← Course outline
Aavistus Training · nis2 · NIS.07

Certification and standardisation

What you'll learn

How European cybersecurity certification schemes and standards fit compliance: when Member States may mandate certified ICT products or services, and the role of European and international standards.

Regulation — cited to the current EU text

Overview

NIS2 does not impose a single mandatory certification regime on all entities. Instead, it creates a layered architecture in which Member States hold a permissive power to require certification, the Commission holds a residual power to mandate it by delegated act, and standardisation operates as a voluntary but actively encouraged convergence tool. Understanding these three tiers is essential for compliance planning.

Member State power to require certification (Article 24(1))

In order to demonstrate compliance with particular requirements of Article 21, Member States may require essential and important entities to use particular ICT products, ICT services, and ICT processes, developed by the essential or important entity or procured from third parties, that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881 (the Cybersecurity Act) 32022L2555 Article 24@2022-12-27. This power is explicitly framed as an option, not an obligation: a Member State that judges certification necessary to demonstrate compliance with particular requirements of Article 21 may impose it; one that does not considers its existing measures sufficient 32022L2555 Article 24@2022-12-27.

The same paragraph also requires Member States to encourage essential and important entities to use qualified trust services 32022L2555 Article 24@2022-12-27. "Encourage" is a lower threshold than "require" — it implies guidance, procurement incentives, or supervisory expectations rather than a hard legal obligation.

Commission power to mandate certification by delegated act (Article 24(2))

The Commission is empowered to adopt delegated acts, in accordance with Article 38, specifying which categories of essential and important entities are required to use certain certified ICT products, ICT services, or ICT processes, or to obtain a certificate under a European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. Those delegated acts shall be adopted where insufficient levels of cybersecurity have been identified, and must include an implementation period, giving affected entities time to comply 32022L2555 Article 24@2022-12-27.

Before adopting such acts, the Commission must carry out an impact assessment and conduct consultations in accordance with Article 56 of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. This procedural safeguard reflects the economic weight of mandatory certification requirements across critical sectors.

Gap-filling: requesting a new ENISA candidate scheme (Article 24(3))

A practical obstacle can arise: no appropriate European cybersecurity certification scheme for the purposes of paragraph 2 of this Article may yet be available. In that situation, the Commission may, after consulting the Cooperation Group and the European Cybersecurity Certification Group, request ENISA to prepare a candidate scheme pursuant to Article 48(2) of Regulation (EU) 2019/881 32022L2555 Article 24@2022-12-27. This provision ensures that the certification architecture can expand to cover emerging or previously unaddressed technology categories without leaving a permanent gap in the mandatory-certification toolkit.

Standardisation as a convergence mechanism (Article 25)

Alongside certification, Article 25 addresses how harmonised technical practice develops across Member States. Member States must encourage the use of European and international standards and technical specifications relevant to the security of network and information systems, for the purpose of promoting convergent implementation of the Article 21 security measures 32022L2555 Article 25@2022-12-27.

Critically, this obligation is technology-neutral: Member States must act without imposing or discriminating in favour of the use of a particular type of technology 32022L2555 Article 25@2022-12-27. That clause prevents standards mandates from functioning as de facto market-access barriers or from locking entities into proprietary ecosystems.

ENISA is assigned a supporting role: in cooperation with Member States and, where appropriate, after consulting relevant stakeholders, it must draw up advice and guidelines regarding the technical areas to be considered in relation to the standardisation objective, as well as regarding already existing standards — including national standards — that would allow those areas to be covered 32022L2555 Article 25@2022-12-27. ENISA's output is advisory, not binding.

Compliance implications

For entities in scope, the practical takeaways are:

  • Check whether your Member State has activated the Article 24(1) power for your sector. If it has, certification under the relevant European scheme is a legal requirement for demonstrating compliance with particular requirements of Article 21, not merely a best practice.
  • Monitor Commission delegated-act activity. If your entity category is named in a future delegated act, certification will become mandatory regardless of Member State discretion, and the implementation period in that act is the deadline.
  • Treat European and international standards referenced in ENISA guidance as the default technical baseline; aligning with them is the lowest-friction path to demonstrating proportionate security measures.
  • Member States are required to encourage entities to use qualified trust services; check whether your competent authority has issued corresponding sector guidance.
Your operations manual

This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following items are labeled illustrative context, not regulation.

No recent cases are cached for this topic.

Check your understanding

1. What triggers the Commission's power to adopt delegated acts mandating certification under Article 24(2)?

2. Under Article 24(1), what is a Member State's obligation with respect to qualified trust services?

3. What procedural safeguard must the Commission complete before adopting delegated acts under Article 24(2)?

4. When no suitable European cybersecurity certification scheme exists for the purposes of Article 24(2), what step may the Commission take?

5. What constraint does Article 25 place on Member States when encouraging the use of standards?