
2
min reading time
The European Union Cybersecurity Certification (EUCC) is a new scheme for certifying information and computer technology products in Europe; it is an update from the previous existing SOG-IS MRA.
EUCC is a Common Criteria-based certification scheme that uses the internationally acclaimed, proven methods used in Common Criteria with additional concepts to provide a modern and flexible solution to stakeholders such as patch management for certified products.
Common Criteria (CC) refers to an international set of standards and guidelines used in evaluating security products and systems. Common Criteria was initially developed to ensure technology products met specific security standards and government regulations. Assurances are separated by metrics concerning overall effectiveness and correctness.
Common Criteria helps ensure higher product standards while also protecting against pressing cybersecurity concerns, including data breaches, information leaks, and privacy concerns.
Once technology products are inspected by experts and have been sufficiently assessed, they receive a recognized Common Criteria Certification.
Understanding the core concepts and rationale behind Common Criteria is crucial for understanding internationally uniform cybersecurity protocols and interpreting the new EUCC scheme.
The EUCC scheme draws from the same central components of Common Criteria, applying them to technology products within the European Union. EUCC adds additional requirements on top of existing Common Criteria and  Cybersecurity Evaluation Methodology (CEM) practices. 
New requirements to cybersecurity certifications include additional monitoring and handling of compliances, more transparent and publicly available vulnerability information, and offering increased support to consumers such as patch management for certified products.
Implementation
Implementation of the EUCC scheme began at the end of 2020. Certification schemes under SOGIS-MRA can  EUCC is scheduled to be fully operational at the beginning of 2022, possibly converting existing assessments and certifications to match the new EUCC scheme. 
Application
EUCC is applied to ICT products which:
embeds a meaningful set of security functional requirements as described by Common Criteria Part 2
aims to achieve ‘substantial’ or ‘high’ level of assurance for the CSA covered by EUCC.
Improvements and Comparisons
EUCC represents some improvements over existing schemes.
Pros include an increased emphasis on:
Some cons to this include:
EUCC Moving Forward
The new EUCC scheme will change some cybersecurity protocols regarding product certification throughout Europe, but still draws on many of the same core concepts as the Common Criteria. It marks a departure from the previous SOG-IS MRA.  
For the time being, both methods will be held to a high standard when assessing and evaluating the cybersecurity protocols of ICT products.
The European Commission has initiated a public consultation between 3rd October to 31. October 2023. on the draft implementing regulation that establishes the European Common Criteria-based cybersecurity certification scheme (EUCC) for information and communication technologies (ICT) products. The received feedback and the draft of the Commission Implementing Regulation is available on the European Commission's website. The final regulation is expected in Q4 2023 and is planned to become applicable 12 months after it enters into force. Once applicable, national cybersecurity certification schemes and related procedures covered by the EUCC will cease to have effect, specifically, those applying evaluation standards covered by the Common Criteria.


Download EUCC Study 2024 for the most important and up-to-date information about the new European Union Cybersecurity Certification Scheme


Learn everything you need to know for a successful Common Criteria certification project. Save costs and effort with your checklist.


This downloadable infographics introduces the Common Criteria Evaluation process to you. Explore now for free.

The journey of achieving Common Criteria certification represents just the beginning of a complex, ongoing process that demands continuous attention and strategic management. Organizations worldwide invest significant resources in obtaining these prestigious security certifications, yet many underestimate the critical importance of proper lifecycle management once their products become Common Criteria certified. Effective CC certification lifecycle management ensures continuous security assurance, regulatory compliance, and market credibility throughout a product’s operational lifespan.
9
min reading time

In an increasingly interconnected world, cybersecurity has become more than just a technical requirement, it's a critical shield protecting organizations from potential digital threats. Common Criteria (CC), an internationally recognized standard also known as ISO/IEC 15408, emerges as a comprehensive framework that meticulously evaluates the security properties of IT products and systems. This international standard provides a structured approach to assessing technological security, offering governments, enterprises, and technology developers a robust methodology for understanding and validating the security mechanisms embedded within their digital solutions. Moreover, Common Criteria serves as a critical benchmark, ensuring that technological products meet rigorous security standards before entering the marketplace.
10
min reading time

As Europe advances its digital transformation agenda, securing its technological infrastructure has become a top priority. At the center of this ambition lies the European cybersecurity certification ecosystem. Most notably, the European Cybersecurity Certification Scheme (EUCC). Designed to harmonize security assurance practices across EU member states, EUCC is the first concrete step under the EU Cybersecurity Act to create a unified framework for certifying ICT products and services. But while EUCC represents a major achievement in digital sovereignty, a crucial question remains: Is it enough? This article explores what the European Cybersecurity Certification does well, where its current limitations lie, and what additional steps are necessary to create a truly resilient cybersecurity landscape across Europe.
7
min reading time