Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

Certification programmes

What the Agency certifies

Each programme is governed by a published standard and bounded by a scope agreed before the assessment begins. An organisation may hold certification under more than one programme, at different levels.

EDCA-P01

Startup Security Certification

An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.

SRSV EDCA-STD-01
Requirements, scope and evidence →
EDCA-P02

Software Product Certification

An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.

SVACTT EDCA-STD-03
Requirements, scope and evidence →
EDCA-P03

Data Protection Certification

An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.

SVACTT EDCA-STD-02
Requirements, scope and evidence →
EDCA-P04

Cloud Security Certification

An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.

SVACTT EDCA-STD-04
Requirements, scope and evidence →
EDCA-P05

AI Governance Certification

An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.

SVACTT EDCA-STD-05
Requirements, scope and evidence →
EDCA-P06

Crypto-Asset Service Certification

An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.

SVACTT EDCA-STD-07
Requirements, scope and evidence →

Comparison

Programmes at a glance

CodeProgrammeGoverning standard Levels availableTypical duration
EDCA-P01 Startup Security Certification EDCA-STD-01 SR · SV Six to ten weeks from application to decision.
EDCA-P02 Software Product Certification EDCA-STD-03 SV · AC · TT Eight to fourteen weeks from application to decision.
EDCA-P03 Data Protection Certification EDCA-STD-02 SV · AC · TT Eight to twelve weeks from application to decision.
EDCA-P04 Cloud Security Certification EDCA-STD-04 SV · AC · TT Eight to twelve weeks from application to decision.
EDCA-P05 AI Governance Certification EDCA-STD-05 SV · AC · TT Ten to sixteen weeks from application to decision.
EDCA-P06 Crypto-Asset Service Certification EDCA-STD-07 SV · AC · TT Ten to sixteen weeks from application to decision.

Level codes: SR — Startup Ready · SV — Security Verified · AC — Advanced Compliance · TT — Trusted Technology. Level requirements →