In July 2026, the European Union Agency for Cybersecurity (ENISA) released its market study: Cybersecurity Assessments: Certification Uptake & State of Play 2021–2025 (Version 1.1). The report presents the clearest quantitative view yet of how European product security evaluations are changing under the EU Cybersecurity Act and the Cyber Resilience Act (CRA).
For twenty years, high-assurance product certification in Europe ran through national silos under the SOG-IS Mutual Recognition Agreement. That era is over. As of February 2026, SOG-IS certificates can no longer be delivered. The European Common Criteria scheme (EUCC) has taken over, while CEN/CENELEC EN 17640 (FiTCEM) establishes the first harmonised evaluation methodology designed specifically for SMEs.
1. The End of SOG-IS and the EUCC Takeover
The most critical structural change in the report is the transition to EUCC. Common Criteria certification historically relied on seven national certification bodies (France, Germany, Italy, Netherlands, Poland, Spain, and Sweden) recognising each other's certificates under SOG-IS.
That regime closed in February 2026. All new Common Criteria certificates must now be issued under the EUCC framework across all 27 EU Member States.
| Scheme Metric | Global Total | EU Share |
|---|---|---|
| Common Criteria Certificates (2025) | 420 | 242 (58%) |
| Accredited Evaluation Labs (ITSEFs) | 91 | 48 (53%) |
| EUCC Certified Products (2025 First Wave) | 17 | 17 (100%) |
| Accredited EUCC ITSEF Laboratories | 24 | 24 (100%) |
| Authorised EUCC Certification Bodies | 14 | 14 (100%) |
The report notes that 20 additional EUCC certificates were already published in early 2026. With 24 testing laboratories and 14 certification bodies already accredited across the Union, EUCC provides the third-party evaluation backbone required for CRA Class II products and European high-assurance mandates.
2. FiTCEM (EN 17640): The Fixed-Time Route for SMEs
Full Common Criteria evaluations cost hundreds of thousands of euros and take 9 to 18 months. For an SME shipping smart hardware or industrial controllers, Common Criteria is commercially prohibitive.
To solve this, national authorities created fixed-time evaluation schemes: CSPN in France (ANSSI), BSZ in Germany (BSI), LINCE in Spain (CCN), and BSPA in the Netherlands (NBV). These schemes fix the evaluation effort beforehand (typically 25 to 35 person-days) and focus on practical penetration testing rather than formal specification documentation.
The report highlights the major milestone: CEN/CENELEC standardisation of EN 17640 (FiTCEM). FiTCEM is the first European standard designed by design to support the Cyber Resilience Act's "Basic" and "Substantial" assurance levels.
- Germany (BSZ): Implemented EN 17640 as its baseline methodology in version 2.0 (Nov 2023), resulting in 14 BSZ certificates in 2025.
- France (CSPN): Formally declared conformity to FiTCEM, issuing 17 certificates in 2025 with over 40 evaluations processed annually.
- Spain (LINCE): Certified 16 products in 2025 and is finalizing its formal mapping to EN 17640.
This convergence means that fixed-time evaluations are no longer isolated national experiments. They represent the emerging European standard for cost-effective CRA conformity assessments.
3. The 30x Surge in IoT Security Baselines
Total successful assessments across all ICT products reached 1,928 in 2025, up from 1,155 in 2024. This growth was driven almost entirely by consumer IoT security labels.
- Germany BSI IT Security Label: Surged from 19 labels in 2024 to 567 labels in 2025—a nearly 30-fold increase as manufacturers prepare for CRA baseline requirements.
- Singapore Cybersecurity Labelling Scheme (CLS): Issued 268 labels in 2025 (mutually recognised with Germany's BSI Level 2).
- SESIP (EN 17927): GlobalPlatform's IoT evaluation methodology, adopted by CEN/CENELEC as EN 17927, grew steadily to 27 certified products in 2025.
- Private scheme contraction: Purely private schemes without regulatory alignment collapsed. The ioXt Alliance dropped from 196 certificates in 2021 to just 2 in 2025, as industry shifted towards statutory schemes like the US Cyber Trust Mark and EU CRA.
The surge in German BSI labels is a direct leading indicator: manufacturers are using national baseline self-assessments and surveillance to build the exact technical files required under CRA Module A (Internal Production Control).
4. Regulation (EU) 2025/37 and Managed Incident Response
The ENISA report includes Managed Security Services (MSS) for the first time. Under Regulation (EU) 2025/37 (the targeted amendment to the EU Cybersecurity Act), ENISA received a formal mandate to develop EU-wide certification schemes for MSS providers.
The European Commission requested an Ad Hoc Working Group to draft candidate certification requirements specifically for Incident Response services.
National adoption is already accelerating: Spain's National Security Framework (ENS / CCN-STIC 896 for MSS) jumped from 170 certified entities in 2021 to 3,186 in 2025. In Germany, BSI's certified incident response scheme (Vorfallbearbeitung) grew to 5 accredited service providers, alongside France's PRIS and PDIS qualifications.
This development directly intersects with CRA Article 14. Starting 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours. Having accredited Incident Response capabilities—either in-house or via certified MSSPs—will determine whether an organization meets those tight statutory windows.
What Manufacturers Must Do Now
The ENISA report proves that European product security evaluation has transitioned from theory to operational infrastructure:
- Do not plan around SOG-IS: All new high-assurance Common Criteria evaluations must target EUCC.
- Use EN 17640 (FiTCEM) for SME hardware and software: If your product falls outside Class II, a fixed-time evaluation delivers the required assurance at a fraction of the cost.
- Align vulnerability handling with Article 14: The regulatory focus is shifting toward incident response and disclosure readiness. Establish your coordinated vulnerability disclosure portal and response workflows before the 11 September 2026 deadline.
You can track CRA regulatory developments, standards, and technical file requirements through the PortaRegulus briefing series and the CVD Portal Knowledge Base.