
ENISA has published an update to its report on the cybersecurity assessments market. This new edition covers the 2021–2025 period.
The Cybersecurity Assessments report aims to present the current state of play of cybersecurity assessments of Information and Communications Technology (ICT) products, cloud services, Information Security Management Systems (ISMS), and managed security services (MSS) along with the conformity assessment bodies involved with such schemes.
The present version is an update from the initial report published in January 2024. Some frameworks have been removed from the study due to lack of data or irrelevance.
The two major changes are the introduction of data regarding the first EU cybersecurity certification scheme, EUCC, and the inclusion of a new category of ICT solutions: managed security services. The type of MSSs included in the report is based on the definition and examples of activities provided in the targeted amendment of the Cybersecurity Act giving the mandate to ENISA to develop certification schemes for such activities.
To mark the publication of this report, the certification unit invites you to a session providing an update on the development of the cybersecurity certification scheme and an overview of market dynamics in the cybersecurity assessment sector.
Join us on Thursday, September 10, for a webinar dedicated to the latest developments in certification work and a presentation of the report's key findings.
- Publication date
- 10 August 2026
- Author
- European Union Agency for Cybersecurity

