Proponents of a centralised certification model argue that harmonisation eliminates the risk of a "race to the bottom" among Member States, provides businesses with a single, predictable compliance pathway, and creates economies of scale in certification infrastructure. This is particularly important as EU cybersecurity certification expands beyond products to cover services, processes and organisational security posture. A common framework also facilitates mutual recognition of certified solutions across borders, reducing duplication and enabling the Digital Single Market to function more effectively.
This centralised approach is already visible in practice through EU‑level cybersecurity certification schemes, most notably the EU cybersecurity certification scheme (EUCC). EUCC is one of the first concrete implementations of the Cybersecurity Act and serves as a key reference point for how certification may evolve under CSA 2.0, illustrating a model anchored in harmonised, technically defined assessment criteria.
EUCC provides a single, harmonised certification framework for ICT products across the EU, based on a common set of technical security requirements and evaluation methodologies derived from the Common Criteria standard.
Instead of navigating multiple national schemes with different scopes, assurance levels and interpretations, a vendor can have a product certified once under EUCC, with the resulting certificate recognised by all Member States. Certification is carried out by accredited conformity assessment bodies, under a common set of EU‑wide rules and oversight.
A defining feature of EUCC is its risk‑based assurance level structure, which allows certification efforts to be proportionate to the product’s criticality and threat exposure. Lower‑risk products can be assessed with lighter requirements, while products used in sensitive or high‑risk contexts can be certified against more stringent assurance levels.
This ensures that the scheme remains scalable for industry while maintaining technical credibility for regulators and customers alike.
In this way, EUCC illustrates how a centralised EU‑level scheme, based on clearly defined and technically oriented security criteria, can reduce fragmentation, enhance trust in certified solutions, and provide a practical and repeatable model for future EU cybersecurity certification schemes.