EUCC Overview: EU Common Criteria Certification Scheme
EUCC is the European Union Common Criteria-based cybersecurity certification scheme, adopted as the first candidate scheme under the EU Cybersecurity Act. It replaces SOG-IS mutual recognition for EU member states and formalises CC-based evaluation at the Union level under ENISA’s coordination.
Key facts
- Authorizing body: ENISA coordinates; national cybersecurity certification authorities (NCCAs) in each EU member state issue certificates
- Country / region: European Union
- Year established: Adopted via Commission Implementing Regulation (EU) 2024/482; application from 27 February 2025
- Product types: ICT products within scope of ISO/IEC 15408
- CCRA status: EUCC certificates are issued by EU national authorities who are CCRA members; mutual recognition with CCRA continues via those national schemes
- Canonical portal: ENISA EUCC page: https://certification.enisa.europa.eu/index_en
Overview
EUCC defines two assurance levels: Substantial (typically AVA_VAN.1 or AVA_VAN.2, paired with EAL1 to EAL3) and High (typically AVA_VAN.3, AVA_VAN.4, or AVA_VAN.5, paired with EAL4 with augmentation or higher). The scheme is voluntary; ICT suppliers can choose to certify their products at either level. It uses ISO/IEC 15408 and the CEM as its technical baseline and incorporates Supporting Documents previously developed under SOG-IS for the smart card and hardware-with-security-boxes domains. The Implementing Regulation has been amended twice since adoption: by Regulation (EU) 2024/3144 in December 2024 (covering accreditation state-of-the-art documents and main-text changes) and by Regulation (EU) 2025/2462, published 8 December 2025 (definitions, ICT product series certification, assurance continuity).
How evaluations work under this scheme
An applicant engages a conformity assessment body (CAB) accredited under EUCC by the national NCCA. The CAB performs the evaluation against the claimed Protection Profile and assurance package, producing the evaluation report. The NCCA issues the EUCC certificate at substantial or high. ENISA maintains the EUCC product list at Union level and publishes state-of-the-art documents, including Protection Profiles recognized for EUCC use.
Notable product categories
- Smart card ICs and secure microcontrollers (the historical SOG-IS high domain)
- HSMs and payment terminals
- Network products and enterprise IT evaluated under cPPs
- eIDAS-related components (trust service components, signature creation devices)
Relationship to CC baseline
EUCC is a conformity assessment framework layered on top of Common Criteria. The substantive evaluation is still CC (SFRs, SARs, CEM, and EALs) and certified products remain listed with their CC attributes. EUCC adds EU-level governance, uniform assurance-level naming (substantial / high), and legal grounding in the Cybersecurity Act. See What is Common Criteria? for the underlying standard.
Where to find official records
- ENISA EUCC page and product list: https://certification.enisa.europa.eu/index_en
- Implementing Regulation text: https://eur-lex.europa.eu/eli/reg_impl/2024/482/oj
- National NCCAs (BSI, ANSSI, and others) publish national EUCC certificates on their own portals.
- NenkinTracker tracks EUCC certificates alongside national CC records.
See also: EUCC: the EU Cybersecurity Certification Scheme, EUCC vs CCRA, Common Criteria vs EUCC migration guide, BSI, ANSSI, SESIP, Glossary.