The European Common Criteria-based cybersecurity certification scheme (EUCC) is the first certification scheme formally adopted under the EU Cybersecurity Act (Regulation 2019/881). The European Commission published the implementing regulation on 31 January 2024, and an amendment (Regulation 2024/3144) followed in December 2024 to clarify applicable ISO/IEC 15408 standard versions and transition rules. EUCC is managed by ENISA and builds on the existing SOG-IS Mutual Recognition Agreement that was already used by 17 EU Member States, effectively replacing those national Common Criteria schemes with a single EU-wide framework. It applies to ICT products — hardware, software, and embedded components — and evaluates their cybersecurity properties through accredited Conformity Assessment Bodies (CABs). The scheme offers two assurance levels: “substantial” (based on AVA_VAN levels 1–2) and “high” (AVA_VAN levels 3–5). Certification is voluntary — there is no legal obligation to certify ICT products under EUCC — but it provides market-recognized evidence of security properties and is expected to be referenced by procurement requirements and sector-specific legislation (e.g. medical devices, smart metering). EUCC certificates are recognized uniformly across the entire EU, eliminating the need for country-by-country certification.
Red Hat’s software portfolio is eligible for EUCC certification where customers or market requirements demand formal Common Criteria evaluation. Historically, Red Hat Enterprise Linux has maintained Common Criteria certifications under national schemes — RHEL has been evaluated against protection profiles such as the NIAP Operating System Protection Profile (OSPP) — and these evaluations can transition into the EUCC framework as the new scheme supersedes SOG-IS certificates. The practical relevance for Red Hat is twofold: first, RHEL and OpenShift provide the evaluated operating system and platform layer upon which customers build their own EUCC-certifiable products (the certification of a higher-level product often depends on the evaluated security properties of its OS); second, Red Hat’s security architecture — SELinux mandatory access control, FIPS 140-3 validated cryptographic modules, measured boot, and secure supply chain — maps directly to the security functional requirements (SFRs) that Common Criteria evaluations test. As EUCC matures and CABs issue certificates at scale (first certificates issued since early 2025), organizations requiring formal product assurance evidence can leverage Red Hat’s existing evaluation artifacts and align them with the EU-wide scheme.
