PortaRegulus
HOME
17 // INTEL · ANALYSIS

SOG-IS is dead, EUCC is live, and the SME middle is finally codified.

ENISA published its 5-year cybersecurity assessment report (2021–2025). The data confirms a structural transition: the 20-year SOG-IS regime ended in February 2026, EUCC is operational, and fixed-time testing (EN 17640) gives SMEs a realistic conformity route.

PortaRegulus Intel ENISA · EUCC · CRA Conformity 16 Aug 2026

In July 2026, the European Union Agency for Cybersecurity (ENISA) released its market study: Cybersecurity Assessments: Certification Uptake & State of Play 2021–2025 (Version 1.1). The report presents the clearest quantitative view yet of how European product security evaluations are changing under the EU Cybersecurity Act and the Cyber Resilience Act (CRA).

For twenty years, high-assurance product certification in Europe ran through national silos under the SOG-IS Mutual Recognition Agreement. That era is over. As of February 2026, SOG-IS certificates can no longer be delivered. The European Common Criteria scheme (EUCC) has taken over, while CEN/CENELEC EN 17640 (FiTCEM) establishes the first harmonised evaluation methodology designed specifically for SMEs.

1. The End of SOG-IS and the EUCC Takeover

The most critical structural change in the report is the transition to EUCC. Common Criteria certification historically relied on seven national certification bodies (France, Germany, Italy, Netherlands, Poland, Spain, and Sweden) recognising each other's certificates under SOG-IS.

That regime closed in February 2026. All new Common Criteria certificates must now be issued under the EUCC framework across all 27 EU Member States.

Scheme Metric Global Total EU Share
Common Criteria Certificates (2025) 420 242 (58%)
Accredited Evaluation Labs (ITSEFs) 91 48 (53%)
EUCC Certified Products (2025 First Wave) 17 17 (100%)
Accredited EUCC ITSEF Laboratories 24 24 (100%)
Authorised EUCC Certification Bodies 14 14 (100%)

The report notes that 20 additional EUCC certificates were already published in early 2026. With 24 testing laboratories and 14 certification bodies already accredited across the Union, EUCC provides the third-party evaluation backbone required for CRA Class II products and European high-assurance mandates.

2. FiTCEM (EN 17640): The Fixed-Time Route for SMEs

Full Common Criteria evaluations cost hundreds of thousands of euros and take 9 to 18 months. For an SME shipping smart hardware or industrial controllers, Common Criteria is commercially prohibitive.

To solve this, national authorities created fixed-time evaluation schemes: CSPN in France (ANSSI), BSZ in Germany (BSI), LINCE in Spain (CCN), and BSPA in the Netherlands (NBV). These schemes fix the evaluation effort beforehand (typically 25 to 35 person-days) and focus on practical penetration testing rather than formal specification documentation.

The report highlights the major milestone: CEN/CENELEC standardisation of EN 17640 (FiTCEM). FiTCEM is the first European standard designed by design to support the Cyber Resilience Act's "Basic" and "Substantial" assurance levels.

This convergence means that fixed-time evaluations are no longer isolated national experiments. They represent the emerging European standard for cost-effective CRA conformity assessments.

3. The 30x Surge in IoT Security Baselines

Total successful assessments across all ICT products reached 1,928 in 2025, up from 1,155 in 2024. This growth was driven almost entirely by consumer IoT security labels.

The surge in German BSI labels is a direct leading indicator: manufacturers are using national baseline self-assessments and surveillance to build the exact technical files required under CRA Module A (Internal Production Control).

4. Regulation (EU) 2025/37 and Managed Incident Response

The ENISA report includes Managed Security Services (MSS) for the first time. Under Regulation (EU) 2025/37 (the targeted amendment to the EU Cybersecurity Act), ENISA received a formal mandate to develop EU-wide certification schemes for MSS providers.

The European Commission requested an Ad Hoc Working Group to draft candidate certification requirements specifically for Incident Response services.

National adoption is already accelerating: Spain's National Security Framework (ENS / CCN-STIC 896 for MSS) jumped from 170 certified entities in 2021 to 3,186 in 2025. In Germany, BSI's certified incident response scheme (Vorfallbearbeitung) grew to 5 accredited service providers, alongside France's PRIS and PDIS qualifications.

This development directly intersects with CRA Article 14. Starting 11 September 2026, manufacturers must report actively exploited vulnerabilities within 24 hours. Having accredited Incident Response capabilities—either in-house or via certified MSSPs—will determine whether an organization meets those tight statutory windows.

What Manufacturers Must Do Now

The ENISA report proves that European product security evaluation has transitioned from theory to operational infrastructure:

You can track CRA regulatory developments, standards, and technical file requirements through the PortaRegulus briefing series and the CVD Portal Knowledge Base.

Build your CRA technical file. Free.