Have your say on the certification of EU Managed Security Services

Back to News

ENISA is launching a public consultation on the draft candidate cybersecurity certification scheme on EU Managed Security Services (EUMSS), following its work with the dedicated Ad Hoc Working Group. 

At the request of the European Commission, ENISA has developed a candidate certification scheme for Managed Security Services. ENISA has found that cybersecurity investment increasingly focuses on technology and outsourcing rather than internal cybersecurity teams. The EUMSS scheme will address current diversity and fragmentation in the approach and requirements that apply to the delivery of managed security services in EU Member States.

ENISA Executive Director, Juhan Lepassaar, said: “Common baselines can guarantee a level of confidence in services offered. This scheme can offer Member States trust in the services that reinforce their prevention and response capabilities, especially in the context of the EU Cybersecurity Reserve.”

Take part in the public consultation and share your feedback through the following EU Survey by 13 September 2026.

A close up to the draft scheme

The draft of the EUMSS scheme builds on existing European cybersecurity certification practices and assessment methodologies.

The scheme follows a layered approach, consisting of a horizontal and a vertical layer. 

The horizontal layer outlines a common set of baseline requirements applicable to all Managed Security Services to be certified under this scheme. These baseline requirements apply as a mandatory prerequisite for each certified service profile. These are the same for all three established assurance levels (i.e. 'basic', 'substantial', and 'high') and cover the following domains: 

  • Secure service and platform design;
  • Deployment and transition management;
  • Availability and continuity management;
  • Operational service management; 
  • Continuous improvement and technology maintenance.

The vertical layer defines service-specific requirements applicable to particular managed security services and the services profiles included in these services. The present version of the scheme focuses on the ‘Incident Management Lifecycle’ vertical and more specifically to the ‘Incident Response’ service profile.

Reinforcing trust in the EU Cybersecurity Reserve

The development of the scheme can further support the EU Cybersecurity Reserve, as providers delivering services under the umbrella of the EU Cybersecurity Reserve have to be certified in accordance with the EUMSS within 2 years once the scheme is in place. 

The draft scheme is designed to provide a harmonised and proportionate framework that supports cross-border service provision and Union-level crisis response capabilities. 

The context behind the development of the scheme

The European Commission has requested ENISA to prepare a candidate European cybersecurity certification scheme for Managed Security Services pursuant to Article 48(1) of the Cybersecurity Act. ENISA established an Ad Hoc Working Group on Managed Security Services Certification to support the preparation of the candidate scheme, which kicked-off its work in October 2025. The document currently under public consultation is the first version of the result of the work of ENISA with the support this group.