Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

EDCA Standards

The requirements organisations are assessed against

The standards are published in full. An organisation is entitled to know exactly what it will be measured against before it applies, and a third party reading a certificate is entitled to know what was examined to produce it.

Standards in force
CodeTitleVersionIssuedStatus
EDCA-STD-00 General Requirements for Certification and Applicant Organisations 3.0 15 January 2026 In force
EDCA-STD-01 Information Security Management 2.1 12 March 2026 In force
EDCA-STD-02 Data Protection and Privacy 2.0 12 March 2026 In force
EDCA-STD-03 Secure Software Development 1.4 20 April 2026 In force
EDCA-STD-04 Cloud and Infrastructure Security 1.3 20 April 2026 In force
EDCA-STD-05 Artificial Intelligence Governance 1.1 2 June 2026 In force
EDCA-STD-07 Crypto-Asset and Distributed Ledger Security 1.0 14 July 2026 In force
EDCA-STD-06 Operational Resilience and Continuity 1.2 2 June 2026 In force

Methodology

How an assessment reaches a finding

01

Requirements

Each standard states discrete, testable requirements. A requirement that cannot be evidenced is not a requirement — it is an aspiration, and the Agency does not certify aspirations.

02

Evidence

Above Level I, every requirement in scope is verified against records, configuration, demonstration or observation. Management statements alone do not close a requirement.

03

Classification

Findings are classified under EDCA-STD-00 as major non-conformities, minor non-conformities or observations. Major non-conformities must be closed before a certificate is issued.

Published standards

EDCA-STD-00 · Version 3.0 · Issued 15 January 2026

General Requirements for Certification and Applicant Organisations

Governs the certification scheme itself: eligibility, impartiality and independence rules, the conduct of assessments, the classification of findings, decision-making, appeals, and the conditions under which a certificate is suspended or withdrawn.

Assessment domains

Eligibility and scope definitionImpartiality and conflict of interestAssessor competence requirementsClassification of findings and non-conformitiesCertification decision and appealsSuspension, withdrawal and reinstatement

EDCA-STD-01 · Version 2.1 · Issued 12 March 2026

Information Security Management

Baseline security requirements applied across all certification programmes: governance, risk treatment, access control, cryptography, operations security and incident management.

Assessment domains

Security governance and accountabilityRisk assessment and treatmentIdentity and access managementCryptography and key managementOperations, logging and monitoringIncident detection, response and notification

EDCA-STD-02 · Version 2.0 · Issued 12 March 2026

Data Protection and Privacy

Requirements for lawful and accountable processing of personal data, aligned to Regulation (EU) 2016/679, covering records of processing, data subject rights, transfers and retention.

Assessment domains

Lawful basis and records of processingData subject rights handlingData protection by design and by defaultInternational transfers and safeguardsRetention, minimisation and erasureProcessor and sub-processor governance

EDCA-STD-03 · Version 1.4 · Issued 20 April 2026

Secure Software Development

Requirements for the secure design, development, testing and release of software products, including dependency management, vulnerability handling and release integrity.

Assessment domains

Secure design and threat modellingSource control and peer reviewDependency and component managementSecurity testing in the pipelineRelease integrity and provenanceVulnerability disclosure and patching

EDCA-STD-04 · Version 1.3 · Issued 20 April 2026

Cloud and Infrastructure Security

Requirements for the configuration, segregation and operation of cloud and hosted infrastructure, including tenancy separation, network controls and infrastructure as code.

Assessment domains

Cloud governance and shared responsibilityTenant and environment segregationNetwork and perimeter controlsInfrastructure as code and configuration baselinesSecrets and credential managementAvailability, backup and recovery

EDCA-STD-05 · Version 1.1 · Issued 2 June 2026

Artificial Intelligence Governance

Requirements for the responsible development and operation of AI systems, covering intended purpose, data governance, human oversight, transparency and post-market monitoring.

Assessment domains

Intended purpose and risk classificationTraining and input data governanceHuman oversight and interventionTransparency and user informationAccuracy, robustness and evaluationPost-deployment monitoring and logging

EDCA-STD-07 · Version 1.0 · Issued 14 July 2026

Crypto-Asset and Distributed Ledger Security

Requirements for organisations that hold, transfer, exchange or administer crypto-assets on behalf of others, or that operate distributed ledger infrastructure. Covers key generation and custody, transaction authorisation, segregation of client assets, counterparty screening, and the security of smart contracts and the nodes and bridges a service depends on.

