Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

Certification programmes

What the Agency certifies

Each programme is governed by a published standard and bounded by a scope agreed before the assessment begins. An organisation may hold certification under more than one programme, at different levels.

EDCA-P01

Startup Security Certification

An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.

SRSV EDCA-STD-01
Requirements, scope and evidence →
EDCA-P02

Software Product Certification

An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.

SVACTT EDCA-STD-03
Requirements, scope and evidence →
EDCA-P03

Data Protection Certification

An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.

SVACTT EDCA-STD-02
Requirements, scope and evidence →
EDCA-P04

Cloud Security Certification

An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.

SVACTT EDCA-STD-04
Requirements, scope and evidence →
EDCA-P05

AI Governance Certification

An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.

SVACTT EDCA-STD-05
Requirements, scope and evidence →
EDCA-P06

Crypto-Asset Service Certification

An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.

SVACTT EDCA-STD-07
Requirements, scope and evidence →
EDCA-P07

Payment Services Security Certification

An assessment of an organisation that initiates, processes or settles payments. It examines how a payment order is authenticated, whether client funds are protected and can be reconciled, how merchants are settled, and what happens when a payment is refunded, reversed or disputed.

SVACTT EDCA-STD-08
Requirements, scope and evidence →
EDCA-P08

AML/CFT Programme Certification

An assessment of the quality of an anti-money-laundering and counter-terrorist-financing programme — and, where the organisation supplies screening tooling to others, of the methodology behind that tooling. It asks whether the risk methodology is defensible, whether the lists are current, and whether alerts are worked rather than merely raised.

SVACTT EDCA-STD-09
Requirements, scope and evidence →
EDCA-P09

Remote Identity Proofing Certification

An assessment of a service that establishes a person's identity without meeting them. It examines how identity evidence is captured and checked for authenticity, how the applicant is bound to that evidence, when a human reviews the decision, and what record survives to show why the decision was taken.

SVACTT EDCA-STD-10
Requirements, scope and evidence →
EDCA-P10

Operational Resilience Certification

An assessment of an organisation whose failure would be felt by its customers rather than only by itself. It examines dependency mapping, recovery capability actually demonstrated rather than merely stated, testing, concentration risk, and the information a customer needs in order to oversee the organisation as a supplier.

SVACTT EDCA-STD-06
Requirements, scope and evidence →

Comparison

Programmes at a glance

CodeProgrammeGoverning standard Levels availableTypical duration
EDCA-P01 Startup Security Certification EDCA-STD-01 SR · SV Six to ten weeks from application to decision.
EDCA-P02 Software Product Certification EDCA-STD-03 SV · AC · TT Eight to fourteen weeks from application to decision.
EDCA-P03 Data Protection Certification EDCA-STD-02 SV · AC · TT Eight to twelve weeks from application to decision.
EDCA-P04 Cloud Security Certification EDCA-STD-04 SV · AC · TT Eight to twelve weeks from application to decision.
EDCA-P05 AI Governance Certification EDCA-STD-05 SV · AC · TT Ten to sixteen weeks from application to decision.
EDCA-P06 Crypto-Asset Service Certification EDCA-STD-07 SV · AC · TT Ten to sixteen weeks from application to decision.
EDCA-P07 Payment Services Security Certification EDCA-STD-08 SV · AC · TT Ten to sixteen weeks from application to decision.
EDCA-P08 AML/CFT Programme Certification EDCA-STD-09 SV · AC · TT Ten to sixteen weeks from application to decision.
EDCA-P09 Remote Identity Proofing Certification EDCA-STD-10 SV · AC · TT Twelve to eighteen weeks from application to decision.
EDCA-P10 Operational Resilience Certification EDCA-STD-06 SV · AC · TT Eight to fourteen weeks from application to decision.

Level codes: SR — Startup Ready · SV — Security Verified · AC — Advanced Compliance · TT — Trusted Technology. Level requirements →