Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

EDCA Standards

The requirements organisations are assessed against

The standards are published in full. An organisation is entitled to know exactly what it will be measured against before it applies, and a third party reading a certificate is entitled to know what was examined to produce it.

Standards in force
CodeTitleVersionIssuedStatus
EDCA-STD-00 General Requirements for Certification and Applicant Organisations 3.0 15 January 2026 In force
EDCA-STD-01 Information Security Management 2.1 12 March 2026 In force
EDCA-STD-02 Data Protection and Privacy 2.0 12 March 2026 In force
EDCA-STD-03 Secure Software Development 1.4 20 April 2026 In force
EDCA-STD-04 Cloud and Infrastructure Security 1.3 20 April 2026 In force
EDCA-STD-05 Artificial Intelligence Governance 1.1 2 June 2026 In force
EDCA-STD-07 Crypto-Asset and Distributed Ledger Security 1.0 14 July 2026 In force
EDCA-STD-08 Payment Services Security 1.0 28 July 2026 In force
EDCA-STD-09 Anti-Money-Laundering and Counter-Terrorist-Financing Programmes 1.0 28 July 2026 In force
EDCA-STD-10 Remote Identity Proofing 1.0 28 July 2026 In force
EDCA-STD-06 Operational Resilience and Continuity 1.2 2 June 2026 In force

Methodology

How an assessment reaches a finding

01

Requirements

Each standard states discrete, testable requirements. A requirement that cannot be evidenced is not a requirement — it is an aspiration, and the Agency does not certify aspirations.

02

Evidence

Above Level I, every requirement in scope is verified against records, configuration, demonstration or observation. Management statements alone do not close a requirement.

03

Classification

Findings are classified under EDCA-STD-00 as major non-conformities, minor non-conformities or observations. Major non-conformities must be closed before a certificate is issued.

Published standards

EDCA-STD-00 · Version 3.0 · Issued 15 January 2026

General Requirements for Certification and Applicant Organisations

Governs the certification scheme itself: eligibility, impartiality and independence rules, the conduct of assessments, the classification of findings, decision-making, appeals, and the conditions under which a certificate is suspended or withdrawn.

Assessment domains

Eligibility and scope definitionImpartiality and conflict of interestAssessor competence requirementsClassification of findings and non-conformitiesCertification decision and appealsSuspension, withdrawal and reinstatement

EDCA-STD-01 · Version 2.1 · Issued 12 March 2026

Information Security Management

Baseline security requirements applied across all certification programmes: governance, risk treatment, access control, cryptography, operations security and incident management.

Assessment domains

Security governance and accountabilityRisk assessment and treatmentIdentity and access managementCryptography and key managementOperations, logging and monitoringIncident detection, response and notification

EDCA-STD-02 · Version 2.0 · Issued 12 March 2026

Data Protection and Privacy

Requirements for lawful and accountable processing of personal data, aligned to Regulation (EU) 2016/679, covering records of processing, data subject rights, transfers and retention.

Assessment domains

Lawful basis and records of processingData subject rights handlingData protection by design and by defaultInternational transfers and safeguardsRetention, minimisation and erasureProcessor and sub-processor governance

EDCA-STD-03 · Version 1.4 · Issued 20 April 2026

Secure Software Development

Requirements for the secure design, development, testing and release of software products, including dependency management, vulnerability handling and release integrity.

Assessment domains

Secure design and threat modellingSource control and peer reviewDependency and component managementSecurity testing in the pipelineRelease integrity and provenanceVulnerability disclosure and patching

EDCA-STD-04 · Version 1.3 · Issued 20 April 2026

Cloud and Infrastructure Security

Requirements for the configuration, segregation and operation of cloud and hosted infrastructure, including tenancy separation, network controls and infrastructure as code.

Assessment domains

Cloud governance and shared responsibilityTenant and environment segregationNetwork and perimeter controlsInfrastructure as code and configuration baselinesSecrets and credential managementAvailability, backup and recovery

EDCA-STD-05 · Version 1.1 · Issued 2 June 2026

Artificial Intelligence Governance

Requirements for the responsible development and operation of AI systems, covering intended purpose, data governance, human oversight, transparency and post-market monitoring.

Assessment domains

Intended purpose and risk classificationTraining and input data governanceHuman oversight and interventionTransparency and user informationAccuracy, robustness and evaluationPost-deployment monitoring and logging

EDCA-STD-07 · Version 1.0 · Issued 14 July 2026

Crypto-Asset and Distributed Ledger Security

Requirements for organisations that hold, transfer, exchange or administer crypto-assets on behalf of others, or that operate distributed ledger infrastructure. Covers key generation and custody, transaction authorisation, segregation of client assets, counterparty screening, and the security of smart contracts and the nodes and bridges a service depends on.

Assessment domains

Key generation, storage, backup and recoveryWallet architecture and transaction authorisationSegregation and reconciliation of client assetsCounterparty and address screeningSmart contract security and change controlNode, bridge and third-party integration security

EDCA-STD-08 · Version 1.0 · Issued 28 July 2026

Payment Services Security

Requirements for organisations that initiate, process or settle payments. Covers authentication of payment orders, protection and segregation of client funds, the integrity of the payment path from initiation to settlement, merchant settlement and reconciliation, and the handling of refunds and disputes.

