Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

For startups

What certification is actually worth to an early-stage company

In plain terms: it removes the same three obstacles that slow down every young technology company — the enterprise security review, the investor's technical due diligence, and the partner who cannot connect systems until someone signs off on yours.

Customers

The security questionnaire

Selling to a mid-sized or enterprise customer means a vendor security review: a spreadsheet of 120 to 400 questions, a request for evidence, and a wait. Teams without documented controls answer it by improvising, which is slow and rarely survives scrutiny.

A certificate with a published scope answers most of that questionnaire in advance, and answers it with something the buyer's own security team can verify independently in the register.

Investors

Technical due diligence

At seed and Series A, technical due diligence looks for the same things: who has access to production, what happens to customer data, whether the company could survive losing its database, and whether there is anything in the codebase or the compliance posture that becomes a liability after the round.

Having those questions already examined by a third party shortens diligence and removes the negotiation discount that uncertainty attracts.

Partners

Integration and procurement

Payment providers, healthcare platforms, public sector buyers and large integrators require documented security controls from anyone connecting to them. Many will not begin commercial discussions without them.

Certification gives a defined, checkable answer at the point where a procurement process would otherwise stall.

Level I

EDCA Startup Ready is designed for where you actually are

Certification schemes built for large organisations fail early-stage companies in a predictable way: they demand a management system, a compliance function and a documentation estate that a team of eleven people cannot maintain and does not need.

Level I asks for the controls that genuinely reduce risk at that size — accountable ownership, multi-factor authentication on administrative access, encrypted data, a backup that has been restored at least once, a record of processing activities, and a plan for the day something goes wrong. Nothing about it is ceremonial.

When the company grows into the next level, the work already done carries forward: the levels are cumulative, so Level II is an extension of Level I rather than a fresh start.

Level I · Certificate code SR

EDCA Startup Ready — requirements

  • Documented information security policy approved by management
  • Named individual accountable for security and data protection
  • Asset and data inventory, including third-party processors
  • Multi-factor authentication on all administrative access
  • Encrypted storage and transport of personal data
  • Documented backup and restoration procedure, tested at least once
  • Records of processing activities under Article 30 GDPR
  • Incident response contacts and notification procedure
Valid 24 months · Self-declaration at 12 months.

What to expect

Honest answers to the questions founders ask

How long does it take?
Six to ten weeks for Level I under the Startup Security programme, of which most of the elapsed time is the applicant's — assembling evidence and closing gaps found at the preliminary assessment. The audit itself is one to two days.
How much internal effort is it?
For a team that already runs a competent engineering operation, typically five to fifteen working days spread across the period, mostly spent writing down what is already being done. Where controls genuinely do not exist, the effort is the effort of building them — which is the point.
What if we fail?
You will not be surprised by it. The preliminary assessment at stage three exists precisely to identify gaps before the audit, and findings raised there are advisory rather than counted against you. If major non-conformities are found at audit, the certificate is not issued until they are closed — there is no time limit imposed beyond the 90-day corrective action window, which can be extended.
Will you help us fix things?
No, and this matters. The Agency does not provide consultancy, remediation or implementation services to organisations it assesses. A body that sells you the fix and then certifies the fix is not independent, and its certificate is worth nothing to the customer relying on it. The Agency will tell you precisely what is wrong; how you remedy it is yours to decide.
Does this replace ISO 27001 or SOC 2?
No. EDCA certification is the Agency's own assessment against its own published standards and is not equivalent to, or a substitute for, ISO/IEC 27001 certification, a SOC 2 report, or any accredited scheme. Many organisations use it as a first step, at a stage where an accredited scheme is disproportionate, and to establish the controls those schemes will later require.
What does it cost?
Fees depend on programme, level and scope, and are fixed in a schedule issued after the scope review at stage two — before any assessment work begins and before any commitment is made. The application itself is free.

Start with a conversation, not a contract

Tell the Agency what you build, who your customers are and where your data sits. You will get a straight answer on which programme and level fit, what evidence you would need, and whether certification is worth doing at your stage at all.

Apply for certification Ask a question first