
EU Cybersecurity Certification Scheme on Common Criteria (EUCC)
Trusted EU-wide cybersecurity certification for ICT products

EU Cybersecurity Certification Scheme on Common Criteria (EUCC)
Trusted EU-wide cybersecurity certification for ICT products
EU Cybersecurity Certification Scheme on Common Criteria (EUCC)
What is EUCC Certification?
The EU Common Criteria Certification (EUCC) scheme, established under the products, services, and processes across the European Union. This scheme is based on Common Criteria (ISO/IEC 15408) and Common Evaluation Methodology (ISO/IEC 18045) and ensures robust security, fosters trust, and facilitates the free movement of certified products within the EU.
DEKRA is a Conformity Assessment Body (CAB) consisting in an accredited Certification Body (CB) and Information Technology Security Evaluation Facility (ITSEF) operating under the EUCC scheme at substantial assurance level.
Our Services
The EUCC CAB provides certification for ICT products under the EUCC scheme, covering a wide range of products such as software, network devices, smart cards, and hardware devices. Focused on a "Substantial level" (AVA_VAN.3) of security, DEKRA offers the following services:
ICT Product Certification
Assurance Continuity
Surveillance and Monitoring Activities
Conformity and Compliance
EUCC Vulnerability Management and Disclosure
In addition to initial certification, DEKRA offers full coverage of the certification lifecycle including certificate’s maintenance and monitoring services (each 2 years), which help to maintain the validity of the certificate throughout the product lifecycle. These services include re-assessment, maintenance, patch management, and certificate review.
Whilst DEKRA has its own laboratory to perform the evaluation activity, this labor can be externalized to another laboratory through legally binding agreements. Subcontractors (ITSEFs), must be independent, ISO/IEC 17025 accredited, and adhere to EUCC requirement. The CB oversees subcontractor activities via a Technical Manager, who monitors qualifications, collects records of assessments, addresses non-conformities, and ensures compliance with operational procedures.