Skip to content
Nenkin

EUCC vs CCRA: How the Two Common Criteria Frameworks Relate

EUCC and CCRA are both Common Criteria certification frameworks, both based on ISO/IEC 15408, and both produce certificates that look similar on paper. They are not the same. EUCC is a European Union regulatory scheme operated under the EU Cybersecurity Act; CCRA is an international arrangement under which national schemes mutually recognise each other’s evaluations. This entry summarises how the two relate and where they diverge.

Summary: CCRA is the multilateral mutual-recognition arrangement among national schemes worldwide; EUCC is the EU-specific Common Criteria scheme operated under EU regulation. EUCC succeeds the SOG-IS MRA inside the EU, while CCRA continues to provide international recognition for participating nations.

At a glance

AspectCCRAEUCC
TypeInternational mutual-recognition arrangementEU-wide regulatory certification scheme
Legal basisVoluntary multilateral arrangement (most recently revised 2014)EU Cybersecurity Act (Regulation (EU) 2019/881), Implementing Regulation (EU) 2024/482
OperatorNational scheme bodies, coordinated through the CCRA Management CommitteeENISA together with national certification authorities
RecognitionCertificates recognised across CCRA member nations under stated assurance limitsCertificates recognised across EU member states
StandardCommon Criteria (ISO/IEC 15408) and CEM (ISO/IEC 18045)Common Criteria (ISO/IEC 15408) and CEM, with EU-specific implementing rules
Successor toFirst CCRA arrangement (2000)SOG-IS MRA, for EU member states
Geographic scopeWorldwide, 36 member nations (18 Authorizing, 18 Consuming)EU member states

What CCRA does

The Common Criteria Recognition Arrangement is a voluntary international arrangement under which participating authorities issue Common Criteria certificates and recognise each other’s evaluations within stated assurance limits. The CCRA defines:

  • A common evaluation methodology (CEM) so labs in different countries produce comparable results.
  • A list of Authorising Members that issue certificates and Consuming Members that recognise them without re-evaluation.
  • Mutual-recognition limits, typically EAL2 for general evaluations and higher EALs for evaluations conformant to specific collaborative Protection Profiles (cPPs).

CCRA membership is not membership of a single regulator. Each participating nation runs its own scheme: BSI in Germany, ANSSI in France, NIAP in the United States, JISEC in Japan, CCCS in Canada, and so on. CCRA defines the rules under which those schemes’ certificates travel internationally.

What EUCC does

The EUCC is the European Union’s first cybersecurity certification scheme adopted under the EU Cybersecurity Act (Regulation (EU) 2019/881). Implementing Regulation (EU) 2024/482 sets out its operational rules, and two amendments have followed (Regulation (EU) 2024/3144 in December 2024, and a second amendment adopted 8 December 2025). EUCC:

  • Is a voluntary scheme adopted under EU regulation. ICT suppliers choose to pursue EUCC certification, but other EU regulation (the Cyber Resilience Act, NIS2, eIDAS, sector-specific frameworks) may require or favour EUCC-certified products for specific product classes.
  • Is operated by ENISA in cooperation with national certification authorities and the European Cybersecurity Certification Group.
  • Builds on the SOG-IS Common Criteria framework previously used across 17 EU member states. Existing SOG-IS certificates can transition to EUCC under defined procedures, and SOG-IS recognition is winding down for EU member states as EUCC takes over.
  • Defines two assurance levels: substantial (AVA_VAN.1 or AVA_VAN.2) and high (AVA_VAN.3, AVA_VAN.4, or AVA_VAN.5), with additional EU-specific procedures for handling vulnerabilities, maintenance, and patch management.

EUCC builds on the Common Criteria standard rather than replacing it: the underlying ISO/IEC 15408 evaluation methodology is unchanged, but EUCC adds EU regulatory wrapping on top.

