Cyber Resilience Act

European cybersecurity certification scheme

Practical term

A European cybersecurity certification scheme is a body of rules adopted by the Commission under which ICT products, services and processes are evaluated and certified. Such schemes are not created by the Cyber Resilience Act (CRA) but by Regulation (EU) 2019/881, the Cybersecurity Act. The CRA picks them up and turns the resulting certificate into a way of demonstrating conformity at several points.

How a scheme comes about

Regulation (EU) 2019/881 sets the frame. The Commission publishes a Union rolling work programme setting strategic priorities for future schemes (Article 47(1)), may request ENISA to prepare a candidate scheme (Article 48(1)), and may then establish it by implementing act (Article 49(7)). The European Cybersecurity Certification Group advises and delivers an opinion, by which ENISA is not bound. At least every five years ENISA evaluates each adopted scheme afresh.

Article 54 of the same Regulation lists what every scheme must at least settle: the product categories covered, the evaluation criteria and methods, whether self-assessment is allowed, how previously undetected vulnerabilities are handled, and the maximum validity of certificates. Once a scheme applies, national certification schemes for the same products cease to produce effects from the date named in the implementing act (Article 57).

One trap exists only in the German text. The CRA writes „Schema für die Cybersicherheitszertifizierung“ almost throughout, but Article 32(2) once says „europäische Systeme für die Cybersicherheitszertifizierung“, in the very sentence that reverts to „Schemata“ a few words later. The English says “scheme” in both places. The same thing is meant.

Three assurance levels

Article 52 of Regulation (EU) 2019/881 provides for the levels “basic”, “substantial” and “high”. They differ in the rigour and depth of the evaluation:

  • basic: the evaluation includes at least a review of the technical documentation and is aimed at minimising the known basic risks (paragraph 5).
  • substantial: the evaluation includes at least a review demonstrating the absence of publicly known vulnerabilities and testing that the security functionalities are correctly implemented. The benchmark is actors with limited skills and resources (paragraph 6).
  • high: the same review, plus testing that the security functionalities are correctly implemented at the state of the art, and an assessment of resistance to skilled attackers using penetration testing. The benchmark is actors with significant skills and resources (paragraph 7).

The level also decides who evaluates. A scheme may allow conformity self-assessment, but only for low-risk products corresponding to assurance level “basic”, in which case the manufacturer may issue an EU statement of conformity under Article 53. Certificates at “basic” and “substantial” are issued by conformity assessment bodies, unless the scheme reserves issuance to a public body. Where a scheme requires “high”, the national cybersecurity certification authority is in charge as a rule, and a conformity assessment body may issue only on prior approval or under a general delegation (Article 56).

That EU statement of conformity under Article 53 of Regulation (EU) 2019/881 is not the EU declaration of conformity of the CRA. Different instrument, different subject matter, and in German both carry the same name, which makes the confusion easy to import.

What a certificate achieves in the CRA

Article 27(8) CRA establishes a presumption of conformity. Products, and the processes put in place by the manufacturer, for which a European cybersecurity certificate or an EU statement of conformity has been issued under a scheme adopted pursuant to Regulation (EU) 2019/881 are presumed to meet the Essential cybersecurity requirements in so far as the certificate or the statement, or parts thereof, cover those requirements.

The second effect carries more commercial weight: a certificate at assurance level at least “substantial” eliminates the obligation to have a third-party conformity assessment carried out for the corresponding requirements, specifically under Article 32(2), points (a) and (b), and Article 32(3), points (a) and (b). That sits in Article 27(9), alongside the Commission’s power to specify by delegated act which schemes may be used to demonstrate conformity at all.

This is a place to read closely. The wording of paragraph 8 makes the presumption conditional on nothing further from the Commission, while recital 81 attaches it to schemes the Commission has identified in an implementing act. As a route of its own in Article 32(1), point (d), and Article 32(3), point (c), the scheme appears only once it has been specified under Article 27(9). Recital 82 names a concrete case: for the EUCC laid down in Implementing Regulation (EU) 2024/482, which concerns products such as hardware security modules and microprocessors, the Commission should be able to specify by delegated act how it provides a presumption of conformity and how a certificate issued under it eliminates the third-party assessment obligation.

The certification route in Article 32

Among the Conformity assessment procedures the scheme has a letter of its own:

  • Article 32(1), point (d): for any product, where a scheme is available and applicable
  • Article 32(3), point (c): for important products in class II, where a scheme is available and applicable, and there at assurance level at least “substantial”
  • Article 32(4), point (a): for critical products listed in Annex IV

For class I the scheme works the other way round. It is not a route of its own there but what keeps module A open: where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or a scheme at assurance level at least “substantial”, or where no such standards, specifications or schemes exist, Article 32(2) forces a procedure involving a third party.

When certification becomes compulsory

Annex IV lists three categories of critical products: hardware devices with security boxes, smart meter gateways within smart metering systems and other devices for advanced security purposes including secure cryptoprocessing, and smartcards or similar devices including secure elements.

For products carrying the core functionality of those categories, the Commission may require a European cybersecurity certificate at assurance level at least “substantial” by delegated act under Article 8(1). Three conditions attach: a suitable scheme must have been adopted pursuant to Regulation (EU) 2019/881 and be available to manufacturers, the Commission must first assess the market impact and consult stakeholders, and the act must provide a transitional period of at least six months, unless a shorter period is justified for imperative reasons of urgency. Where no such act is adopted, those products fall under the procedures in Article 32(3), the class II ones.

What a certificate does not replace

The presumption reaches only as far as the certificate covers the requirements; everything else still has to be evidenced. Annex VII, point 5 accordingly requires the technical documentation to list the harmonised standards whose references have been published in the Official Journal of the European Union, the common specifications and the certification schemes applied in full or in part, and where in part, which parts.

Untouched are the duties that do not hang on the evaluated state of the product: CE marking and the EU declaration of conformity, the support period, ongoing vulnerability handling and the Reporting obligations in Article 14. A certificate says nothing about any of them.

Nor is anything automatic on the evaluator side. Under recital 100, conformity assessment bodies notified for a European certification scheme should be newly assessed and notified under the CRA. Relevant authorities can define synergies on overlapping requirements to avoid unnecessary burden. What they cannot do is stand in for the notification.

What is still open

The Regulation sets the instrument out in full, but guarantees nothing about when a usable scheme will exist. Which schemes the Commission specifies under Article 27(9), for which Annex IV categories it makes certification compulsory under Article 8(1), and when either happens, is left to delegated acts.

For planning purposes the certification route is therefore an offer with a caveat. Anyone building a class I product around it needs a fallback through harmonised standards or a third-party procedure, and needs it well before the date of application on 11 December 2027.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.