EDCA-P01 · Governed by EDCA-STD-01
Startup Security Certification
An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.
Scope of assessment
The scope is agreed in writing before the assessment begins and is printed on the certificate. A certificate says nothing outside its scope.
- The organisation as a whole, including its production environment
- Personnel, contractor and administrative access
- Customer data held or processed by the organisation
- Third parties with access to production systems or personal data
What is examined
Each area below is assessed against the requirements of EDCA-STD-01, Information Security Management, version 2.1.
- Security governance and assigned accountability
- Access control and authentication
- Data handling, encryption and retention
- Backup, restoration and continuity of the service
- Incident response readiness
- Supplier and sub-processor oversight
Programme particulars
- Programme code
- EDCA-P01
- Governing standard
- EDCA-STD-01 — Information Security Management, version 2.1, issued 12 March 2026
- Levels available
-
Level I — EDCA Startup Ready
Level II — EDCA Security Verified - Typical duration
- Six to ten weeks from application to decision.
- Surveillance
- As required by the level held. See level requirements.
Evidence normally requested
The list is indicative. The evidence request issued after the preliminary assessment is specific to the agreed scope.
- Information security policy and supporting procedures
- Asset, data and supplier inventories
- Access control configuration and administrative account listing
- Backup configuration and evidence of a restoration test
- Records of processing activities
Apply for Startup Security Certification
Submitting an application costs nothing and commits you to nothing. The Agency will confirm eligibility, propose a scope and issue a fee schedule before any assessment work begins.