Industry News

ENISA Report Shows SOG-IS Retirement and Rapid Adoption of EUCC and FiTCEM Standards

The European Union Agency for Cybersecurity (ENISA) has released its 2021–2025 assessment report: Cybersecurity Assessments: Certification Uptake & State of Play (Version 1.1).

The report provides authoritative data on the evolution of European cybersecurity certification schemes ahead of the EU Cyber Resilience Act (CRA) application dates.

Key Market Developments

  • Retirement of SOG-IS: As of February 2026, national certification bodies can no longer issue certificates under the SOG-IS agreement. All new Common Criteria certificates must comply with the European Cybersecurity Certification Scheme (EUCC).
  • EUCC Infrastructure: 24 ITSEF testing laboratories and 14 Certification Bodies are currently active under EUCC. In total, 53% of global Common Criteria laboratories operate within the European Union.
  • FiTCEM (EN 17640) for SMEs: CEN/CENELEC standardised the fixed-time evaluation methodology (EN 17640), unifying national schemes from France (CSPN), Germany (BSZ), Spain (LINCE), and the Netherlands (BSPA) to provide an affordable conformity assessment route for SMEs.
  • Surge in IoT Security Labels: ICT product assessments grew to 1,928 in 2025, led by Germany's BSI IT Security Label surging from 19 to 567 labels, and Singapore's CLS issuing 268 labels under mutual recognition.
  • Managed Security Services & Incident Response: Under Regulation (EU) 2025/37, ENISA has initiated the draft candidate certification scheme for Incident Response services, aligning with CRA Article 14 24-hour reporting readiness.

For in-depth analysis of the data and implications for manufacturers, read the full regulatory briefing on PortaRegulus and our detailed technical guide on the CVD Portal Blog.

Prepare your product technical file for the Cyber Resilience Act.

Get started free