Threat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 06.08.2026 10:36 CET100 dossiersMITRE ATT&CK mapping

Editorial explainer · official sources (ENISA, EUR-Lex)medium

Certifying your defenders: Europe's draft scheme for managed security services

On 24 July 2026 ENISA opened the public consultation on the draft European certification scheme for Managed Security Services (EUMSS): the first time the Union has tried to define what can be demanded of those who sell security as a service. The scheme stems from a Commission request under Article 48(1) of the Cybersecurity Act and from an extension of ENISA's mandate introduced by Regulation (EU) 2025/37. It is a draft under consultation, not law in force: feedback is being collected until 13 September 2026. That is precisely why it is worth reading now — this is the moment when the text can still change.

The problem this scheme tries to solve

Anyone buying cybersecurity as a service faces a structural problem: they cannot verify what they are buying.

A company that outsources network monitoring, incident response or a penetration test is purchasing something it cannot, by definition, do itself. If it could, it would not be buying it. And when the invoice arrives, the document it receives describes an activity, not its quality. A flawless monitoring report is indistinguishable, to the reader, from a flawless monitoring report produced by a monitoring system that was not watching the right things.

It is the same problem posed by choosing an auditor or a testing laboratory: the historical answer is third-party certification. Applied to cybersecurity, it is arriving now.

Where it comes from

The EUMSS scheme is not an autonomous ENISA initiative. It is a formal request from the European Commission, made on 25 April 2025 under Article 48(1) of the Cybersecurity Act, the provision allowing the Commission to ask the Agency to prepare a candidate certification scheme.

Upstream sits a legislative step: Regulation (EU) 2025/37 of 19 December 2024, amending Regulation (EU) 2019/881 «as regards managed security services». This is the act that extends the European certification framework to a category previously outside it — services, that is, and not only products and processes.

The dedicated working group began its work on 13 October 2025. On 24 July 2026 ENISA opened the public consultation, which closes on 13 September 2026.

  1. 19 December 2024
    The legal basis

    Regulation (EU) 2025/37: managed services enter the certification framework.

  2. 25 April 2025
    The request

    The Commission asks ENISA for the scheme, under art. 48(1) of the Cybersecurity Act.

  3. 13 October 2025
    The work begins

    The EUMSS ad hoc working group is convened.

  4. 24 July 2026
    The consultation

    ENISA publishes the draft and opens for feedback.

  5. 13 September 2026
    The deadline

    Closing date for responses to the public consultation.

What it covers, and how it is built

The definition of managed security services, per ENISA's dedicated page, «covers areas such as incident response, penetration testing, security audits and consultancy». That is a wide perimeter: not just the SOC watching the alerts, but also whoever gets called once the incident has already happened, and whoever checks whether the defences hold.

The structure has two layers.

The horizontal layer contains the baseline requirements, mandatory for all certified services and — this is the surprising part — identical across all three assurance levels provided for by the Cybersecurity Act: basic, substantial, high. ENISA states it explicitly: «These baseline requirements apply as a mandatory prerequisite for each certified service profile». There are five domains: secure service and platform design; deployment and transition management; availability and continuity management; operational service management; continuous improvement and technology maintenance.

The vertical layer contains the specific profiles. Today there is only one: the Incident Management Lifecycle vertical, Incident Response profile.

The fact that baseline requirements do not change across the three levels is an interesting design choice. It says there is a floor below which a security service is not a security service, regardless of what it costs. The assurance levels distinguish the rigour of the assessment, not the existence of the controls.

  1. 01
    Horizontal layer
    five domains, mandatory across all three assurance levels
  2. 02
    Vertical layer
    the service profiles · today only Incident Response
  3. 03
    Certification
    three levels — basic, substantial, high — on the rigour of assessment

The one obligation already written down

European certification schemes are, as a rule, voluntary: that is the design of Article 56 of the Cybersecurity Act, and the ENISA announcement does not describe EUMSS as mandatory.

With one exception already fixed, and worth knowing because it is the first concrete foothold: providers delivering services under the EU Cybersecurity Reserve will have to be certified under EUMSS «within 2 years once the scheme is in place». The Reserve is the European mechanism that keeps incident response providers on standby, activatable in the event of a significant cyber crisis in a Member State.

It is a small detail with legible logic: certification starts being demanded from those who get called when things go seriously wrong.

Why it is worth reading now even if it does not apply to you

Anyone who buys these services currently holds a document that is useful regardless of its regulatory fate: a list of legitimate questions to put to a supplier.

The five horizontal domains translate, without much effort, into five contractual questions. How is the platform my data runs on designed. What happens when the service is switched on, and when it is wound down. What continuity is guaranteed, and with what numbers. How is delivery managed operationally, and by whom. How is the technology you are paying for kept current.

These are questions that can be asked today, without waiting for any scheme. What certification will change, if and when it arrives, is not that the questions become possible: it is that the answer will have to be verified by someone other than the supplier.

5
horizontal domains
mandatory for every profile and every level
3
assurance levels
basic, substantial, high
2
years granted
to EU Cybersecurity Reserve providers, from entry into force

What to do

If you deliver managed security services, respond to the consultation by 13 September. This is when the text can still be changed, and the providers who take part are also the ones who will arrive prepared.

If you buy them, read the five domains and compare them against the contract you have. Not to challenge it: to see which of those five areas are not written down anywhere.

Do not expect certification to answer the hardest question. A certified service demonstrates that a process has been described and verified against a standard. It does not demonstrate that it is working today, for you, against whoever is attacking you right now. It is a real improvement on the starting point, not a substitute for oversight.

What is not yet true

This needs stating plainly, because it is the thing most easily misread: EUMSS is a draft under consultation, not law in force. It will become binding only through a Commission implementing act, and no date has been announced for that step.

Two further clarifications. The description of the five domains in this article comes from ENISA's 24 July announcement, not from reading the draft technical document. And there is a date discrepancy between sources worth flagging: ENISA writes «On 15 January 2025 the Commission adopted an amendment», while EUR-Lex dates Regulation 2025/37 to 19 December 2024, published in the Official Journal on 15 January 2025. These are the adoption and publication dates: not an error, but two numbers that appear to contradict each other side by side.

More dossiers