# European Cybersecurity Certification Schemes — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/european-cybersecurity-certification-schemes
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address European cybersecurity certification schemes (EUCS) as referenced in NIS2, which establish a framework for certifying cloud services and other ICT products/services against defined security criteria.

## Overview

## Legal Framework

European cybersecurity certification schemes operate at the intersection of NIS2 and the GDPR. Article 24 of NIS2 establishes the use of European cybersecurity certification schemes as a mechanism for essential and important entities to demonstrate compliance with security requirements. Recital 138 of NIS2 delegates authority to the European Commission to specify which categories of essential and important entities must use certified ICT products, ICT services, and ICT processes, or obtain certificates under such schemes.

In parallel, the GDPR provides its own certification architecture. Article 42 GDPR establishes data protection certification mechanisms and seals, while Article 24(3) GDPR explicitly recognizes adherence to approved certification mechanisms as a permissible means for controllers to demonstrate compliance with their obligations under Article 24(1) and (2). The controller—not the processor—bears responsibility for compliance with data protection principles and must be able to demonstrate that compliance through documented policies and imposed processor obligations under Article 28.

Article 43 GDPR governs the accreditation of certification bodies, requiring Member States to establish accreditation processes and offering multiple structural options for who performs accreditation assessments. The EU legislature treats certification as an effective instrument both to promote compliance and to enhance transparency under the Regulation.

## Key Developments

The EDPB's Guidelines 1/2018 clarify the framework for data protection certification and the identification of certification criteria under Articles 42 and 43 GDPR, establishing that certification criteria must be sufficiently specific, objective, and auditable to serve as reliable compliance evidence.

The EDPB's Opinion 34/2025, addressing the Greek Supervisory Authority's draft decision on C.E.C.L. certification criteria, signals ongoing supervisory scrutiny of how certification schemes operationalize GDPR requirements. This opinion reflects that certification criteria are not merely technical benchmarks but must align substantively with data protection obligations—particularly regarding the controller's accountability duties under Article 24(2) GDPR.

The NIS2 framework, through Recital 138, indicates that the Commission's delegated acts will progressively narrow the scope of voluntary certification by mandating specific schemes for defined entity categories, creating a regulatory trajectory toward compulsory certification for certain sectors.

## Practical Guidance

- **Map certification obligations across both regimes**: Organizations classified as essential or important entities under NIS2 should assess whether their ICT products, services, and processes fall within categories the Commission may designate as requiring certification under its delegated powers per Recital 138.

- **Leverage certification as accountability evidence**: Controllers should treat certification under Article 42 GDPR as a documented compliance tool under Article 24(3), ensuring that certification scope aligns with the principles the controller must demonstrate under Article 24(1)—not merely technical security controls.

- **Verify certification body accreditation**: Before relying on any certification, confirm that the certifying body holds valid accreditation through a process consistent with Article 43 GDPR, and that the accreditation covers the relevant certification scope and criteria.

- **Align processor contracts with certification requirements**: Under Article 28 GDPR, controllers must impose corresponding obligations on processors; where certification schemes impose specific security or processing standards, these must flow through to processor agreements.

- **Monitor EDPB criteria developments**: Track EDPB opinions on draft certification criteria—such as Opinion 34/2025—to anticipate supervisory expectations and ensure selected schemes meet the specificity and objectivity standards that data protection authorities will apply during audits.

## Legislation (full text of key provisions)

### Use of European cybersecurity certification schemes

*Source: NIS2, nis2-art-24-en, 2022-12-14 — https://overview.legal/posts/96253*

### Recital 138 — delegated acts for cybersecurity certification requirements

*Source: NIS2, nis2-rec-138-en, 2022-12-14 — https://overview.legal/posts/96804*

In order to ensure a high common level of cybersecurity across the Union on the basis of this Directive, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission in respect of supplementing this Directive by specifying which categories of essential and important entities are to be required to use certain certified ICT products, ICT services and ICT processes or obtain a certificate under a European cybersecurity certification scheme. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (22). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

### Recital 80 — cybersecurity certification compliance standards promotion

*Source: NIS2, nis2-rec-80-en, 2022-12-14 — https://overview.legal/posts/96688*

For the purpose of demonstrating compliance with cybersecurity risk-management measures and in the absence of appropriate European cybersecurity certification schemes adopted in accordance with Regulation (EU) 2019/881 of the European Parliament and of the Council (18), Member States should, in consultation with the Cooperation Group and the European Cybersecurity Certification Group, promote the use of relevant European and international standards by essential and important entities or may require entities to use certified ICT products, ICT services and ICT processes.

## Literature

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

## Related topics

- **Certification** — https://overview.legal/topics/certification
  Data protection certification mechanisms
- **NIS2 Addressees and Responsible Entities** — https://overview.legal/topics/nis2-addressees-identification
  The 'Addressees' section of NIS2 specifically identifies and defines the entities and authorities to whom the directive applies and who bear responsibility for 
- **Accountability** — https://overview.legal/topics/accountability
  Principle of demonstrating GDPR compliance
- **Encryption** — https://overview.legal/topics/encryption
  Encryption and cryptographic measures
- **Security** — https://overview.legal/topics/beveiliging
  Technical and organizational measures to protect personal data
- **Right to Explanation** — https://overview.legal/topics/right-to-explanation-individual-decisions
  This topic is essential as it specifically addresses the fundamental right of individuals to receive meaningful explanations about how automated decisions affec

---
Generated by overview.legal · https://overview.legal/topics/european-cybersecurity-certification-schemes · 2026-08-22
