<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Certification on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/certification/</link><description>Recent content in Certification on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/certification/index.xml" rel="self" type="application/rss+xml"/><item><title>EU Cloud Services Scheme (EUCS)</title><link>https://lesitedefrancois.be/en/compliance/eucs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eucs/</guid><description>&lt;p&gt;The &lt;strong&gt;European Cybersecurity Certification Scheme for Cloud Services (EUCS)&lt;/strong&gt; is a certification framework being developed under the 2019 EU Cybersecurity Act (CSA), led by ENISA. It is &lt;strong&gt;not yet adopted&lt;/strong&gt; — the scheme has been in drafting since 2020 and remains stalled as of mid-2026 due to unresolved political disagreements over digital sovereignty requirements. EUCS is designed as an EU-wide, &lt;strong&gt;voluntary&lt;/strong&gt; certification that would harmonize the fragmented national cloud certifications (such as France&amp;rsquo;s SecNumCloud or Germany&amp;rsquo;s C5) into three assurance levels: basic, substantial, and high. It applies to cloud service providers offering IaaS, PaaS, or SaaS on the European market. While EUCS is technically voluntary, its practical impact will be significant because the NIS2 Directive allows Member States to require entities in essential and important sectors to use only EUCS-certified cloud services. The core political controversy centers on whether the &amp;ldquo;high&amp;rdquo; assurance level should include sovereignty requirements — mandating EU headquarters, EU-only data processing, and immunity from non-EU extraterritorial laws (e.g. the US CLOUD Act). A March 2024 draft removed these requirements to achieve technical consensus, but the proposed recast of the Cybersecurity Act (CSA2), tabled in January 2026, would reinstate a formal sovereignty tier, with France leading advocacy for its inclusion.&lt;/p&gt;</description></item><item><title>EU Cybersecurity Act (CSA)</title><link>https://lesitedefrancois.be/en/compliance/eu-csa/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eu-csa/</guid><description>&lt;p&gt;The &lt;strong&gt;EU Cybersecurity Act (CSA)&lt;/strong&gt; — Regulation (EU) 2019/881 — was adopted by the European Council in April 2019 and fully entered into force on 28 June 2021. It is a European regulation (directly applicable in all Member States without transposition) that serves two primary functions: it strengthened and made permanent the mandate of ENISA (the EU Agency for Cybersecurity), and it established a &lt;strong&gt;voluntary EU-wide cybersecurity certification framework&lt;/strong&gt; for ICT products, services, and processes. The CSA is not itself a certification scheme but rather the legal foundation upon which specific schemes are built — currently EUCC (adopted January 2024), EUCS (cloud, under development), EU5G (5G networks, under development), EUDI Wallets, and EUMSS (managed security services). Each scheme defines assurance levels (basic, substantial, high), evaluation methodologies, and mutual recognition rules so that a certificate issued in one Member State is valid across the entire EU. The CSA applies to any entity — manufacturer, service provider, or operator — that voluntarily seeks EU cybersecurity certification for its offerings, though sector-specific regulations (NIS2, CRA, DORA) may make certification effectively mandatory for certain use cases. A &lt;strong&gt;recast of the CSA (CSA2)&lt;/strong&gt; was proposed by the European Commission on 20 January 2026, aiming to strengthen certification mandates, reinstate sovereignty requirements in cloud certification, and reinforce ENISA&amp;rsquo;s supervisory role.&lt;/p&gt;</description></item><item><title>EU5G Certification Scheme</title><link>https://lesitedefrancois.be/en/compliance/eu5g/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eu5g/</guid><description>&lt;p&gt;The &lt;strong&gt;EU5G cybersecurity certification scheme&lt;/strong&gt; is a certification framework being developed under the EU Cybersecurity Act (Regulation 2019/881), intended to provide harmonized security assurance for 5G network products and components across the European Union. ENISA established an Ad Hoc Working Group (AHWG) on EU5G in Q4 2021 following a European Commission request. As of mid-2026, the scheme &lt;strong&gt;has not been formally adopted&lt;/strong&gt; and no complete public draft is available — making it the least mature of the three schemes requested under the CSA (after EUCC, adopted in January 2024, and