Complete our quick form
The European Union Common Criteria-based cybersecurity certification scheme (EUCC) is the first certification scheme established under the EU Cybersecurity Act and implemented through Commission Implementing Regulation (EU) 2024/482.
EUCC defines a harmonized framework for the cybersecurity evaluation and certification of ICT products intended for the EU internal market, based on internationally recognized Common Criteria standards (ISO/IEC 15408 and ISO/IEC 18045), and requires third‑party conformity assessment.
Applus+ Laboratories brings more than 20 years of experience in Common Criteria and cybersecurity evaluations and can act as:
This enables manufacturers to demonstrate a high level of cybersecurity assurance for the EU market and strengthens trust in the security of their products.
While EUCC is currently defined as a voluntary certification scheme, upcoming regulatory obligations under the Cyber Resilience Act (CRA) may require EUCC or equivalent certification for certain categories of products with digital elements.
In addition, the CRA introduces mandatory post‑market obligations such as vulnerability and incident reporting starting in September 2026, and full application of requirements from December 2027.
EUCC certification can play a key role in supporting CRA compliance when combined with additional regulatory measures. See our dedicated EUCC & CRA article for further details.
The EUCC scheme applies to a wide range of ICT products or Protection Profiles intended for the EU internal market. Products are evaluated against Substantial or High assurance levels, as defined under the Cybersecurity Act (CSA), using security requirements derived from Common Criteria.
Typical product categories include:
To start an EUCC evaluation process, manufacturers should:
Applus+ Laboratories supports clients throughout the entire EUCC certification process.
Applus+ Laboratories is:
Our longstanding experience in Common Criteria and EU cybersecurity certification enables us to deliver reliable, efficient, and future‑proof evaluations.
ENISA (the European Union Agency for Cybersecurity) plays a central role in the EUCC framework by supporting the development, maintenance, and consistent application of EU cybersecurity certification schemes established under the EU Cybersecurity Act.
Within the EUCC scheme, ENISA contributes through technical guidance, state‑of‑the‑art cybersecurity references, and coordination activities, helping ensure a harmonized and robust implementation of EUCC across Member States.
EUCC builds upon the established Common Criteria framework, maintaining its core evaluation principles while introducing additional requirements aligned with EU cybersecurity policy and lifecycle security expectations.
Compared to traditional Common Criteria schemes, EUCC places greater emphasis on assurance continuity, vulnerability handling, transparency, and state‑of‑the‑art practices.
Under the EUCC scheme, patch management mechanisms may be included within the evaluation scope to support the principle of assurance continuity.
When properly designed and assessed, patch management allows manufacturers to deploy security updates and vulnerability fixes without invalidating the EUCC certificate, provided defined conditions are met.
EUCC‑certified products must be supported by robust vulnerability management and disclosure processes covering the entire product lifecycle.
Following the EUCC Guidelines on Vulnerability Management and Disclosure is strongly recommended to ensure continued compliance and certificate maintenance.
EUCC certification requires manufacturers to make specific information publicly available, including:
EUCC compliance is assessed against state‑of‑the‑art cybersecurity practices, as defined in:
For High assurance levels, additional Technical Domain documents may apply and must be considered during evaluation.
| FILE | DEVELOPER | PRODUCT NAME | CSA level | Status |
|---|---|---|---|---|
| EUCC-2026-001 | Cisco Systems, Inc. | Cisco Catalyst 9800 Series Wireless Controllers and Access Points 17.18 | Substantial | Ongoing |
| EUCC-2026-002 | Cisco Systems, Inc. | Cisco Aggregation Services Router 1000 Series (ASR1K), Cisco Catalyst 8200, 8300, 8400, 8500 Series Routers (Cat8k) running IOS-XE 17.18 | Substantial | Ongoing |
| EUCC-2026-003 | Cisco Systems, Inc. | Cisco 1000 Series Integrated Services Routers (C1100) running IOS-XE 17.18 | Substantial | Ongoing |
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). Click HERE for more information. You can accept all cookies by pressing the "Accept" button or configure or reject their use by clicking here.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy