NIS2 Certification Doesn’t Exist at EU Level: What EUCC Covers, Why EUCS Stalled, and What Auditors Accept Instead
Germany’s BSI answers the question in one sentence: “Ein allgemeines Zertifikat zum Nachweis der Anforderungen gibt es nicht” — there is no general certificate for demonstrating NIS2 requirements [8]. Seven years after the Cybersecurity Act built the machinery for EU-wide cybersecurity certification, exactly one scheme has been adopted, and it certifies smartcards and firewalls, not companies [9].
That does not make the question naive. Article 24 of Directive (EU) 2022/2555 is titled “Use of European cybersecurity certification schemes”, certification appears in the enforcement provisions, and vendors sell “NIS2 certification” every day. The gap between what exists and what is marketed is where compliance budgets get wasted. This guide covers the formal, third-party-assessed routes only — if your question is whether you can attest to your own compliance, see our guide to NIS2 self-certification and national self-declaration routes.
“NIS2 Certification” Means Three Different Things — and Only One Is in the Directive
Most confusion here is a category error, not a knowledge gap: a procurement lead asking about certified suppliers and a CISO asking about their own ISMS get sent to the same search results and the same vendor pages.
| What you might mean | What gets certified | Does it exist today? | Where NIS2 addresses it |
|---|---|---|---|
| A qualification for your people | An individual | Yes — CISA, CISSP, CISM, vendor courses | Nowhere. The Directive imposes training duties, not credentials |
| A certificate for an ICT product, service or process you buy or sell | A product, service or process | Yes — EUCC, for products | Article 24(1) and 24(2) |
| A certificate for your organisation’s management system | Your ISMS and its controls | Yes, but never as an EU NIS2 scheme — ISO/IEC 27001, or a national scheme such as Belgium’s CyberFundamentals | Only indirectly, through Article 32(7)(g) |
Article 24(1) is worth reading closely, because almost every summary paraphrases it into something it does not say. Verbatim, Member States “may require essential and important entities to use particular ICT products, ICT services and ICT processes … that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881″ [1]. The obligation, where a Member State creates one, lands on what you procure and deploy. It does not certify you. The only provision that could ever require an entity itself to hold a certificate is Article 24(2), and it has never been used — more on that below.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
EUCC: The Only Adopted Scheme, and It Probably Isn’t About You
The EUCC is the European Common Criteria-based scheme, laid down in Commission Implementing Regulation (EU) 2024/482, adopted 31 January 2024 and applicable twelve months after entry into force [5][15]. It replaces the old SOG-IS arrangement that ran across 17 Member States, and it is the first — still the only — scheme adopted under Article 49 of the Cybersecurity Act [9].
In plain terms: EUCC certifies things you can put in a rack or a chip fab. ENISA describes its scope as ICT products including “technological components (chips, smartcards), hardware and software” [5]. If you operate a hospital, a water utility or a logistics firm, EUCC is a procurement signal, not a compliance target.
| Question | What the scheme actually says |
|---|---|
| Legal basis | Commission Implementing Regulation (EU) 2024/482, amended December 2024 and December 2025 [5] |
| Object of certification | ICT products — chips, smartcards, hardware, software [5] |
| Assurance levels | “Substantial” (AVA_VAN.1–2, broadly EAL1–3) and “high” (AVA_VAN.3–5, broadly EAL4–7). There is no “basic” level in EUCC [12] |
| Who assesses | An accredited conformity assessment body, with the technical evaluation done by an ITSEF. At “high”, the national certification authority reviews the evaluation report before a certificate issues [12] |
| Self-assessment | Not permitted. Every EUCC certificate requires independent evaluation [12] |
| Validity | Up to five years, with mandatory updates when product changes affect the evaluated security [12] |
| Mandatory? | No. Article 56(2) of the Cybersecurity Act: “The cybersecurity certification shall be voluntary, unless otherwise specified by Union law or Member State law” [4] |
| Recognition | A European cybersecurity certificate “shall be recognised in all Member States” (Article 56(10)) [4] |
The consequence for a CISO is narrow but real: where you deploy security-critical components — HSMs, smartcards, network appliances, secure elements — an EUCC certificate at “high” is portable evidence across all 27 Member States, which the old national Common Criteria certificates were not. Ask suppliers for the assurance level, not just the fact of certification. That is a due-diligence input under Article 21(2)(d), and it overlaps with the Cyber Resilience Act, covered in our analysis of how CRA product certification reduces your NIS2 supply-chain burden.
