How European cybersecurity certification schemes and standards fit compliance: when Member States may mandate certified ICT products or services, and the role of European and international standards.
NIS2 does not impose a single mandatory certification regime on all entities. Instead, it creates a layered architecture in which Member States hold a permissive power to require certification, the Commission holds a residual power to mandate it by delegated act, and standardisation operates as a voluntary but actively encouraged convergence tool. Understanding these three tiers is essential for compliance planning.
In order to demonstrate compliance with particular requirements of Article 21, Member States may require essential and important entities to use particular ICT products, ICT services, and ICT processes, developed by the essential or important entity or procured from third parties, that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881 (the Cybersecurity Act) 32022L2555 Article 24@2022-12-27. This power is explicitly framed as an option, not an obligation: a Member State that judges certification necessary to demonstrate compliance with particular requirements of Article 21 may impose it; one that does not considers its existing measures sufficient 32022L2555 Article 24@2022-12-27.
The same paragraph also requires Member States to encourage essential and important entities to use qualified trust services 32022L2555 Article 24@2022-12-27. "Encourage" is a lower threshold than "require" — it implies guidance, procurement incentives, or supervisory expectations rather than a hard legal obligation.
The Commission is empowered to adopt delegated acts, in accordance with Article 38, specifying which categories of essential and important entities are required to use certain certified ICT products, ICT services, or ICT processes, or to obtain a certificate under a European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. Those delegated acts shall be adopted where insufficient levels of cybersecurity have been identified, and must include an implementation period, giving affected entities time to comply 32022L2555 Article 24@2022-12-27.
Before adopting such acts, the Commission must carry out an impact assessment and conduct consultations in accordance with Article 56 of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. This procedural safeguard reflects the economic weight of mandatory certification requirements across critical sectors.
A practical obstacle can arise: no appropriate European cybersecurity certification scheme for the purposes of paragraph 2 of this Article may yet be available. In that situation, the Commission may, after consulting the Cooperation Group and the European Cybersecurity Certification Group, request ENISA to prepare a candidate scheme pursuant to Article 48(2) of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. This provision ensures that the certification architecture can expand to cover emerging or previously unaddressed technology categories without leaving a permanent gap in the mandatory-certification toolkit.
Alongside certification, Article 25 addresses how harmonised technical practice develops across Member States. Member States must encourage the use of European and international standards and technical specifications relevant to the security of network and information systems, for the purpose of promoting convergent implementation of the Article 21 security measures 32022L2555 Article 25@2022-12-27.
Critically, this obligation is technology-neutral: Member States must act without imposing or discriminating in favour of the use of a particular type of technology 32022L2555 Article 25@2022-12-27. That clause prevents standards mandates from functioning as de facto market-access barriers or from locking entities into proprietary ecosystems.
ENISA is assigned a supporting role: in cooperation with Member States and, where appropriate, after consulting relevant stakeholders, it must draw up advice and guidelines regarding the technical areas to be considered in relation to the standardisation objective, as well as regarding already existing standards — including national standards — that would allow those areas to be covered 32022L2555 Article 25@2022-12-27. ENISA's output is advisory, not binding.
For entities in scope, the practical takeaways are:
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
The following items are labeled illustrative context, not regulation.
No recent cases are cached for this topic.
1. What triggers the Commission's power to adopt delegated acts mandating certification under Article 24(2)?
The Commission may adopt delegated acts specifying mandatory certification requirements only where insufficient levels of cybersecurity have been identified, and those acts must include an implementation period for affected entities. 32022L2555 Article 24@2022-12-27
2. Under Article 24(1), what is a Member State's obligation with respect to qualified trust services?
Article 24(1) uses "encourage" for qualified trust services, a lower threshold than the "may require" power available for ICT product and service certification. 32022L2555 Article 24@2022-12-27
3. What procedural safeguard must the Commission complete before adopting delegated acts under Article 24(2)?
Before adopting delegated acts under Article 24(2), the Commission must carry out an impact assessment and conduct consultations in accordance with Article 56 of Regulation (EU) 2019/881. 32022L2555 Article 24@2022-12-27
4. When no suitable European cybersecurity certification scheme exists for the purposes of Article 24(2), what step may the Commission take?
Article 24(3) allows the Commission to request ENISA to prepare a candidate scheme under Article 48(2) of Regulation (EU) 2019/881, but only after consulting the Cooperation Group and the European Cybersecurity Certification Group. 32022L2555 Article 24@2022-12-27
5. What constraint does Article 25 place on Member States when encouraging the use of standards?
Article 25 requires Member States to encourage standards use without imposing or discriminating in favour of a particular type of technology, preventing standards mandates from acting as de facto market-access barriers or proprietary lock-in. 32022L2555 Article 25@2022-12-27