The EU Cybersecurity Act (CSA) — Regulation (EU) 2019/881 — was adopted by the European Council in April 2019 and fully entered into force on 28 June 2021. It is a European regulation (directly applicable in all Member States without transposition) that serves two primary functions: it strengthened and made permanent the mandate of ENISA (the EU Agency for Cybersecurity), and it established a voluntary EU-wide cybersecurity certification framework for ICT products, services, and processes. The CSA is not itself a certification scheme but rather the legal foundation upon which specific schemes are built — currently EUCC (adopted January 2024), EUCS (cloud, under development), EU5G (5G networks, under development), EUDI Wallets, and EUMSS (managed security services). Each scheme defines assurance levels (basic, substantial, high), evaluation methodologies, and mutual recognition rules so that a certificate issued in one Member State is valid across the entire EU. The CSA applies to any entity — manufacturer, service provider, or operator — that voluntarily seeks EU cybersecurity certification for its offerings, though sector-specific regulations (NIS2, CRA, DORA) may make certification effectively mandatory for certain use cases. A recast of the CSA (CSA2) was proposed by the European Commission on 20 January 2026, aiming to strengthen certification mandates, reinstate sovereignty requirements in cloud certification, and reinforce ENISA’s supervisory role.
Red Hat is both a direct and indirect stakeholder of the CSA framework. As a manufacturer of ICT products (RHEL, OpenShift, Ansible) that could seek EUCC certification, and as a platform underlying cloud services that may require EUCS certification, Red Hat’s product security practices are designed to align with the evaluation requirements that CSA schemes define. More broadly, Red Hat actively participates in the standardization process that underpins CSA schemes: through the Eclipse Open Regulatory Compliance Working Group, OpenSSF, and direct engagement with ENISA working groups, Red Hat helps ensure that certification standards reflect the open source development model — where security is achieved through transparent, community-auditable processes rather than proprietary black-box evaluations. Red Hat’s secure development lifecycle, SBOM generation, Sigstore-based signing, and CSAF/VEX advisory infrastructure provide the machine-readable evidence artifacts that CSA certification schemes are increasingly designed to consume. For customers, this means that deploying Red Hat software provides a foundation aligned with the CSA’s vision of provable, certified security — whether or not a formal scheme certificate is pursued.