EUCS: Drafted, Politically Stuck, Issuing Nothing
The cloud services scheme is the one most in-scope entities actually care about, because cloud is where their regulated workloads live. It is not available. The Dutch national certification authority states it flatly: “Currently, the EUCS scheme is waiting for final adoption. This means that currently no certificates are being issued in the Netherlands under the EUCS” [7].
The blockage is not technical. ENISA published the first EUCS draft in December 2020; in 2022 the Commission asked for a clause ensuring that data at the highest level “would not fall under non-European jurisdictions”, which in practice meant EU-only hosting and processing plus European headquarters and majority ownership. Seven Member States objected that July, arguing it “excludes too many companies”; twelve, led by the Netherlands, objected to the May 2023 draft. The sovereignty requirement was dropped from the third version in March 2024 and left to national regulators — and the scheme has still not been adopted [17]. The European Parliament’s research service records the underlying disagreement as unresolved and names sovereignty criteria as the most contentious issue in the whole certification framework [9].
What that means for you in practice, until adoption:
- Do not write EUCS into contracts as a deliverable. There is no scheme to certify against and no conformity assessment body issuing under it. A clause requiring EUCS certification by a fixed date is unenforceable against a provider who cannot obtain one.
- Do write it in as a forward commitment. A clause obliging the provider to obtain certification within a defined window of the scheme becoming operational costs you nothing now and avoids a renegotiation later.
- Use what is auditable today. ISO/IEC 27001 with ISO/IEC 27017 and 27018, SOC 2 Type II, or the provider’s national scheme — and, per the Dutch authority’s own advice to prospective applicants, engage a licensed conformity assessment body early rather than waiting for the scheme to land [7].
Three further schemes sit behind EUCS in the queue: 5G, digital identity wallets, and managed security services [9]. The last of these matters to any entity that outsources its SOC, since MSSPs are themselves in NIS2 scope.
The One Mechanism That Could Make Certification Mandatory — and Its Clock
Article 24(2) is the trigger, and it is more constrained than most commentary suggests. It empowers the Commission to adopt delegated acts “specifying which categories of essential and important entities are to be required to use certain certified ICT products, ICT services and ICT processes or obtain a certificate under a European cybersecurity certification scheme” [1]. That final clause is the only place in the Directive where an entity-level certificate can become compulsory.
Four conditions gate it, and all four are in the text:
- A relevant scheme must exist. The requirement attaches to a scheme adopted under Article 49 of Regulation (EU) 2019/881. Where no appropriate scheme is available, Article 24(3) provides that the Commission may ask ENISA to prepare a candidate scheme, after consulting the Cooperation Group and the European Cybersecurity Certification Group [1] — which is the position for every sector outside ICT products today.
- A cybersecurity deficiency must be identified. The delegated acts “shall be adopted where insufficient levels of cybersecurity have been identified”, and must include an implementation period [1].
- Impact assessment and consultation must happen first. The Commission must carry out an impact assessment and consult in accordance with Article 56 of the Cybersecurity Act [1], which itself obliges the Commission to keep assessing “whether a specific European cybersecurity certification scheme is to be made mandatory” at least every two years [4].
- Parliament and Council can stop it. A delegated act under Article 24(2) “shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification”, extendable at either institution’s request [2].
