
Today, ENISA is publishing the first draft of the European Cybersecurity Certification Scheme for Managed Security Services for public consultation. The publication marks a key milestone in the work initiated following the European Commission’s formal request of 25 April 2025 for ENISA to prepare a candidate scheme under Article 48(1) of the Cybersecurity Act.
ENISA formally replied to the Commission on 23 June 2025, confirming its readiness to begin developing the scheme and proposing a layered approach combining common horizontal requirements with service-specific profiles. The draft published today reflects this approach and initially focuses on the Incident Response Service Profile, while providing a structure that can be extended progressively to other Managed Security Services.
A close up to the draft scheme
The draft of the EUMSS scheme builds, where appropriate, on existing European cybersecurity certification practices and assessment methodologies.
Overall, the scheme follows a layered approach, consisting of a horizontal and a vertical layer.
The horizontal layer outlines a common set of baseline requirements applicable to all Managed Security Services to be certified under this Scheme. These baseline requirements apply as a mandatory prerequisite for each certified service profile, are the same for all three established assurance levels (i.e. 'basic', 'substantial', and 'high') and cover the following domains:
- Secure service and platform design;
- Deployment and transition management;
- Availability and continuity management;
- Operational service management;
- Continuous improvement and technology maintenance.
The vertical layer defines service-specific requirements applicable to particular Managed Security Services and services profiles included in these services. The present version of the scheme focuses on the Incident Management Lifecycle vertical and more specifically to the Incident Response service profile.
Take part in the public consultation and share your feedback via the survey published until 13th of September 2026.
Reinforcing trust in the EU Cybersecurity Reserve
The development of the scheme can further support the EU Cybersecurity Reserve, as providers delivering services under the umbrella of the EU Cybersecurity Reserve shall be certified in accordance with that scheme within 2 years from the date of application once the scheme is in place. The draft scheme is designed to provide a harmonised and proportionate framework that supports cross-border service provision and Union-level crisis response capabilities.
The context behind the development of the scheme
The European Commission has requested ENISA to prepare a candidate European cybersecurity certification scheme for Managed Security Services (MSS) pursuant to Article 48(1) of the Cybersecurity Act. ENISA established an Ad Hoc Working Group on Managed Security Services Certification (EUMSS AHWG) to support the preparation of the candidate scheme, which kicked-off its work on October 2025. The document currently under public consultation is the first version of the result of the work of ENISA with the support the EUMSS AHWG.
- Publication date
- 24 July 2026
- Author
- European Union Agency for Cybersecurity
- Certification Scheme
- EUMSS
- Managed Security Services
- Incident Response
