Skip to content
Nenkin

EUCC: What the EU Cybersecurity Certification Scheme Means for Common Criteria

The European Union Common Criteria-based Cybersecurity Certification Scheme (EUCC) is a new certification framework under the EU Cybersecurity Act (Regulation 2019/881). It represents the most significant structural change to Common Criteria certification in Europe since the CCRA was established.

For teams working with Common Criteria certified products (whether in procurement, compliance, or product security) the EUCC introduces changes to how certificates are issued, recognized, and maintained within the EU.

What is the EUCC?

The EUCC is the first EU-wide cybersecurity certification scheme adopted under the Cybersecurity Act. It is built on Common Criteria (ISO/IEC 15408) and the Common Evaluation Methodology (CEM), but wraps them in an EU regulatory framework that standardizes processes, governance, and recognition across all EU member states.

The scheme is voluntary: ICT suppliers who want to demonstrate assurance through an EU-wide assessment process can opt in. It was formally adopted as Commission Implementing Regulation (EU) 2024/482 (31 January 2024), then amended by Regulation (EU) 2024/3144 in December 2024 and again by Regulation (EU) 2025/2462 in December 2025. It applies to ICT products (hardware, software, and combined products).

Why the EUCC matters

Before the EUCC, Common Criteria certification in Europe was handled by national schemes such as BSI in Germany, ANSSI in France, OCSI in Italy, NSCIB in the Netherlands, and others. Each scheme had its own processes, timelines, and administrative requirements, even though they all evaluated against the same ISO 15408 standard.

The EUCC aims to:

  1. Unify the European CC landscape: one regulatory framework replaces the patchwork of national scheme practices
  2. Ensure EU-wide recognition: EUCC certificates are valid across all EU member states without additional national requirements
  3. Align with EU cybersecurity policy: the scheme integrates with other EU regulations like the Cyber Resilience Act (CRA) and NIS2 Directive
  4. Standardize governance: National Cybersecurity Certification Authorities (NCCAs) operate under harmonized rules

Two assurance levels

The EUCC defines two assurance levels, keyed off the Common Criteria vulnerability analysis component (AVA_VAN) rather than EAL number alone:

Substantial

Maps to: AVA_VAN.1 to AVA_VAN.2 (EAL1 to EAL3)

  • Certificates issued by accredited CABs (labs)
  • NCCA oversight, not direct issuance
  • Target for most commercial products

High

Maps to: AVA_VAN.3 to AVA_VAN.5 (EAL4 to EAL7)

  • Requires NCCA to issue or approve
  • Protection Profile conformance expected
  • Government, critical infrastructure, HSMs
EUCC repositions the EAL ladder under two regulatory tiers anchored on vulnerability analysis depth. “High” pulls the national authority back into the loop.

”Substantial” level

  • Covers AVA_VAN.1 and AVA_VAN.2, corresponding to EAL1 to EAL3
  • Certificates are issued by conformity assessment bodies (CABs), essentially accredited evaluation labs
  • The NCCA in each member state oversees the CABs but does not issue certificates directly at this level
  • Most commercial products will target this level

”High” level

  • Covers AVA_VAN.3 to AVA_VAN.5, corresponding to EAL4 to EAL7 (with the augmentations expected at higher tiers)
  • Certificates at this level require NCCA involvement: the national authority must either issue or approve the certificate
  • Intended for products with higher security requirements, government use, or critical infrastructure
  • Protection Profile conformance is generally expected at this level

What changes from existing CC practice

Certificate issuance

Under existing CCRA practice, certificates are issued by national scheme bodies (BSI, ANSSI, etc.). Under the EUCC, “substantial” level certificates can be issued directly by accredited CABs (evaluation labs), without the national scheme body acting as certificate issuer. “High” level certificates still require NCCA involvement.

Validity period

EUCC certificates have a default maximum validity of 5 years under Article 12 of the implementing regulation; the certification body may set a longer period only with prior approval from the NCCA. After that, they must be renewed or they expire. This is more prescriptive than some existing national schemes, which may allow certificates to remain active indefinitely if maintained.

Vulnerability disclosure

The EUCC requires certificate holders to have processes for handling vulnerability reports related to certified products. If a significant vulnerability is discovered, the certificate may be suspended or withdrawn.

Marking

Products with EUCC certificates may carry an EU cybersecurity certification mark, indicating the assurance level achieved. This provides visual recognition for procurement teams.

Monitoring

NCCAs must perform ongoing compliance monitoring, not just certify-and-forget. This includes market surveillance and the ability to challenge or revoke certificates.

Impact on existing CC certificates

Existing Common Criteria certificates issued by national schemes remain valid. The EUCC does not retroactively invalidate BSI, ANSSI, or other national certificates.

