OTSecurity

ENISA launches draft EUMSS cybersecurity certification scheme for managed security services, seeks feedback


The European Union Agency for Cybersecurity (ENISA) launched a public consultation on the draft European Union Managed Security Services (EUMSS) cybersecurity certification scheme following work by its dedicated Ad Hoc Working Group. Developed at the request of the European Commission, the candidate scheme comes as ENISA finds that organizations are increasingly investing in cybersecurity technologies and outsourced services rather than expanding internal cybersecurity teams. The EUMSS scheme aims to address fragmented approaches and inconsistent requirements governing the delivery of managed security services across EU Member States.

Interested stakeholders are invited to submit feedback through the EU Survey as part of the public consultation by Sept. 13 this year.

“Common baselines can guarantee a level of confidence in services offered,” Juhan Lepassaar, ENISA executive director, said in a media statement last week. “This scheme can offer Member States trust in the services that reinforce their prevention and response capabilities, especially in the context of the EU Cybersecurity Reserve.”

The European Commission has requested ENISA to prepare a candidate European cybersecurity certification scheme for Managed Security Services pursuant to Article 48(1) of the Cybersecurity Act. ENISA established an Ad Hoc Working Group on Managed Security Services Certification to support the preparation of the candidate scheme, which kicked off its work in October 2025. The document currently under public consultation is the first version of the result of the work of ENISA with the support of the group.

The draft of the EUMSS scheme builds on existing European cybersecurity certification practices and assessment methodologies. It is also designed to provide a harmonized and proportionate framework that supports cross-border service provision and Union-level crisis response capabilities. 

The study examines the definition of managed security services in EU legislation and references to these activities across different regulatory texts. It also assesses the managed security services market, reviews international standards covering the various service categories, and analyses existing national cybersecurity certification schemes and assessment approaches across EU Member States. In addition, the study proposes a strategy for developing an EU cybersecurity certification scheme for managed security services.

“The development of the scheme is still ongoing. The structure of the scheme itself is now quite mature, so it could soon be transmitted to the Commission for translation into an Implementing Act,” ENISA said. “Therefore, the work will continue for several months to finalise these annexes and reference documents, with the collaboration of the ENISA EUMSS Ad Hoc Working Group.”

It added, “We are also considering the development of guidance to accompany the scheme, to help all stakeholders understand how to best apply the scheme, and we are seeking your advice in that matter, to help us focus on the most useful documents. The draft candidate EUMSS scheme is quite complex, and also a draft of what will become a legal document.”

The scheme follows a layered approach, consisting of a horizontal and a vertical layer. 

The horizontal layer outlines a common set of baseline requirements applicable to all Managed Security Services to be certified under this scheme. These baseline requirements apply as a mandatory prerequisite for each certified service profile. These are the same for all three established assurance levels (i.e. ‘basic’, ‘substantial’, and ‘high’). They cover various domains including secure service and platform design; deployment and transition management; availability and continuity management; operational service management; and continuous improvement and technology maintenance.

The vertical layer defines service-specific requirements applicable to particular managed security services and the service profiles included in these services. The present version of the scheme focuses on the ‘Incident Management Lifecycle’ vertical and more specifically on the ‘Incident Response’ service profile.

ENISA also recognized that development of the scheme can further support the EU Cybersecurity Reserve, as providers delivering services under the umbrella of the EU Cybersecurity Reserve have to be certified in accordance with the EUMSS within 2 years once the scheme is in place. 

Just last week, ENISA signed a contribution agreement with the European Commission to help the healthcare sector strengthen its cyber defenses against evolving threats. As one of its first deliverables under the EU Action Plan, ENISA published updated procurement guidelines to improve cybersecurity of hospitals and healthcare providers. The agreement’s primary objective is to implement the service catalogue, which currently groups Support Mechanism services into four categories, including preparedness, detection, response, and governance.



Source link