ctipilot.ch

EU Managed Security Services (EUMSS) certification scheme

policy · policy:enisa-eumss-certification-scheme-2026 single-source-national-cert

Draft ENISA certification scheme for EU Managed Security Services under the Cybersecurity Act, in public consultation 2026-07-24 to 2026-09-13; mandatory baseline requirements across five domains plus a first vertical for Incident Response services, and mandatory within two years for providers operating under the EU Cybersecurity Reserve.

Aliases: EUMSS certification

Coverage timeline
1
first 2026-07-26 → last 2026-07-26
Peak priority
notable
1 notable
Sources cited
3
1 hosts
Sections touched
1
weekly-policy
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-07-26ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action Plan
    weekly-policyTwo ENISA moves turn guidance into procurement gates — a mandatory EUMSS certification for Reserve providers, and EU hospital-procurement security rules

Where this entity is cited

  • weekly-policy1

Source distribution

  • enisa.europa.eu3 (100%)

explore in graph

Entries about EU Managed Security Services (EUMSS) certification scheme (1)

2026-07-26 · view entry permalink →

NOTABLENATOA2

ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action Plan

Two ENISA developments landed inside 2026-W30 that share a direction — moving cyber-assurance from advisory guidance into procurement leverage — and both reach this constituency through its supplier and sector tail rather than through any direct Swiss obligation.

The more operationally consequential is the EU Managed Security Services (EUMSS) certification scheme, on which ENISA opened a public consultation on 2026-07-24, open until 2026-09-13. The draft uses a layered structure — mandatory baseline requirements across five domains that "apply as a mandatory prerequisite for each certified service profile" (ENISA, 2026-07-24), plus service-specific verticals, the first of which targets Incident Response services. The load-bearing clause is that any managed-security provider delivering services under the EU Cybersecurity Reserve — the EU's pooled incident-response capacity drawn on during major cross-border crises — must hold EUMSS certification within two years of the scheme's entry into force, which turns a voluntary certification into a procurement gate for that pool of providers. For a Swiss or European public-sector body or CI operator, that makes EUMSS a concrete future criterion in MSSP and IR-retainer selection, and a reason to comment during the consultation window if a current or prospective supplier would need the certification to remain eligible.

The second is the EU Health Action Plan: ENISA signed a EUR 6 million, three-year Contribution Agreement with the European Commission (ENISA, 2026-07-22) to stand up a health-sector cyber support mechanism, and published its first concrete deliverable — updated procurement guidelines for the cybersecurity of hospitals and healthcare providers, developed with the NIS Cooperation Group and the EU Health ISAC. Although Switzerland sits outside the EU's own funding scope, the procurement guidance is directly usable by any Swiss or European public hospital or cantonal health authority as ready-made contract and RFP language for medical devices, hospital IT and connected-care systems.

These baseline requirements apply as a mandatory prerequisite for each certified service profile.

A Contribution Agreement of EUR 6 million was signed between ENISA and the European Commission. This Contribution Agreement is set for three years

ENISA 2026-07-24
policy26 Jul 23:48Zsingle-source · national CERTOpen finding ↗
Sources: ENISA