European Digital Certification Agency
Independent Certification for Secure and Trusted Technology
Building Trust in European Technology
The Agency assesses IT startups, digital products and technology companies against defined requirements for cybersecurity, data protection, operational reliability and responsible technology management.
Verify a certificate
Enter a certificate number to confirm its holder, scope and current status in the public register.
Every certificate carries a QR code linking to its entry in the register.
The Agency
An assessment, not an endorsement
The European Digital Certification Agency is an independent certification organisation established in 2023 and registered in Republic of Estonia. It examines how technology companies actually manage security, personal data, service continuity and the systems they build — and states what it found, in writing, against a published standard.
Certification is not a marketing exercise. An assessment establishes what an organisation does, evidences it, and identifies where it falls short. Where requirements are not met, the Agency says so and the certificate is not issued until they are.
More about the Agency, its governance and its independence rules →
Why organisations certify
- Shorten enterprise security reviews. A certificate with a published scope answers most of a customer's due diligence questionnaire before it is sent.
- Give investors evidence, not assurances. Technical due diligence is faster when controls have already been examined by a third party.
- Find weaknesses while they are cheap. The preliminary assessment identifies gaps before an audit, and long before an incident.
- Meet contractual and procurement requirements. Many buyers require documented, independently verified security controls from suppliers.
- Demonstrate data protection compliance. Assessment against EDCA-STD-02 covers the accountability obligations of Regulation (EU) 2016/679.
- Show status publicly and verifiably. Every certificate is listed in an open register that any third party can check.
Certification programmes
Ten programmes, each governed by a published standard
An organisation may hold certification under more than one programme. Each assessment is bounded by a scope agreed in writing before it begins.
Startup Security Certification
An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.
Programme details → EDCA-P02 · EDCA-STD-03Software Product Certification
An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.
Programme details → EDCA-P03 · EDCA-STD-02Data Protection Certification
An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.
Programme details → EDCA-P04 · EDCA-STD-04Cloud Security Certification
An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.
Programme details → EDCA-P05 · EDCA-STD-05AI Governance Certification
An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.
Programme details → EDCA-P06 · EDCA-STD-07Crypto-Asset Service Certification
An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.
Programme details → EDCA-P07 · EDCA-STD-08Payment Services Security Certification
An assessment of an organisation that initiates, processes or settles payments. It examines how a payment order is authenticated, whether client funds are protected and can be reconciled, how merchants are settled, and what happens when a payment is refunded, reversed or disputed.
Programme details → EDCA-P08 · EDCA-STD-09AML/CFT Programme Certification
An assessment of the quality of an anti-money-laundering and counter-terrorist-financing programme — and, where the organisation supplies screening tooling to others, of the methodology behind that tooling. It asks whether the risk methodology is defensible, whether the lists are current, and whether alerts are worked rather than merely raised.
Programme details → EDCA-P09 · EDCA-STD-10Remote Identity Proofing Certification
An assessment of a service that establishes a person's identity without meeting them. It examines how identity evidence is captured and checked for authenticity, how the applicant is bound to that evidence, when a human reviews the decision, and what record survives to show why the decision was taken.
Programme details → EDCA-P10 · EDCA-STD-06Operational Resilience Certification
An assessment of an organisation whose failure would be felt by its customers rather than only by itself. It examines dependency mapping, recovery capability actually demonstrated rather than merely stated, testing, concentration risk, and the information a customer needs in order to oversee the organisation as a supplier.
Programme details →Not sure which applies?
Describe what you build and where your data sits. The Agency will confirm the appropriate programme and level, at no cost and with no commitment.
Ask the Agency →Certification levels
Four levels, from first controls to sustained assurance
The level reflects the depth of the assessment and the maturity evidenced, not the size of the organisation. It is recorded in the certificate number itself.
EDCA Startup Ready
Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.
Valid 24 monthsEDCA Security Verified
Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.
Valid 24 monthsEDCA Advanced Compliance
Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.
Valid 36 monthsEDCA Trusted Technology
The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.
Valid 36 monthsFor startups
Proportionate to your stage
A twelve-person company is not assessed as though it were a bank. The EDCA Startup Ready level exists so that an early-stage team can evidence the controls that matter to its first enterprise customers, without pretending to a maturity it has not yet built.
The process in outline
- Application and scope review
- Preliminary assessment and gap analysis
- Certification audit
- Corrective action
- Decision by the Certification Committee
- Issue of certificate and publication in the register