The delegation itself has an expiry date that almost nobody cites. Article 38 confers the Article 24(2) power on the Commission “for a period of five years from 16 January 2023” [2]. As of August 2026, no delegated act under Article 24(2) has been adopted. Even in the fastest realistic sequence — scheme adoption, deficiency finding, impact assessment, consultation, adoption, two-month scrutiny, then the implementation period the act must itself contain — a mandatory certificate is years, not months, away for any category of entity. Planning your compliance programme around one arriving is planning around the wrong risk.
What a Certificate Actually Buys You Under Enforcement
Here is the honest version, and it is neither “certification is pointless” nor “ISO 27001 makes you compliant”.
Certification has one explicit, textual effect in NIS2 enforcement. Article 32(7) obliges competent authorities, when taking enforcement measures, to “take due account of” eight factors, of which (g) is “any adherence to approved codes of conduct or approved certification mechanisms” [3]. That is a mitigation factor in a sanctioning decision — genuinely valuable, and one of the few factors on that list an entity can build in advance rather than react to. It is not a defence to non-compliance, and it does not shift the burden. Note the symmetry, too: Article 32(5)(a) lets authorities suspend a certification held by an essential entity as an enforcement measure in its own right [3].
What certification does not do is close out the evidence obligations. The BSI, as a national competent authority, is unusually direct: “Eine Unternehmenszertifizierung alleine ist nicht ausreichend, um sämtliche Anforderungen des BSIG zu erfüllen” — a company certification alone is not sufficient to meet all statutory requirements. ISO 27001 “kann ein Baustein” — can be one building block — alongside internal documentation, training records, audit reports and internal control procedures [8]. German KRITIS operators are the exception that proves the rule: they must submit security audits, inspections or certifications without being asked, on a cycle that moved from two years to three under the NIS-2-Umsetzungsgesetz [8].
The gaps are specific enough to name. Commission Implementing Regulation (EU) 2024/2690 sets out roughly 150 technical requirements, binding on eleven categories of digital service provider — including cloud, data centre, CDN, DNS, managed service and managed security service providers — but not on manufacturers or most other in-scope sectors, which remain governed by national transposition of Article 21 [10]. Mapped against ISO/IEC 27001:2022 Annex A by OpenKRITIS, several CIR requirements have no equivalent control at all [11]:
| CIR 2024/2690 requirement | ISO/IEC 27001:2022 Annex A equivalent | What you have to add |
|---|---|---|
| 1.2.3 — direct reporting line for the security function | None mapped | A documented, unbroken reporting line to the management body |
| 4.3.1–4.3.4 — crisis management | Partial to none | Crisis process distinct from BCP/DR, with roles and escalation |
| 10.2.2 — background verification criteria | None mapped | Written criteria for screening, not just a screening policy |
| 11.5.3 — shared identities | None mapped | Explicit register and justification for every shared account |
OpenKRITIS’s own conclusion is the right framing: “existing ISMS and certifications will need to be extended for these gaps” [11]. A certificate is a strong starting position and a good sanctioning-stage argument. It is not a finish line. If you are weighing the investment, we have costed it out in our ISO 27001 business case for NIS2-compliant organisations, and set out who may legitimately assess you in our guide to what counts as a qualified auditor under NIS2.
What to Do Now, by Role
| Role | Decision to make in the next quarter |
|---|---|
| CISO / IT security manager | Treat EUCC as a procurement filter for security-critical components, not a programme goal. Run your ISMS against the CIR control set, not the ISO Annex A list, and close the four gaps above explicitly |
| Compliance officer / legal | Stop tracking “NIS2 certification” as a deliverable. Track two things instead: your Member State’s use of the Article 24(1) power, and any Article 24(2) delegated act notified to Parliament and Council |
| Procurement / vendor management | Ask cloud providers for their EUCS readiness plan and a forward commitment clause. Ask hardware vendors for EUCC certificates and the assurance level, not just the fact of certification |
| Board / C-suite | Approve certification on the business case — tender eligibility, customer requirements, Article 32(7)(g) mitigation — not on a belief that it discharges the obligation. It does not |
What Changes Next: CSA2
The Commission proposed a revised Cybersecurity Act on 20 January 2026. It would impose binding timelines on scheme development — twelve months from a Commission request — and add a “cyber posture” scheme aimed at entities operating across several Member States meeting their NIS2 obligations: the first EU scheme designed around an organisation rather than a product [13]. Two caveats belong with that. Schemes would still “only address technical risks and remain voluntary unless mandatory under EU or national law” [13], and a proposal is not law. Adoption is expected no earlier than late 2026, with a transition period after.