Assessment domains

Authentication and authorisation of payment ordersProtection and segregation of client fundsIntegrity of the payment pathMerchant settlement and reconciliationRefunds, reversals and disputesFraud detection and transaction monitoring

EDCA-STD-09 · Version 1.0 · Issued 28 July 2026

Anti-Money-Laundering and Counter-Terrorist-Financing Programmes

Requirements for the design and operation of an AML/CFT programme, and for tooling supplied to others for that purpose. This standard is not about security: it asks whether the risk methodology is sound, whether screening lists are current, whether alerts are actually worked and closed, and whether the records would survive inspection.

Assessment domains

Business-wide risk assessment and calibrationCustomer due diligence proportionate to riskSanctions and list screening, and list currencyAlert management and quality of dispositionInformation accompanying transfers of funds and crypto-assetsRecords, retention and retrievability

EDCA-STD-10 · Version 1.0 · Issued 28 July 2026

Remote Identity Proofing

Requirements for establishing that a person is who they claim to be without meeting them: capture and authentication of identity evidence, binding of the applicant to that evidence, the human review that catches what automation does not, and retention of what was actually seen at the time of the decision.

Assessment domains

Identity evidence capture and document authenticityPresentation attack detection and livenessBinding of the person to the evidenceAutomated decisioning and human reviewEvidence retention, integrity and retrievabilityError rate measurement and monitoring

EDCA-STD-06 · Version 1.2 · Issued 2 June 2026

Operational Resilience and Continuity

Requirements for maintaining service under disruption: dependency mapping, recovery objectives, continuity testing and supplier concentration risk.

Assessment domains

Critical service and dependency mappingRecovery objectives and capabilityContinuity and disaster recovery testingSupplier concentration and exit planningCrisis communicationPost-incident review

Certification levels

Level requirements

Levels are cumulative: each level includes the requirements of those below it. The level held is recorded in the certificate number.

Level I · Certificate code SR

EDCA Startup Ready

Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.

Intended for
Pre-seed to seed stage companies, typically fewer than 25 staff, with a product in early commercial use.
Validity
24 months
Surveillance
Self-declaration at 12 months.

Requirements

  • Documented information security policy approved by management
  • Named individual accountable for security and data protection
  • Asset and data inventory, including third-party processors
  • Multi-factor authentication on all administrative access
  • Encrypted storage and transport of personal data
  • Documented backup and restoration procedure, tested at least once
  • Records of processing activities under Article 30 GDPR
  • Incident response contacts and notification procedure
Level II · Certificate code SV

EDCA Security Verified

Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.

Intended for
Companies with paying business customers, or handling personal data of more than 10,000 data subjects.
Validity
24 months
Surveillance
Surveillance assessment at 12 months.

Requirements

  • All Level I requirements, verified rather than declared
  • Risk assessment methodology applied and reviewed within 12 months
  • Independent vulnerability assessment of production systems
  • Access review performed at least twice in the preceding year
  • Secure development practice with peer review and dependency scanning
  • Logging and monitoring with defined retention and alerting
  • Supplier due diligence and data processing agreements in place
  • Incident register with evidence of exercises or real handling
Level III · Certificate code AC

EDCA Advanced Compliance

Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.

Intended for
Scale-up companies, regulated sectors, and suppliers subject to customer security assessments or public procurement requirements.
Validity
36 months
Surveillance
Annual surveillance assessment.

Requirements

  • All Level II requirements
  • Compliance obligations register mapped to controls and owners
  • Management review of security performance at least twice yearly
  • Penetration testing by an independent party within 12 months
  • Business continuity plan tested against a defined scenario
  • Change management with segregation between authoring and release
  • Documented data retention and erasure schedule, applied in practice
  • Corrective action process with tracked closure of findings
Level IV · Certificate code TT

EDCA Trusted Technology

The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.

Intended for
Established technology providers serving critical, financial, healthcare or public sector customers.
Validity
36 months
Surveillance
Annual surveillance assessment and interim technical review.

Requirements

  • All Level III requirements
  • At least one prior EDCA certification cycle completed without major non-conformity
  • Board-level accountability for technology risk, evidenced in minutes
  • Continuous control monitoring with measured effectiveness
  • Resilience testing including supplier and infrastructure failure
  • Responsible technology governance, including automated decision-making
  • Independent assurance over the control environment
  • Public statement of security and data protection commitments

Versioning and transition

Standards are maintained by the Technical Standards Board. A new version is published with a stated date of entry into force and a transition period, during which the superseded version remains valid for assessments already under way.

The version number follows the significance of the change. A change to the first component introduces or removes requirements and always carries a transition period of at least six months. A change to the second component clarifies existing requirements, corrects errors or updates references, and takes effect immediately for assessments that have not yet reached the audit stage.

Certificates state the standard and version against which the assessment was made. A certificate remains valid for its full period notwithstanding the publication of a later version of the standard; the later version applies at recertification.

Relationship to other frameworks

The EDCA standards draw on established international practice, including the ISO/IEC 27000 family, the NIST Cybersecurity Framework, and the requirements of Regulation (EU) 2016/679. They are not equivalent to those frameworks and certification by the Agency is not a substitute for certification or accreditation under them.

Where an organisation already holds certification under a recognised framework, the Agency will take existing evidence into account to avoid duplicating work, but reaches its own finding against its own requirements.