EU Cybersecurity Act: ENISA Mandate and the Certification Framework

Introduction

Regulation (EU) 2019/881 — the EU Cybersecurity Act (CSA) — represents a landmark in the EU’s approach to cybersecurity governance. The CSA has two principal objectives: (a) to confer a permanent mandate and enhanced resources on the European Union Agency for Cybersecurity (ENISA), transforming it from a temporary agency into a standing body with operational, technical, and policy capabilities; and (b) to establish a European cybersecurity certification framework for ICT products, services, and processes, creating a single market for cybersecurity assurance across the Union.

ENISA’s Permanent Mandate

Before the CSA, ENISA operated under successive limited-duration mandates (2004–2009, 2009–2013, 2013–2020), creating uncertainty about its long-term role and limiting its capacity for strategic planning. The CSA grants ENISA a permanent mandate (Article 1), securing its institutional position and enabling multi-year programming. Headquartered in Athens with a second office in Heraklion, ENISA has expanded its staff to over 120 permanent and temporary agents, with a budget of approximately €35 million (2026).

The CSA defines ENISA’s mission as: (a) to achieve a high common level of cybersecurity across the Union; (b) to support Member States in implementing the NIS 2 Directive; (c) to operate the European cybersecurity certification framework; (d) to promote cooperation between Member States, Union institutions, and international partners; (e) to contribute to cyber crisis management under the Cyber Solidarity Act (Regulation 2023/…); and (f) to provide expertise on emerging technologies, including artificial intelligence, quantum computing, and the Internet of Things.

ENISA’s Operational Tasks

The CSA expands ENISA’s operational tasks beyond its earlier advisory role. These include: (a) maintaining and disseminating threat and vulnerability information through the EU Cyber Threat Intelligence platform; (b) supporting the operational coordination of CSIRTs through the CSIRT Network established under NIS 2; (c) conducting pan-European cybersecurity exercises (Cyber Europe) to test preparedness and response; (d) developing cybersecurity capability-building programmes for Member States, particularly new Member States and those with less developed cyber capacity; (e) contributing to the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) for crisis management at the strategic level; (f) providing the secretariat for the Cooperation Group and the European Cybersecurity Certification Group; and (g) establishing and maintaining a European vulnerability database.

The European Cybersecurity Certification Framework

Title III of the CSA establishes the voluntary European cybersecurity certification framework — a system of EU-wide certification schemes for ICT products, services, and processes. The framework aims to reduce fragmentation caused by 27 national certification schemes, enhance trust in ICT products, and enable cross-border recognition of cybersecurity certifications. Certification is based on common criteria and evaluation methods developed by ENISA in cooperation with the European Cybersecurity Certification Group (ECCG) — comprising national cybersecurity certification authorities — and adopted by the Commission through implementing acts.

Each scheme defines: (a) the scope (product categories, services, or processes); (b) assurance levels — basic, substantial, or high — reflecting the degree of evaluation rigour (Article 52); (c) conformity assessment methods (self-assessment, third-party assessment, national authority evaluation); (d) the evaluation criteria (technical standards, best practices); (e) vulnerability handling requirements; (f) the form and content of the EU statement of conformity or certificate; and (g) validity period (maximum five years, renewable).

EUCC and EUCS Schemes

The first scheme adopted under the CSA framework is the EU Common Criteria (EUCC) scheme (Commission Implementing Regulation 2024/…). Based on the international Common Criteria standard (ISO/IEC 15408), the EUCC scheme covers ICT products (hardware, software, firmware) with assurance levels from EAL 1 to EAL 4+ (substantial) and up to EAL 5–6 (high). The scheme is voluntary, though sector-specific legislation (e.g., NIS 2 for essential entities) may mandate its use for certain high-risk product categories.

The EU Cloud Services (EUCS) scheme, under development since 2020, addresses cloud security assurance. The EUCS scheme introduces three assurance levels and, critically for market access, includes sovereignty requirements at the “high” level: cloud service providers must be established in the EU, have no non-EU ownership, and apply EU law regarding government access to data. The EUCS proposal has proven controversial, with the United States and certain Member States arguing that the sovereignty requirements violate international trade commitments under the General Agreement on Trade in Services (GATS).

Voluntary vs Mandatory Certification

The CSA provides that certification schemes are voluntary by default (Article 56). However, the Commission may, in delegated or implementing acts under sector-specific legislation, make certification mandatory for specific ICT products, services, or processes where: (a) they play a critical role in essential services or digital infrastructure; (b) they process high-risk personal data; or (c) the risk of cybersecurity incidents is systemic.

The Cyber Resilience Act (Regulation 2024/…, CRA) introduces mandatory cybersecurity requirements for products with digital elements, including certification under EUCC for specific categories of critical products (routers, smart meters, IoT security devices). The interplay between the CSA’s voluntary framework and the CRA’s mandatory requirements creates a layered regime: the CSA provides the certification methodology and governance, while sector-specific legislation dictates when certification is compulsory.

Conformity Assessment and Accreditation

Certification under CSA schemes is carried out by Conformity Assessment Bodies (CABs) accredited by national accreditation bodies under Regulation (EC) No 765/2008. For “high” assurance levels, the evaluation may be conducted by an independent third party (typically a licensed IT security evaluation facility), with the certificate issued by the national cybersecurity certification authority. For “substantial” and “basic” levels, self-assessment or second-party assessment may be permitted, depending on the scheme’s rules.

Governance and International Cooperation

The CSA establishes a European Cybersecurity Certification Group (ECCG) — composed of national certification authorities — to advise ENISA and the Commission on market needs, scheme design, and equivalence with international certification regimes. The Stakeholder Cybersecurity Certification Group provides input from industry, academia, and civil society. The Commission may recognise third-country certification schemes as equivalent to EU schemes under Article 58, provided the third country’s legal framework ensures an equivalent level of assurance and permits mutual recognition.

Review and Reform

The CSA includes a five-year review clause (Article 67), requiring the Commission to assess effectiveness, efficiency, and governance by 2026. The 2024 Commission evaluation identified areas for improvement: faster development of certification schemes, enhanced resources for ENISA (particularly for operational tasks under NIS 2 and the CRA), and better integration with the Cyber Solidarity Act’s incident response framework.