster runway than a green-field scheme would have had.
The pace also matters as a credibility signal. Procurement teams, integrators, and security-policy authors all need to know whether a new certification framework is going to become a real publishing surface or a regulatory framework that ends up sitting unused. Thirty certificates is enough to say the framework is being used. Not yet enough to say it has displaced the existing schemes, but enough that downstream policy decisions (EU Cyber Resilience Act references, sector-specific procurement guidelines, vertical accreditation programmes) can start to lean on it.
The CAB landscape
Certificates have been issued by multiple conformity assessment bodies (CABs) operating across several Member States. That distribution matters because it confirms that EUCC is operating as designed: a pan-EU scheme run by national authorities, not a single body issuing in the name of the Union. Each CAB is accredited in its home Member State, supervised by that state’s NCCA, and free to compete on its own merits within the EUCC framework. Different vendors choose different CABs for reasons of geography, language, sector expertise, and existing relationships.
The variety also matters as a resilience story. A scheme that depends on a single CAB issuing everything is fragile. A scheme that has several CABs producing certificates, each operating under independent national oversight, can keep functioning if one of them pauses, restructures, or is taken offline for accreditation review.
What is being certified
Most early EUCC certifications fall into the categories that the wider Common Criteria community has been certifying for years: smart cards, secure microcontrollers, embedded platforms, and the toolchains that sit around them. That is exactly what one would expect from a scheme that inherits its lab and CAB base from the SOG-IS era: the bodies that were already accredited for smart-card and platform evaluations were the first to bring their accreditation across to the EUCC framework.
The interesting thing is what is starting to appear alongside those traditional categories. Recent EUCC entries include IoT-class systems certified at lower assurance levels, and a small but growing share of certificates from product categories that have not historically been a CC mainstay. EUCC is not category-bound: it supports the full EAL1 to EAL7 range and accepts product classes outside the traditional CC smart-card corpus. The presence of those non-traditional entries in the first 30 certificates is a signal that the scheme is being tested across the breadth of its remit, not just at its smart-card sweet spot.
The Common Criteria standard underneath
EUCC certificates issued from 2026 onward are largely based on CC:2022 Release 1 with the Common Evaluation Methodology CEM:2022. That is the current Common Criteria standard, and it matters that EUCC is using it. Schemes that lag the standard make it harder for vendors to plan multi-scheme certifications and for regulators to write down requirements that apply across schemes. EUCC adopting the current CC version from the start aligns it with the international corpus and reduces friction for vendors that want to certify the same product under multiple frameworks.
What it means for the wider CC ecosystem
The bigger point: EUCC is the first concrete deliverable of the EU Cybersecurity Act’s certification framework. The framework is intended to host other schemes too (cloud services, 5G network components, EU Digital Identity Wallets, eventually IoT) under a common regulatory umbrella. Whether those other schemes succeed depends partly on whether EUCC can demonstrate that the framework actually works in practice. Thirty certificates is the first real evidence that it does.
There is, of course, still work to do. Publishing practice across CC schemes still needs better coordination, which is the subject of a companion post on the silent EUCC portal reformat. The Substantial and High assurance labels are still being absorbed by procurement teams who have spent twenty years thinking in EAL packages. Cross-recognition with CCRA national schemes is still being worked out by individual Member States. None of that is settled at 30 certificates. But none of it could be settled at zero certificates either, and 30 is a meaningful start.
Congratulations to everyone who got it here. The next 30 will likely come faster.
How NenkinTracker tracks EUCC
NenkinTracker indexes the full EUCC corpus under the EUCC scheme view. Every certificate is browsable with its CAB, issuance year, assurance level, Protection Profile claim (or lack of one), and the three core documents (the Certificate PDF, the Security Target, and the Certification Report). Direct links from each cert detail page lead back to the canonical ENISA registry entries.
See also
- Anatomy of an EUCC Certificate: a walkthrough of an individual EUCC certificate, segment by segment
- EUCC: What the EU Cybersecurity Certification Scheme Means for Common Criteria: the scheme background and regulatory framing
- EUCC vs CCRA: how the two frameworks compare on governance and recognition
- When the source moves silently: the companion piece on EUCC publishing practice