Frequently Asked Questions
Is there a NIS2 certificate my company can obtain?
Not at EU level. No European cybersecurity certification scheme certifies an organisation’s compliance with NIS2, and the BSI states plainly that no general certificate for demonstrating the requirements exists [8]. Some Member States have built national schemes that serve this function domestically — Belgium’s CyberFundamentals is the best-known, covered in our guide to the CCB’s three-tier CyberFundamentals scheme.
Does ISO 27001 make us NIS2 compliant?
No, and no competent authority treats it that way. It covers a large share of the Article 21 measures, counts as evidence, and is an express mitigating factor under Article 32(7)(g) [3]. It leaves named gaps — crisis management, security-function reporting lines, background-verification criteria, shared-identity governance — and it cannot satisfy the registration and incident-notification duties at all [8][11].
Can we be forced to certify later?
Yes, through an Article 24(2) delegated act, but only once a relevant scheme exists, a cybersecurity deficiency has been identified, an impact assessment and consultation are complete, and Parliament and Council have not objected within two months [1][2]. None of this has happened.
Should we wait for EUCS before certifying our cloud estate?
No. EUCS has been in political deadlock over sovereignty conditions since 2022, no adoption date is fixed, and the Dutch authority confirms no certificates are being issued [7][17]. Certify against what exists and write forward commitments into contracts.
The Practical Position
NIS2 was drafted to plug into the Cybersecurity Act’s certification framework, and the connection has never been switched on. Article 24(1) is a Member State option about procurement; Article 24(2) is a dormant power on a delegation clock that started in January 2023 [1][2].
So “what NIS2 certification should we get?” has no product-shaped answer, and pursuing one is how organisations end up holding a certificate and an enforcement gap at the same time. Build the evidence base the CIR and your national transposition actually require, certify where it earns its cost in tender eligibility and Article 32(7)(g) mitigation, and track two things quietly: your Member State’s use of Article 24(1), and any delegated act notified under Article 24(2). Both would arrive with an implementation period. Neither will arrive as a surprise.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS 2 Directive, Article 24 — Use of European cybersecurity certification schemes
- NIS 2 Directive, Article 38 — Exercise of the delegation
- NIS 2 Directive, Article 32 — Supervisory and enforcement measures
- Regulation (EU) 2019/881, Article 56 — Cybersecurity certification (full text)
- ENISA — EUCC Certification Scheme (linked above)
- ENISA — Cybersecurity Act, EU regulatory context
- Dutch National Cybersecurity Certification Authority — Cloud Services (EUCS) (linked above)
- BSI — Allgemeine FAQ zu NIS-2 (linked above)
- European Parliamentary Research Service — Cybersecurity Act review: What to expect
- Hunton Andrews Kurth — CIR 2024/2690 scope and entry into force
- OpenKRITIS — NIS2 Implementing Act (EU) 2024/2690 mapped to ISO/IEC 27001:2022
- QIMA — Mapping EUCC to Common Criteria: assurance levels and evaluation requirements
- Cullen International — Revised Cybersecurity Act (CSA2): changes to the certification framework
- EUR-Lex — Directive (EU) 2022/2555 (NIS2), consolidated text
- EUR-Lex — Commission Implementing Regulation (EU) 2024/482 (EUCC)
- EUR-Lex — Regulation (EU) 2019/881 (Cybersecurity Act)
- EUISS — Technical is political: when a cloud certification scheme divides Europe
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
