Cybersecurity certification

Cybersecurity certification involves evaluating and verifying the security compliance of ICT products, services and systems against established standards.

European Union (EU) cybersecurity certificates provide consumers and businesses with standardized information about the security assurance of certified ICT products, services and systems. While certification does not guarantee complete cybersecurity, it does demonstrate compliance with the criteria of cybersecurity scheme. Under the Cybersecurity Act (CSA), the EU is creating a unified, voluntary framework to enhance trust and transparency in the digital market.

The organization of certification in the field of cybersecurity in Estonia (figure in Estonian only).pdf | 524.89 KB | pdf

Cybersecurity certification is regulated by the following legislation:

Cybersecurity Act

Cybersecurity Act (CSA)

Product Conformity Act

European standardisation regulation

Regulation (EC) No 765/2008 of the European Parliament and of the Council

Cyber Resilience Act (CRA)

NIS2 Directive

National Cybersecurity Certification Authority (NCCA)

The Consumer Protection and Technical Regulatory Authority (CPTRA) is the National Cybersecurity Certification Authority (NCCA-EE) in accordance with §13¹ of the Cybersecurity Act. The CPTRA oversees the implementation of cybersecurity certification schemes in line with the EU Cybersecurity Act (CSA). The main responsibilities include:

  • enforcing rules for cybersecurity certification schemes;
  • ensuring compliance with certification requirements for ICT products, services and systems;
  • supporting national accreditation bodies in overseeing conformity assessment bodies;
  • monitoring developments in cybersecurity certification.

EU Cybersecurity Certification Schemes

Certification schemes have been established under the EU Cybersecurity Act (CSA) to establish a unified approach to cybersecurity certification in the European internal market. The certification scheme certificates are applicable across the EU and valid in all member states.

The CPTRA issues a license to a Conformity Assessment Body (CAB) for cybersecurity certification in accordance with §13² of the Cybersecurity Act to a CAB that has been accredited in accordance with Regulation (EC) No 765/2008 of the European Parliament and of the Council.

List of certification schemes

European Common Criteria-based cybersecurity certification scheme (EUCC)

Conformity Assessment Bodies (CABs)

To certify and/or evaluate ICT products, services and systems in Estonia, an organization must become a Conformity Assessment Body (CAB). CABs can carry out both certification and evaluation activities, as long as these activities are separated.

Organizations interested in becoming a CAB must:

  • meet the requirements set out in the CSA;
  • obtain accreditation from national accreditation body appointed pursuant to Regulation (EC) No 765/2008;
  • meet the requirements of the relevant EU cybersecurity certification scheme;
  • apply for authorization through the NCCA-EE.

Once licensed, a CAB is listed on the European ENISA Certification website. While Estonian-issued certificates are recognized across the EU, their oversight is managed nationally by NCCA-EE.

For guidance on the process, contact the CPTRA at [email protected].

List of accredited CABs

Currently, no CABs are accredited in Estonia.

Last updated: 12.05.2026

search block image