EUCS, still stalled). Current work has focused on specific components: in June 2024, ENISA launched a public consultation on technical specifications for eUICC (embedded Universal Integrated Circuit Card) certification, which will be handled under the existing EUCC framework rather than a new standalone scheme. A broader EU NESAS scheme for 5G network products is under development, leveraging the existing GSMA NESAS/3GPP SCAS methodology. The scheme is expected to be &lt;strong&gt;voluntary&lt;/strong&gt; once adopted, with assurance levels aligned to the CSA&amp;rsquo;s basic/substantial/high structure. Its practical significance will be shaped by the revised Cybersecurity Act (CSA2), proposed in January 2026, which strengthens ENISA&amp;rsquo;s mandate and may provide additional impetus for adoption.&lt;/p&gt;</description></item><item><title>EUCC (EU Common Criteria)</title><link>https://lesitedefrancois.be/en/compliance/eucc/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eucc/</guid><description>&lt;p&gt;The &lt;strong&gt;European Common Criteria-based cybersecurity certification scheme (EUCC)&lt;/strong&gt; is the first certification scheme formally adopted under the EU Cybersecurity Act (Regulation 2019/881). The European Commission published the implementing regulation on 31 January 2024, and an amendment (Regulation 2024/3144) followed in December 2024 to clarify applicable ISO/IEC 15408 standard versions and transition rules. EUCC is managed by ENISA and builds on the existing SOG-IS Mutual Recognition Agreement that was already used by 17 EU Member States, effectively replacing those national Common Criteria schemes with a single EU-wide framework. It applies to &lt;strong&gt;ICT products&lt;/strong&gt; — hardware, software, and embedded components — and evaluates their cybersecurity properties through accredited Conformity Assessment Bodies (CABs). The scheme offers two assurance levels: &amp;ldquo;substantial&amp;rdquo; (based on AVA_VAN levels 1–2) and &amp;ldquo;high&amp;rdquo; (AVA_VAN levels 3–5). Certification is &lt;strong&gt;voluntary&lt;/strong&gt; — there is no legal obligation to certify ICT products under EUCC — but it provides market-recognized evidence of security properties and is expected to be referenced by procurement requirements and sector-specific legislation (e.g. medical devices, smart metering). EUCC certificates are recognized uniformly across the entire EU, eliminating the need for country-by-country certification.&lt;/p&gt;</description></item><item><title>ISO/IEC 27001</title><link>https://lesitedefrancois.be/en/compliance/iso-27001/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/iso-27001/</guid><description>&lt;p&gt;&lt;strong&gt;ISO/IEC 27001&lt;/strong&gt; is the world&amp;rsquo;s most widely recognized standard for Information Security Management Systems (ISMS). It is published jointly by &lt;strong&gt;ISO&lt;/strong&gt; (International Organization for Standardization) and &lt;strong&gt;IEC&lt;/strong&gt; (International Electrotechnical Commission) — making it a truly international standard, not tied to any single country or jurisdiction. The current version is &lt;strong&gt;ISO/IEC 27001:2022&lt;/strong&gt;, which replaced the 2013 edition and restructured its Annex A controls to align with the updated ISO/IEC 27002:2022 guidance (93 controls organized in 4 themes: Organizational, People, Physical, Technological). The standard specifies &lt;strong&gt;requirements&lt;/strong&gt; (clauses 4–10) for establishing, implementing, maintaining, and continually improving an ISMS — covering context analysis, leadership commitment, risk assessment, treatment planning, operational controls, performance evaluation, and continuous improvement. Certification is &lt;strong&gt;voluntary&lt;/strong&gt; but has become a global market expectation: ISO 27001 certification is required by countless procurement policies, regulatory frameworks (NIS2 references it, ENS aligns with it, E-ITS accepts it as equivalent, BSI IT-Grundschutz enables ISO 27001 certification), and customer contracts. Certification is issued by accredited certification bodies (accredited under ISO/IEC 17021) following a two-stage audit process, valid for &lt;strong&gt;3 years&lt;/strong&gt; with annual surveillance audits. Over 70,000 organizations worldwide hold ISO 27001 certification. Unlike prescriptive frameworks (DISA STIG, CIS Benchmarks), ISO 27001 is &lt;strong&gt;risk-based and outcome-oriented&lt;/strong&gt; — it specifies what must be achieved but not how, allowing organizations to tailor implementations to their context.&lt;/p&gt;</description></item></channel></rss>