Article content
In briefShow moreShow lessEUCC provides common rules and procedures for certifying ICT products across their lifecycle.
- EUCC provides common rules and procedures for certifying ICT products across their lifecycle.
- The scheme is voluntary and can be used for products such as routers and identification cards.
- Certification evidence must be distinguished from the later binding product duties under the Cyber Resilience Act.
EUCC was adopted as an implementing scheme under the EU Cybersecurity Act. Its purpose was to create a Union-wide framework for assessing and certifying ICT products so that users could place greater trust in them. The scheme is based on the Common Criteria approach.
The certification model is connected to the product lifecycle. The assessment therefore concerns more than a single feature at the time of delivery; it also addresses how security properties and assurance are documented during development and use. EUCC sets out certification roles and procedures for that work.
Routers and identification cards were examples of products for which security can be particularly important. Certification gives formal recognition to assessed security properties. It is nevertheless evidence and a trust mechanism, not a universal guarantee that a product is risk-free in every deployment.
EUCC is voluntary. The decision therefore does not make every ICT product subject to mandatory certification. An organisation or procurement process may use a certificate as relevant security evidence, while a particular contract, sector or purchasing authority may impose additional or more specific requirements.
The distinction from the Cyber Resilience Act is important. The Commission described EUCC as complementing the CRA, which introduces binding cybersecurity requirements for hardware and software products in the EU. The EUCC decision itself was not the CRA’s set of mandatory product obligations.
For Norway, the decision did not directly create a Norwegian duty. EUCC was an EU implementing regulation under the Cybersecurity Act, and EEA participation or Norwegian recognition had to be checked for the procurement in question. The announcement itself did not impose CRA duties in Norway.
EUCC built on Common Criteria and the existing European mutual-recognition arrangement. A certificate covers a defined product, version, security target and assurance level. Buyers therefore need to verify scope and validity, the evaluator, and whether the deployed configuration matches the evaluated one. Certification of one version does not automatically cover later updates or the supplier's complete service.
Sources
European Commission: “First EU-wide cybersecurity certification scheme,” 31 January 2024.
European Commission: “Implementing Regulation on the EUCC scheme,” 31 January 2024.
For discussion
Which procurements need EUCC evidence, and how do we verify that the certificate covers the deployed version?

