Decoding the world of cybersecurity

Europe sets assurance baseline for cyber providers

ENISA’s proposed certification scheme would establish common assurance requirements for managed security services, beginning with incident response and providers supporting the EU Cybersecurity Reserve.

Europe sets assurance baseline for cyber providers
Summary
  • ENISA has opened consultation on a European certification scheme covering the design, delivery, continuity, and maintenance of managed security services.
  • The first service profile addresses incident response, while providers supporting the EU Cybersecurity Reserve will face a future certification requirement.
  • The scheme could influence supplier selection, market access, and procurement requirements across European public bodies and regulated sectors.

The European Union is preparing to place managed security providers within a common certification framework, extending formal assurance beyond technology products and cloud services to the companies hired to monitor systems, investigate attacks, and support recovery.

ENISA, the EU Agency for Cybersecurity, has opened a public consultation on the proposed European Union Managed Security Services certification scheme, known as EUMSS. Responses are due by 13 September 2026, after which the draft will continue through the European cybersecurity certification process.

Requested by the European Commission under the Cybersecurity Act, the scheme is intended to establish consistent requirements for managed security services across member states. Its horizontal controls cover secure service and platform design, deployment and transition, operational service management, availability, continuity, continuous improvement, and technology maintenance.

A second layer applies requirements to individual areas of managed security work. ENISA has started with the incident management lifecycle and an initial profile for incident response, where suppliers may receive privileged access, forensic evidence, employee information, commercially sensitive records, and authority to intervene directly in customer systems.

The draft retains the EU certification framework’s basic, substantial, and high assurance levels. Although the same broad security areas run through each level, the depth of assessment and the evidence expected from a provider will increase according to the assurance sought.

Certification will therefore cover more than whether a supplier has documented policies. Providers will need to demonstrate how services are designed, how platforms are maintained, how operational changes are controlled, how availability is protected, and how service continuity is managed when their own people or infrastructure are placed under pressure.

Companies participating in the EU Cybersecurity Reserve will be required to obtain EUMSS certification within two years of the scheme coming into effect. The reserve was created to support member states and EU institutions during significant cyber incidents, giving the proposed framework an immediate role in the selection of suppliers trusted to work on major public-sector responses.

ENISA’s consultation documents will also be relevant to managed detection and response providers, incident-response specialists, security operations companies, insurers, legal advisers, and organisations that rely heavily on outsourced cyber capability. Certification could become a procurement requirement beyond the providers formally obliged to obtain it, particularly in critical infrastructure and regulated sectors.

European organisations currently assess managed security suppliers through a mixture of contractual questionnaires, independent standards, customer audits, sector rules, and internally defined risk requirements. The evidence demanded from one buyer can differ considerably from that requested by another, even when the underlying service is similar.

A common European scheme could provide a more comparable basis for evaluating providers and reduce some duplicated assessment work. It may also help buyers distinguish between suppliers that operate mature, resilient service platforms and those whose assurances rely largely on contractual language or broad corporate certifications.

Customer oversight will still need to address the service being purchased and the environment in which it will operate. A certification assessment cannot determine whether a provider has enough experienced personnel during a widespread incident, whether its analysts understand a particular industrial estate, or whether contractual response times remain achievable when several customers require support at once.

Contracts must also settle responsibility for evidence preservation, subcontractor access, data location, incident notification, liability, and authority to make operational changes. Those controls become particularly important where a managed provider can deploy software, alter security policies, isolate systems, or administer customer identities.

The provider’s own security architecture is another concentration point. A compromise of its tooling, identity platform, remote-access systems, or software supply chain could expose several customers through one route. The scheme’s treatment of privileged access, customer segregation, internal monitoring, and dependencies will influence how much confidence buyers can place in the final certificate.

EUMSS will sit alongside a wider expansion of European operational-resilience rules. DORA has formalised oversight of important technology dependencies in financial services, while NIS2 has increased scrutiny of supply chain security, management accountability, and the measures organisations use to select and supervise external providers.

The consultation will determine how far the scheme tests operational capability and service resilience, how assessment costs are distributed, and whether smaller specialist providers can participate without weakening the assurance expected from companies entrusted with sensitive incident work.

×