However:

  • New evaluations conducted under the EUCC framework will follow EUCC rules for issuance, maintenance, and validity
  • National schemes may continue to operate in parallel for products that do not need EU-wide EUCC certification
  • Over time, procurement requirements within the EU may increasingly reference EUCC certificates specifically, rather than generic CC certificates

Who is affected

Vendors seeking certification

If you sell IT products in the EU and your customers require CC certification, you will increasingly need to consider the EUCC pathway. This is especially true if your products fall under other EU regulations (Cyber Resilience Act, NIS2) that may mandate or reference EUCC certification.

Procurement teams

EU government procurement will likely shift toward requiring EUCC certificates. Understanding the difference between “substantial” and “high” assurance levels (and how they map to existing EAL levels) will be important for writing accurate procurement requirements.

Evaluation labs

ITSEFs operating in the EU must be accredited as CABs under the EUCC to issue “substantial” level certificates. This adds new accreditation requirements beyond existing ISO 17025 and CC scheme recognition.

Compliance teams

If you track CC certifications for compliance purposes, EUCC introduces a new certificate type to monitor. Products may hold both a traditional national CC certificate and a EUCC certificate, or transition from one to the other.

Relationship to other EU regulation

The EUCC does not exist in isolation. It is part of a broader EU cybersecurity regulatory framework:

  • Cyber Resilience Act (CRA): mandates cybersecurity requirements for products with digital elements sold in the EU. The CRA may reference EUCC as a presumption-of-conformity pathway.
  • NIS2 Directive: requires essential and important entities to use cybersecurity-certified products where available. EUCC certification may satisfy these requirements.
  • EU Cybersecurity Act: the parent regulation that establishes the framework for EU certification schemes. The EUCC is the first scheme adopted under it; others (for cloud services, for example) may follow.

Tracking EUCC and CC certifications

As the EUCC rolls out alongside existing national CC schemes, tracking the certification landscape becomes more complex. Products may hold certificates from different frameworks, and understanding which certificates are active, expiring, or superseded requires monitoring multiple sources.

NenkinTracker already tracks certifications from EUCC and major national CC schemes including BSI, ANSSI, NIAP, and others. As the EUCC matures, we will continue expanding our coverage.

Start tracking certifications for free to stay current on both EUCC and traditional CC certificates.

See also

Frequently asked questions

What is the EUCC?
EUCC is the European Union Common Criteria-based Cybersecurity Certification Scheme. It is the first EU-wide cybersecurity certification scheme adopted under the EU Cybersecurity Act (Regulation 2019/881) and Commission Implementing Regulation 2024/482, later amended by Regulation 2024/3144 (December 2024) and Regulation 2025/2462 (December 2025). It is voluntary. Built on Common Criteria (ISO/IEC 15408), it standardises certification processes, governance, and recognition across all EU member states.
What are the EUCC assurance levels?
EUCC defines two assurance levels keyed off the Common Criteria vulnerability analysis component (AVA_VAN). Substantial covers AVA_VAN.1 and AVA_VAN.2, corresponding to EAL1 to EAL3, and certificates may be issued by accredited conformity assessment bodies (CABs) under National Cybersecurity Certification Authority oversight. High covers AVA_VAN.3 to AVA_VAN.5, corresponding to EAL4 to EAL7, requires NCCA involvement to issue or approve, and typically expects Protection Profile conformance.
Are EUCC certificates valid in all EU member states?
Yes. EUCC certificates are valid across all EU member states without additional national requirements. NCCAs in each member state operate under harmonised rules coordinated by ENISA and the European Cybersecurity Certification Group. Replacing the patchwork of national CC scheme practices with a single regulatory framework is one of the central goals of the scheme.
How long is an EUCC certificate valid?
EUCC certificates have a default maximum validity of 5 years (Article 12 of Implementing Regulation (EU) 2024/482). The certification body may set a longer period only with prior approval from the National Cybersecurity Certification Authority. This is more prescriptive than some existing national CCRA schemes, which historically allowed certificates to remain active indefinitely if maintained. EUCC also requires NCCAs to perform ongoing compliance monitoring, not certify-and-forget.
Does EUCC invalidate existing Common Criteria certificates?
No. Existing Common Criteria certificates issued by national schemes (BSI, ANSSI, OCSI, NSCIB and others) remain valid. EUCC does not retroactively invalidate them. New evaluations conducted under the EUCC framework follow EUCC rules, and over time EU procurement requirements may increasingly reference EUCC specifically rather than generic Common Criteria.
How does EUCC relate to the Cyber Resilience Act and NIS2?
EUCC is part of a broader EU cybersecurity regulatory framework. The Cyber Resilience Act may reference EUCC as a presumption-of-conformity pathway for products with digital elements. NIS2 requires essential and important entities to use cybersecurity-certified products where available, which EUCC certification can satisfy. Both regulations build on the framework established by the EU Cybersecurity Act.