Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

About the Agency

An independent body for the assessment of digital technology

The Agency exists to answer one question on behalf of customers, investors and partners: does this organisation manage its technology and its data responsibly, and can that be evidenced?

Mission

The European Digital Certification Agency assesses IT startups, digital products and technology companies against defined requirements for cybersecurity, data protection, operational reliability and responsible technology management.

Its purpose is practical. A buyer evaluating a supplier, an investor conducting technical due diligence, or a partner about to connect systems all need the same thing: a competent, disinterested examination of controls that actually exist, expressed in terms they can rely on. Producing that examination — and publishing its result in a register anyone can check — is what the Agency does.

The Agency was established in 2023 and is registered in Republic of Estonia under registration number 16842197. Its registered office is at Narva mnt 5, 10117 Tallinn, Estonia.

Principles of independence

Certification is worth exactly as much as the independence of the body issuing it. The following rules govern the Agency's conduct and are enforceable through the Impartiality Panel.

Independence
The Agency does not provide consultancy, remediation or implementation services to organisations it assesses, and does not accept payment contingent on the outcome of an assessment. Assessment fees are fixed before the assessment begins and are payable whatever the decision.
Separation of assessment and decision
The team that performs an assessment does not decide its outcome. Certification decisions are taken by the Certification Committee on the basis of the audit report and the evidence of corrective action.
Evidence over declaration
Above Level I, no requirement is accepted on the basis of a statement alone. Every control within scope is verified against records, configuration or demonstration.
Proportionality
Requirements are applied in proportion to the size of the organisation, the sensitivity of the data it handles and the criticality of the service it provides. A twelve-person company is not assessed as though it were a bank.
Transparency of the scheme
The standards against which organisations are assessed are published in full, together with their version history. Certified organisations and their scope are published in an open register.
Accountability for our own decisions
Every decision is given in writing with reasons, and every applicant has a right of appeal to a panel that did not take the original decision.

Governance and structure

Assessment, decision and oversight are carried out by separate bodies. No individual participates in both the assessment of an organisation and the decision on its certification.

Certification Committee

Takes all certification, suspension and withdrawal decisions. Composed of senior assessors and independent members who have no commercial relationship with the organisation under consideration.

Technical Standards Board

Maintains the EDCA standards, approves new versions and determines the transition period during which a superseded version remains valid for assessments already under way.

Impartiality Panel

Reviews conflicts of interest, complaints about the conduct of assessments, and the Agency's compliance with its own independence rules. Reports separately from the Agency's management.

Appeals Panel

Hears appeals against certification decisions. Convened for each appeal from members who took no part in the decision under appeal.

Assessors

Assessments are carried out by assessors admitted to the Agency's register of approved personnel. Admission requires demonstrated professional experience in information security, data protection or software engineering, evidence of continuing professional development, and successful completion of the Agency's own examination on EDCA-STD-00 and the standard relevant to the programme.

Assessors declare all commercial relationships before being assigned to an assessment. An assessor who has provided consultancy, implementation or advisory services to an organisation within the preceding three years may not take part in its assessment, and may not join the Certification Committee considering it.

Status of the Agency

The Agency is not an EU body

EDCA is an independent certification organisation and is not an institution, agency, or official body of the European Union. It does not act under any mandate from the European Commission or any other EU institution, and its certificates do not constitute EU conformity assessment, CE marking, accreditation under Regulation (EC) No 765/2008, or certification under Article 42 of Regulation (EU) 2016/679.

A certificate issued by the Agency states the Agency's own finding, against the Agency's own published standards, within a defined scope. It is offered on that basis and should be relied upon on that basis. See the legal notice for the full statement.

Complaints and appeals

An applicant may appeal a certification decision within 30 days of receiving it. The appeal is heard by an Appeals Panel convened from members who took no part in the original decision. The appeal is decided within 45 days of receipt and the reasons are given in writing.

Complaints about the conduct of an assessment, the behaviour of an assessor, or the Agency's compliance with its own independence rules are addressed to the Impartiality Panel at official@edca.pro. Third parties may also use this address to report that a certified organisation no longer meets the requirements of its certificate; such reports are investigated and may result in suspension or withdrawal.