Skip to content
Nenkin

EUCC Overview: EU Common Criteria Certification Scheme

EUCC is the European Union Common Criteria-based cybersecurity certification scheme, adopted as the first candidate scheme under the EU Cybersecurity Act. It replaces SOG-IS mutual recognition for EU member states and formalises CC-based evaluation at the Union level under ENISA’s coordination.

Key facts

  • Authorizing body: ENISA coordinates; national cybersecurity certification authorities (NCCAs) in each EU member state issue certificates
  • Country / region: European Union
  • Year established: Adopted via Commission Implementing Regulation (EU) 2024/482; application from 27 February 2025
  • Product types: ICT products within scope of ISO/IEC 15408
  • CCRA status: EUCC certificates are issued by EU national authorities who are CCRA members; mutual recognition with CCRA continues via those national schemes
  • Canonical portal: ENISA EUCC page: https://certification.enisa.europa.eu/index_en

Overview

EUCC defines two assurance levels: Substantial (typically AVA_VAN.1 or AVA_VAN.2, paired with EAL1 to EAL3) and High (typically AVA_VAN.3, AVA_VAN.4, or AVA_VAN.5, paired with EAL4 with augmentation or higher). The scheme is voluntary; ICT suppliers can choose to certify their products at either level. It uses ISO/IEC 15408 and the CEM as its technical baseline and incorporates Supporting Documents previously developed under SOG-IS for the smart card and hardware-with-security-boxes domains. The Implementing Regulation has been amended twice since adoption: by Regulation (EU) 2024/3144 in December 2024 (covering accreditation state-of-the-art documents and main-text changes) and by Regulation (EU) 2025/2462, published 8 December 2025 (definitions, ICT product series certification, assurance continuity).

How evaluations work under this scheme

An applicant engages a conformity assessment body (CAB) accredited under EUCC by the national NCCA. The CAB performs the evaluation against the claimed Protection Profile and assurance package, producing the evaluation report. The NCCA issues the EUCC certificate at substantial or high. ENISA maintains the EUCC product list at Union level and publishes state-of-the-art documents, including Protection Profiles recognized for EUCC use.

Notable product categories

  • Smart card ICs and secure microcontrollers (the historical SOG-IS high domain)
  • HSMs and payment terminals
  • Network products and enterprise IT evaluated under cPPs
  • eIDAS-related components (trust service components, signature creation devices)

Relationship to CC baseline

EUCC is a conformity assessment framework layered on top of Common Criteria. The substantive evaluation is still CC (SFRs, SARs, CEM, and EALs) and certified products remain listed with their CC attributes. EUCC adds EU-level governance, uniform assurance-level naming (substantial / high), and legal grounding in the Cybersecurity Act. See What is Common Criteria? for the underlying standard.

Where to find official records

See also: EUCC: the EU Cybersecurity Certification Scheme, EUCC vs CCRA, Common Criteria vs EUCC migration guide, BSI, ANSSI, SESIP, Glossary.

Frequently asked questions

What is EUCC?
EUCC is the European Union Common Criteria-based cybersecurity certification scheme, the first candidate scheme adopted under the EU Cybersecurity Act. It was established by Commission Implementing Regulation (EU) 2024/482 and has applied since 27 February 2025. EUCC replaces SOG-IS mutual recognition for EU member states and formalises CC-based evaluation at the Union level under ENISA's coordination.
Who issues EUCC certificates?
ENISA coordinates EUCC at the Union level, but certificates are issued by national cybersecurity certification authorities (NCCAs) in each EU member state, typically the same body that runs the national CC scheme (BSI in Germany, ANSSI in France, OCSI in Italy, CCN in Spain, and others). ENISA maintains the EUCC product list and publishes the state-of-the-art documents the scheme uses.
What are the EUCC assurance levels?
EUCC defines two assurance levels: Substantial and High. The mapping is to AVA_VAN levels rather than to specific EAL packages: Substantial typically corresponds to AVA_VAN.1 or AVA_VAN.2 (often paired with EAL1 to EAL3), while High corresponds to AVA_VAN.3, AVA_VAN.4, or AVA_VAN.5 (paired with EAL4 with augmentation or higher). Both levels use the standard Common Criteria CEM and EAL machinery.
How long is an EUCC certificate valid?
EUCC certificates are issued for a maximum of five years under the Implementing Regulation, and the certificate holder can apply for renewal. Vulnerability handling and maintenance obligations apply throughout the validity period. This contrasts with traditional CCRA certificates, which do not have a fixed Union-wide validity cap (each national scheme defines its own renewal practice).
What is the difference between EUCC and CCRA?
CCRA is a voluntary international mutual-recognition arrangement covering 36 nations (18 Authorizing plus 18 Consuming), with recognition limited to EAL2 for arbitrary evaluations and to collaborative Protection Profiles at higher levels. EUCC is the EU's voluntary cybersecurity certification scheme adopted under the Cybersecurity Act, with full Union-wide recognition at Substantial and High. EUCC certificates are issued by NCCAs that are also CCRA members, so mutual recognition with CCRA continues via those national schemes.
Does EUCC cover smart cards?
Yes. EUCC explicitly incorporates the Supporting Documents previously developed under SOG-IS for the smart card and hardware domain, which means smart card ICs and secure microcontrollers can move from the historical SOG-IS high domain into EUCC at the high level. Other notable product categories under EUCC include HSMs, payment terminals, network products under cPPs, and eIDAS-related components.