Certification programmes
What the Agency certifies
Each programme is governed by a published standard and bounded by a scope agreed before the assessment begins. An organisation may hold certification under more than one programme, at different levels.
Startup Security Certification
An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.
Software Product Certification
An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.
Data Protection Certification
An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.
Cloud Security Certification
An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.
AI Governance Certification
An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.
Crypto-Asset Service Certification
An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.
Payment Services Security Certification
An assessment of an organisation that initiates, processes or settles payments. It examines how a payment order is authenticated, whether client funds are protected and can be reconciled, how merchants are settled, and what happens when a payment is refunded, reversed or disputed.
AML/CFT Programme Certification
An assessment of the quality of an anti-money-laundering and counter-terrorist-financing programme — and, where the organisation supplies screening tooling to others, of the methodology behind that tooling. It asks whether the risk methodology is defensible, whether the lists are current, and whether alerts are worked rather than merely raised.
Remote Identity Proofing Certification
An assessment of a service that establishes a person's identity without meeting them. It examines how identity evidence is captured and checked for authenticity, how the applicant is bound to that evidence, when a human reviews the decision, and what record survives to show why the decision was taken.
Operational Resilience Certification
An assessment of an organisation whose failure would be felt by its customers rather than only by itself. It examines dependency mapping, recovery capability actually demonstrated rather than merely stated, testing, concentration risk, and the information a customer needs in order to oversee the organisation as a supplier.
Comparison
Programmes at a glance
| Code | Programme | Governing standard | Levels available | Typical duration |
|---|---|---|---|---|
| EDCA-P01 | Startup Security Certification | EDCA-STD-01 | SR · SV | Six to ten weeks from application to decision. |
| EDCA-P02 | Software Product Certification | EDCA-STD-03 | SV · AC · TT | Eight to fourteen weeks from application to decision. |
| EDCA-P03 | Data Protection Certification | EDCA-STD-02 | SV · AC · TT | Eight to twelve weeks from application to decision. |
| EDCA-P04 | Cloud Security Certification | EDCA-STD-04 | SV · AC · TT | Eight to twelve weeks from application to decision. |
| EDCA-P05 | AI Governance Certification | EDCA-STD-05 | SV · AC · TT | Ten to sixteen weeks from application to decision. |
| EDCA-P06 | Crypto-Asset Service Certification | EDCA-STD-07 | SV · AC · TT | Ten to sixteen weeks from application to decision. |
| EDCA-P07 | Payment Services Security Certification | EDCA-STD-08 | SV · AC · TT | Ten to sixteen weeks from application to decision. |
| EDCA-P08 | AML/CFT Programme Certification | EDCA-STD-09 | SV · AC · TT | Ten to sixteen weeks from application to decision. |
| EDCA-P09 | Remote Identity Proofing Certification | EDCA-STD-10 | SV · AC · TT | Twelve to eighteen weeks from application to decision. |
| EDCA-P10 | Operational Resilience Certification | EDCA-STD-06 | SV · AC · TT | Eight to fourteen weeks from application to decision. |
Level codes: SR — Startup Ready · SV — Security Verified · AC — Advanced Compliance · TT — Trusted Technology. Level requirements →