EDCA Standards
The requirements organisations are assessed against
The standards are published in full. An organisation is entitled to know exactly what it will be measured against before it applies, and a third party reading a certificate is entitled to know what was examined to produce it.
| Code | Title | Version | Issued | Status |
|---|---|---|---|---|
| EDCA-STD-00 | General Requirements for Certification and Applicant Organisations | 3.0 | 15 January 2026 | In force |
| EDCA-STD-01 | Information Security Management | 2.1 | 12 March 2026 | In force |
| EDCA-STD-02 | Data Protection and Privacy | 2.0 | 12 March 2026 | In force |
| EDCA-STD-03 | Secure Software Development | 1.4 | 20 April 2026 | In force |
| EDCA-STD-04 | Cloud and Infrastructure Security | 1.3 | 20 April 2026 | In force |
| EDCA-STD-05 | Artificial Intelligence Governance | 1.1 | 2 June 2026 | In force |
| EDCA-STD-07 | Crypto-Asset and Distributed Ledger Security | 1.0 | 14 July 2026 | In force |
| EDCA-STD-06 | Operational Resilience and Continuity | 1.2 | 2 June 2026 | In force |
Methodology
How an assessment reaches a finding
Requirements
Each standard states discrete, testable requirements. A requirement that cannot be evidenced is not a requirement — it is an aspiration, and the Agency does not certify aspirations.
Evidence
Above Level I, every requirement in scope is verified against records, configuration, demonstration or observation. Management statements alone do not close a requirement.
Classification
Findings are classified under EDCA-STD-00 as major non-conformities, minor non-conformities or observations. Major non-conformities must be closed before a certificate is issued.
Published standards
EDCA-STD-00 · Version 3.0 · Issued 15 January 2026
General Requirements for Certification and Applicant Organisations
Governs the certification scheme itself: eligibility, impartiality and independence rules, the conduct of assessments, the classification of findings, decision-making, appeals, and the conditions under which a certificate is suspended or withdrawn.
Assessment domains
EDCA-STD-01 · Version 2.1 · Issued 12 March 2026
Information Security Management
Baseline security requirements applied across all certification programmes: governance, risk treatment, access control, cryptography, operations security and incident management.
Assessment domains
EDCA-STD-02 · Version 2.0 · Issued 12 March 2026
Data Protection and Privacy
Requirements for lawful and accountable processing of personal data, aligned to Regulation (EU) 2016/679, covering records of processing, data subject rights, transfers and retention.
Assessment domains
EDCA-STD-03 · Version 1.4 · Issued 20 April 2026
Secure Software Development
Requirements for the secure design, development, testing and release of software products, including dependency management, vulnerability handling and release integrity.
Assessment domains
EDCA-STD-04 · Version 1.3 · Issued 20 April 2026
Cloud and Infrastructure Security
Requirements for the configuration, segregation and operation of cloud and hosted infrastructure, including tenancy separation, network controls and infrastructure as code.
Assessment domains
EDCA-STD-05 · Version 1.1 · Issued 2 June 2026
Artificial Intelligence Governance
Requirements for the responsible development and operation of AI systems, covering intended purpose, data governance, human oversight, transparency and post-market monitoring.
Assessment domains
EDCA-STD-07 · Version 1.0 · Issued 14 July 2026
Crypto-Asset and Distributed Ledger Security
Requirements for organisations that hold, transfer, exchange or administer crypto-assets on behalf of others, or that operate distributed ledger infrastructure. Covers key generation and custody, transaction authorisation, segregation of client assets, counterparty screening, and the security of smart contracts and the nodes and bridges a service depends on.
Assessment domains
EDCA-STD-06 · Version 1.2 · Issued 2 June 2026
Operational Resilience and Continuity
Requirements for maintaining service under disruption: dependency mapping, recovery objectives, continuity testing and supplier concentration risk.
Assessment domains
Certification levels
Level requirements
Levels are cumulative: each level includes the requirements of those below it. The level held is recorded in the certificate number.
EDCA Startup Ready
Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.
- Intended for
- Pre-seed to seed stage companies, typically fewer than 25 staff, with a product in early commercial use.
- Validity
- 24 months
- Surveillance
- Self-declaration at 12 months.
Requirements
- Documented information security policy approved by management
- Named individual accountable for security and data protection
- Asset and data inventory, including third-party processors
- Multi-factor authentication on all administrative access
- Encrypted storage and transport of personal data
- Documented backup and restoration procedure, tested at least once
- Records of processing activities under Article 30 GDPR
- Incident response contacts and notification procedure
EDCA Security Verified
Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.
- Intended for
- Companies with paying business customers, or handling personal data of more than 10,000 data subjects.
- Validity
- 24 months
- Surveillance
- Surveillance assessment at 12 months.
Requirements
- All Level I requirements, verified rather than declared
- Risk assessment methodology applied and reviewed within 12 months
- Independent vulnerability assessment of production systems
- Access review performed at least twice in the preceding year
- Secure development practice with peer review and dependency scanning
- Logging and monitoring with defined retention and alerting
- Supplier due diligence and data processing agreements in place
- Incident register with evidence of exercises or real handling
EDCA Advanced Compliance
Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.
- Intended for
- Scale-up companies, regulated sectors, and suppliers subject to customer security assessments or public procurement requirements.
- Validity
- 36 months
- Surveillance
- Annual surveillance assessment.
Requirements
- All Level II requirements
- Compliance obligations register mapped to controls and owners
- Management review of security performance at least twice yearly
- Penetration testing by an independent party within 12 months
- Business continuity plan tested against a defined scenario
- Change management with segregation between authoring and release
- Documented data retention and erasure schedule, applied in practice
- Corrective action process with tracked closure of findings
EDCA Trusted Technology
The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.
- Intended for
- Established technology providers serving critical, financial, healthcare or public sector customers.
- Validity
- 36 months
- Surveillance
- Annual surveillance assessment and interim technical review.
Requirements
- All Level III requirements
- At least one prior EDCA certification cycle completed without major non-conformity
- Board-level accountability for technology risk, evidenced in minutes
- Continuous control monitoring with measured effectiveness
- Resilience testing including supplier and infrastructure failure
- Responsible technology governance, including automated decision-making
- Independent assurance over the control environment
- Public statement of security and data protection commitments
Versioning and transition
Standards are maintained by the Technical Standards Board. A new version is published with a stated date of entry into force and a transition period, during which the superseded version remains valid for assessments already under way.
The version number follows the significance of the change. A change to the first component introduces or removes requirements and always carries a transition period of at least six months. A change to the second component clarifies existing requirements, corrects errors or updates references, and takes effect immediately for assessments that have not yet reached the audit stage.
Certificates state the standard and version against which the assessment was made. A certificate remains valid for its full period notwithstanding the publication of a later version of the standard; the later version applies at recertification.
Relationship to other frameworks
The EDCA standards draw on established international practice, including the ISO/IEC 27000 family, the NIST Cybersecurity Framework, and the requirements of Regulation (EU) 2016/679. They are not equivalent to those frameworks and certification by the Agency is not a substitute for certification or accreditation under them.
Where an organisation already holds certification under a recognised framework, the Agency will take existing evidence into account to avoid duplicating work, but reaches its own finding against its own requirements.