Skip to content
Topic Regulator-defined

European Cybersecurity Certification Schemes

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed to specifically address European cybersecurity certification schemes (EUCS) as referenced in NIS2, which establish a framework for certifying cloud services and other ICT products/services against defined security criteria.

4 linked items 3 Laws1 Literature

Overview

18 sources · Jul 23, 2026

Legal Framework

European cybersecurity certification schemes operate at the intersection of NIS2 and the GDPR. Article 24 of NIS2 establishes the use of European cybersecurity certification schemes as a mechanism for essential and important entities to demonstrate compliance with security requirements. Recital 138 of NIS2 delegates authority to the European Commission to specify which categories of essential and important entities must use certified ICT products, ICT services, and ICT processes, or obtain certificates under such schemes.

In parallel, the GDPR provides its own certification architecture. Article 42 GDPR establishes data protection certification mechanisms and seals, while Article 24(3) GDPR explicitly recognizes adherence to approved certification mechanisms as a permissible means for controllers to demonstrate compliance with their obligations under Article 24(1) and (2). The controller—not the processor—bears responsibility for compliance with data protection principles and must be able to demonstrate that compliance through documented policies and imposed processor obligations under Article 28.

Article 43 GDPR governs the accreditation of certification bodies, requiring Member States to establish accreditation processes and offering multiple structural options for who performs accreditation assessments. The EU legislature treats certification as an effective instrument both to promote compliance and to enhance transparency under the Regulation.

Key Developments

The EDPB's Guidelines 1/2018 clarify the framework for data protection certification and the identification of certification criteria under Articles 42 and 43 GDPR, establishing that certification criteria must be sufficiently specific, objective, and auditable to serve as reliable compliance evidence.

The EDPB's Opinion 34/2025, addressing the Greek Supervisory Authority's draft decision on C.E.C.L. certification criteria, signals ongoing supervisory scrutiny of how certification schemes operationalize GDPR requirements. This opinion reflects that certification criteria are not merely technical benchmarks but must align substantively with data protection obligations—particularly regarding the controller's accountability duties under Article 24(2) GDPR.

The NIS2 framework, through Recital 138, indicates that the Commission's delegated acts will progressively narrow the scope of voluntary certification by mandating specific schemes for defined entity categories, creating a regulatory trajectory toward compulsory certification for certain sectors.

Practical Guidance

  • Map certification obligations across both regimes: Organizations classified as essential or important entities under NIS2 should assess whether their ICT products, services, and processes fall within categories the Commission may designate as requiring certification under its delegated powers per Recital 138.

  • Leverage certification as accountability evidence: Controllers should treat certification under Article 42 GDPR as a documented compliance tool under Article 24(3), ensuring that certification scope aligns with the principles the controller must demonstrate under Article 24(1)—not merely technical security controls.

  • Verify certification body accreditation: Before relying on any certification, confirm that the certifying body holds valid accreditation through a process consistent with Article 43 GDPR, and that the accreditation covers the relevant certification scope and criteria.

  • Align processor contracts with certification requirements: Under Article 28 GDPR, controllers must impose corresponding obligations on processors; where certification schemes impose specific security or processing standards, these must flow through to processor agreements.

  • Monitor EDPB criteria developments: Track EDPB opinions on draft certification criteria—such as Opinion 34/2025—to anticipate supervisory expectations and ensure selected schemes meet the specificity and objectivity standards that data protection authorities will apply during audits.

Everything on this topic, by type links go to the exact provision / paragraph / section