Three assurance levels
Basic, Substantial and High scale the depth of evaluation and the attacker model – from baseline protection to resilience against advanced attacks.
EUCS (European Cybersecurity Certification Scheme for Cloud Services) is ENISA's planned EU-wide certification scheme for cloud services. It is still in draft – we prepare you today, with BSI C5 as the dependable bridge.
EUCS is the planned European cybersecurity certification scheme for cloud services. It is being developed by ENISA under the EU Cybersecurity Act (Regulation (EU) 2019/881) and aims to harmonise today's fragmented landscape of national cloud attestations – such as BSI C5 in Germany and SecNumCloud in France – across the EU. Building on ISO/IEC 27001, ISO/IEC 27017 and existing schemes, three assurance levels are planned: Basic, Substantial and High.
Important: EUCS is still a candidate scheme. It has NOT yet been adopted as a Commission implementing act, the timeline has slipped for years, and the originally contentious sovereignty / immunity requirements for the highest level were softened or dropped in later drafts (as of 2024). We therefore treat EUCS as "in preparation" and base your evidence today on the already dependable BSI C5.
How EUCS is structured in the current draft – this may change with the final legal act.
Basic, Substantial and High scale the depth of evaluation and the attacker model – from baseline protection to resilience against advanced attacks.
A comprehensive set of security objectives and controls across domains such as governance, cryptography, operations, incident management and supply chain – derived from established standards.
Mapping onto ISO/IEC 27001, ISO/IEC 27017 and national schemes (BSI C5, SecNumCloud) so existing attestations remain reusable.
Certification by accredited Conformity Assessment Bodies, with different depth per level (self-assessment foreseen only at the lowest tier).
Time-limited certificates with continuous monitoring / surveillance to evidence the security posture over time.
Publication and peer-review mechanisms are foreseen to enable EU-wide mutual recognition of certificates.
Why EUCS already matters for DACH organisations – even without a final legal act.
NIS2 requires managing supply-chain risk. A harmonised cloud seal like EUCS becomes the obvious evidence for cloud providers – bridged today by BSI C5 as a recognised cloud attestation standard.
For financial entities, DORA addresses management of critical ICT third-party providers. Cloud certificates (EUCS in future, BSI C5 today) provide structured evidence for provider assessments.
EUCS builds on ISO/IEC 27001 and 27017. A living ISMS is the most efficient basis to later rise to an EUCS level without duplicated work.
Until EUCS is in force, BSI C5 is the dependable, attestation-based proof of cloud security in the DACH region – and the best starting point for later EUCS maturity.
A pragmatic path from baseline to EUCS readiness.
We define the relevant cloud service, the target assurance level and the distance to existing attestations (ISO 27001, BSI C5).
We establish or strengthen your BSI C5 attestation as dependable proof today and document controls so they connect to EUCS.
We map your controls onto the current EUCS draft, identify gaps per level and prioritise the uplift.
We set up continuous monitoring and track the legislative process so you can certify without delay once the final scheme lands.
Primary sources on the scheme and matching VamiSec services.
Clear answers on status and practical meaning.
No. EUCS is a candidate scheme and has not yet been adopted as a Commission implementing act. The timeline has slipped repeatedly; we communicate it as "in preparation".
The current draft foresees three assurance levels: Basic, Substantial and High. They scale the depth of evaluation and the attacker model.
The originally contentious sovereignty / immunity requirements for the highest level were softened or dropped in later drafts (as of 2024). The final text remains to be seen.
Rely on BSI C5 as a dependable cloud attestation and a living ISO/IEC 27001 ISMS. Both connect to EUCS and protect you from duplicated work.
Both frameworks require managing cloud and ICT third-party risk. A harmonised cloud seal like EUCS becomes the obvious evidence – bridged today by BSI C5.
We raise your cloud evidence to BSI C5 level today and keep it EUCS-ready – so you are prepared the moment the scheme takes effect.