Assessment domains

Key generation, storage, backup and recoveryWallet architecture and transaction authorisationSegregation and reconciliation of client assetsCounterparty and address screeningSmart contract security and change controlNode, bridge and third-party integration security

EDCA-STD-06 · Version 1.2 · Issued 2 June 2026

Operational Resilience and Continuity

Requirements for maintaining service under disruption: dependency mapping, recovery objectives, continuity testing and supplier concentration risk.

Assessment domains

Critical service and dependency mappingRecovery objectives and capabilityContinuity and disaster recovery testingSupplier concentration and exit planningCrisis communicationPost-incident review

Certification levels

Level requirements

Levels are cumulative: each level includes the requirements of those below it. The level held is recorded in the certificate number.

Level I · Certificate code SR

EDCA Startup Ready

Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.

Intended for
Pre-seed to seed stage companies, typically fewer than 25 staff, with a product in early commercial use.
Validity
24 months
Surveillance
Self-declaration at 12 months.

Requirements

  • Documented information security policy approved by management
  • Named individual accountable for security and data protection
  • Asset and data inventory, including third-party processors
  • Multi-factor authentication on all administrative access
  • Encrypted storage and transport of personal data
  • Documented backup and restoration procedure, tested at least once
  • Records of processing activities under Article 30 GDPR
  • Incident response contacts and notification procedure
Level II · Certificate code SV

EDCA Security Verified

Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.

Intended for
Companies with paying business customers, or handling personal data of more than 10,000 data subjects.
Validity
24 months
Surveillance
Surveillance assessment at 12 months.

Requirements

  • All Level I requirements, verified rather than declared
  • Risk assessment methodology applied and reviewed within 12 months
  • Independent vulnerability assessment of production systems
  • Access review performed at least twice in the preceding year
  • Secure development practice with peer review and dependency scanning
  • Logging and monitoring with defined retention and alerting
  • Supplier due diligence and data processing agreements in place
  • Incident register with evidence of exercises or real handling
Level III · Certificate code AC

EDCA Advanced Compliance

Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.

Intended for
Scale-up companies, regulated sectors, and suppliers subject to customer security assessments or public procurement requirements.
Validity
36 months
Surveillance
Annual surveillance assessment.

Requirements

  • All Level II requirements
  • Compliance obligations register mapped to controls and owners
  • Management review of security performance at least twice yearly
  • Penetration testing by an independent party within 12 months
  • Business continuity plan tested against a defined scenario
  • Change management with segregation between authoring and release
  • Documented data retention and erasure schedule, applied in practice
  • Corrective action process with tracked closure of findings
Level IV · Certificate code TT

EDCA Trusted Technology

The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.

Intended for
Established technology providers serving critical, financial, healthcare or public sector customers.
Validity
36 months
Surveillance
Annual surveillance assessment and interim technical review.

Requirements

  • All Level III requirements
  • At least one prior EDCA certification cycle completed without major non-conformity
  • Board-level accountability for technology risk, evidenced in minutes
  • Continuous control monitoring with measured effectiveness
  • Resilience testing including supplier and infrastructure failure
  • Responsible technology governance, including automated decision-making
  • Independent assurance over the control environment
  • Public statement of security and data protection commitments

Versioning and transition

Standards are maintained by the Technical Standards Board. A new version is published with a stated date of entry into force and a transition period, during which the superseded version remains valid for assessments already under way.

The version number follows the significance of the change. A change to the first component introduces or removes requirements and always carries a transition period of at least six months. A change to the second component clarifies existing requirements, corrects errors or updates references, and takes effect immediately for assessments that have not yet reached the audit stage.

Certificates state the standard and version against which the assessment was made. A certificate remains valid for its full period notwithstanding the publication of a later version of the standard; the later version applies at recertification.

Relationship to other frameworks

The EDCA standards draw on established international practice, including the ISO/IEC 27000 family, the NIST Cybersecurity Framework, and the requirements of Regulation (EU) 2016/679. They are not equivalent to those frameworks and certification by the Agency is not a substitute for certification or accreditation under them.

Where an organisation already holds certification under a recognised framework, the Agency will take existing evidence into account to avoid duplicating work, but reaches its own finding against its own requirements.