Book an Appointment
GRC · Cloud Certification

EUCS the emerging EU seal for cloud security

EUCS (European Cybersecurity Certification Scheme for Cloud Services) is ENISA's planned EU-wide certification scheme for cloud services. It is still in draft – we prepare you today, with BSI C5 as the dependable bridge.

Candidate schemeStatus: draft, not yet adopted as a legal act
ENISA / CSABasis: EU Cybersecurity Act (Reg. (EU) 2019/881)
Basic · Substantial · HighPlanned assurance levels
NIS2 linkDe-facto lever for cloud evidence under NIS2 / Data Act

What EUCS is – and what it is not (yet)

EUCS is the planned European cybersecurity certification scheme for cloud services. It is being developed by ENISA under the EU Cybersecurity Act (Regulation (EU) 2019/881) and aims to harmonise today's fragmented landscape of national cloud attestations – such as BSI C5 in Germany and SecNumCloud in France – across the EU. Building on ISO/IEC 27001, ISO/IEC 27017 and existing schemes, three assurance levels are planned: Basic, Substantial and High.

Important: EUCS is still a candidate scheme. It has NOT yet been adopted as a Commission implementing act, the timeline has slipped for years, and the originally contentious sovereignty / immunity requirements for the highest level were softened or dropped in later drafts (as of 2024). We therefore treat EUCS as "in preparation" and base your evidence today on the already dependable BSI C5.

Core building blocks of the scheme

How EUCS is structured in the current draft – this may change with the final legal act.

01

Three assurance levels

Basic, Substantial and High scale the depth of evaluation and the attacker model – from baseline protection to resilience against advanced attacks.

02

Control catalogue

A comprehensive set of security objectives and controls across domains such as governance, cryptography, operations, incident management and supply chain – derived from established standards.

03

Built on existing norms

Mapping onto ISO/IEC 27001, ISO/IEC 27017 and national schemes (BSI C5, SecNumCloud) so existing attestations remain reusable.

04

Conformity assessment

Certification by accredited Conformity Assessment Bodies, with different depth per level (self-assessment foreseen only at the lowest tier).

05

Validity & surveillance

Time-limited certificates with continuous monitoring / surveillance to evidence the security posture over time.

06

Transparency & peer review

Publication and peer-review mechanisms are foreseen to enable EU-wide mutual recognition of certificates.

The bridge to NIS2, DORA & ISO 27001

Why EUCS already matters for DACH organisations – even without a final legal act.

NIS2 & the cloud supply chain

NIS2 requires managing supply-chain risk. A harmonised cloud seal like EUCS becomes the obvious evidence for cloud providers – bridged today by BSI C5 as a recognised cloud attestation standard.

DORA & ICT third parties

For financial entities, DORA addresses management of critical ICT third-party providers. Cloud certificates (EUCS in future, BSI C5 today) provide structured evidence for provider assessments.

ISO/IEC 27001 as the foundation

EUCS builds on ISO/IEC 27001 and 27017. A living ISMS is the most efficient basis to later rise to an EUCS level without duplicated work.

BSI C5 as today's bridge

Until EUCS is in force, BSI C5 is the dependable, attestation-based proof of cloud security in the DACH region – and the best starting point for later EUCS maturity.

How we proceed together

A pragmatic path from baseline to EUCS readiness.

01

1 · Scope & gap analysis

We define the relevant cloud service, the target assurance level and the distance to existing attestations (ISO 27001, BSI C5).

02

2 · Bridge via BSI C5

We establish or strengthen your BSI C5 attestation as dependable proof today and document controls so they connect to EUCS.

03

3 · EUCS readiness mapping

We map your controls onto the current EUCS draft, identify gaps per level and prioritise the uplift.

04

4 · Monitoring & tracking

We set up continuous monitoring and track the legislative process so you can certify without delay once the final scheme lands.

Frequently asked questions about EUCS

Clear answers on status and practical meaning.

Is EUCS already applicable law?

No. EUCS is a candidate scheme and has not yet been adopted as a Commission implementing act. The timeline has slipped repeatedly; we communicate it as "in preparation".

Which assurance levels are planned?

The current draft foresees three assurance levels: Basic, Substantial and High. They scale the depth of evaluation and the attacker model.

What about the sovereignty requirements?

The originally contentious sovereignty / immunity requirements for the highest level were softened or dropped in later drafts (as of 2024). The final text remains to be seen.

What can I already do today?

Rely on BSI C5 as a dependable cloud attestation and a living ISO/IEC 27001 ISMS. Both connect to EUCS and protect you from duplicated work.

How does EUCS relate to NIS2 and DORA?

Both frameworks require managing cloud and ICT third-party risk. A harmonised cloud seal like EUCS becomes the obvious evidence – bridged today by BSI C5.

EUCS readiness without flying blind

We raise your cloud evidence to BSI C5 level today and keep it EUCS-ready – so you are prepared the moment the scheme takes effect.