EDCA-P02 · Governed by EDCA-STD-03
Software Product Certification
An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- A named product or product family, at a stated version
- The development pipeline that produces it
- Third-party components distributed with the product
- The vulnerability handling process applying to it
What is examined
Each area below is assessed against the requirements of EDCA-STD-03, Secure Software Development, version 1.4.
- Secure design and threat modelling
- Source control, peer review and build integrity
- Dependency and component management
- Automated security testing coverage
- Release, versioning and provenance
- Vulnerability disclosure and remediation timelines
Programme particulars
- Programme code
- EDCA-P02
- Governing standard
- EDCA-STD-03 — Secure Software Development, version 1.4, issued 20 April 2026
- Levels available
-
Level II — EDCA Security Verified
Level III — EDCA Advanced Compliance
Level IV — EDCA Trusted Technology - Typical duration
- Eight to fourteen weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Architecture and threat model documentation
- Pipeline configuration and testing results
- Software bill of materials for the assessed version
- Vulnerability register and remediation records
- Release procedure and change approval records
Apply for Software Product Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.