How they coexist

For a product seeking broad market recognition, the question is rarely “EUCC or CCRA” but rather “what combination of certifications does my market require”. Common patterns:

  • EU government and regulated-sector procurement is increasingly oriented toward EUCC, with SOG-IS recognition winding down for EU member states.
  • Non-EU government procurement (US federal, Japan, Canada, and others) continues to rely on national CCRA schemes.
  • Smart cards and secure microcontrollers historically certified under SOG-IS at high assurance levels are migrating their recognition to EUCC over a transition period.
  • Vendors targeting both EU and non-EU markets typically pursue a CCRA certification for international recognition together with an EUCC-aligned certification or transition for EU regulatory acceptance.

The exact migration mechanics differ by product category and by national authority. Vendors should consult their primary scheme early when planning evaluations that need to land valid in both frameworks.

Differences worth knowing

A few points where EUCC and CCRA diverge in operational details:

  • Vulnerability handling. EUCC has explicit obligations on certificate holders for vulnerability management and patch dissemination. CCRA leaves vulnerability handling to the issuing scheme’s national rules.
  • Validity periods. Both frameworks rely on the underlying CC assurance-continuity process for maintenance and re-evaluation, but EUCC adds EU-level rules around patch management and conformity reporting.
  • Authority over issued certificates. A CCRA certificate is owned by the issuing national scheme. An EUCC certificate is governed under EU regulation, with national certification authorities operating within that framework.
  • Mark and labelling. EUCC certificates carry the EUCC mark; CCRA certificates carry the issuing scheme’s mark and may also carry the CCRA logo if the certificate is recognised by the arrangement.

Tracking certificates across both

NenkinTracker indexes EUCC and CCRA certifications side by side and links them to the same product where that linkage is published by the schemes. Explore the tracker to search certifications and follow products across both frameworks.

See also

Frequently asked questions

What is the difference between EUCC and CCRA?
CCRA is a voluntary international mutual-recognition arrangement under which national schemes (BSI, ANSSI, NIAP and others) accept each other's Common Criteria certificates. EUCC is an EU-wide regulatory scheme operated under the EU Cybersecurity Act, where certification can be a legal prerequisite. CCRA is multilateral and worldwide; EUCC is regulatory and EU-specific. Both build on ISO/IEC 15408.
Does EUCC replace the CCRA?
No. EUCC operates inside the EU under EU regulation, while CCRA continues to provide international mutual recognition across 36 member nations worldwide. EUCC succeeds the SOG-IS MRA for EU member states, not CCRA. Vendors targeting both EU and non-EU markets typically pursue a CCRA certification for international recognition together with an EUCC-aligned certification for EU regulatory acceptance.
Who operates EUCC?
EUCC is operated by ENISA (the EU Agency for Cybersecurity) in cooperation with national certification authorities (NCAs) in each EU member state and the European Cybersecurity Certification Group. Implementing Regulation (EU) 2024/482 sets out the operational rules, and the underlying legal basis is the EU Cybersecurity Act (Regulation (EU) 2019/881). National authorities issue certificates within the harmonised EU framework.
Are CCRA certificates accepted in the EU?
They are recognised under the CCRA among participating EU member states, but EU-specific procurement and regulated- sector requirements are increasingly oriented toward EUCC. EU government and regulated-sector procurement is migrating to EUCC; SOG-IS recognition is winding down for EU member states. CCRA remains the primary route for non-EU markets such as US federal, Japan, and Canada.
What happens to existing SOG-IS certificates under EUCC?
EUCC succeeds the SOG-IS MRA for EU member states, and existing SOG-IS certificates can transition to EUCC under defined procedures. Smart cards and secure microcontrollers historically certified under SOG-IS at high assurance levels are migrating their recognition into EUCC over a transition period. The exact mechanics differ by product category and by national authority, so vendors should consult their primary scheme early.
Does EUCC change vulnerability handling rules?
Yes. EUCC has explicit obligations on certificate holders for vulnerability management and patch dissemination, written into the EU regulatory framework. CCRA, by contrast, leaves vulnerability handling to each issuing scheme's national rules. EUCC also adds EU-level rules around patch management and conformity reporting on top of the standard Common Criteria assurance-continuity process shared by both frameworks.