Independent certification body · Registered in Republic of Estonia Standards Register Contact
European Digital
Certification Agency
Building trust in European technology

European Digital Certification Agency

Independent Certification for Secure and Trusted Technology

Building Trust in European Technology

The Agency assesses IT startups, digital products and technology companies against defined requirements for cybersecurity, data protection, operational reliability and responsible technology management.

Verify a certificate

Enter a certificate number to confirm its holder, scope and current status in the public register.

Every certificate carries a QR code linking to its entry in the register.

42 Certificates in force
42 Certified organisations
32 Countries represented
8 Published standards

The Agency

An assessment, not an endorsement

The European Digital Certification Agency is an independent certification organisation established in 2023 and registered in Republic of Estonia. It examines how technology companies actually manage security, personal data, service continuity and the systems they build — and states what it found, in writing, against a published standard.

Certification is not a marketing exercise. An assessment establishes what an organisation does, evidences it, and identifies where it falls short. Where requirements are not met, the Agency says so and the certificate is not issued until they are.

More about the Agency, its governance and its independence rules →

Why organisations certify

  • Shorten enterprise security reviews. A certificate with a published scope answers most of a customer's due diligence questionnaire before it is sent.
  • Give investors evidence, not assurances. Technical due diligence is faster when controls have already been examined by a third party.
  • Find weaknesses while they are cheap. The preliminary assessment identifies gaps before an audit, and long before an incident.
  • Meet contractual and procurement requirements. Many buyers require documented, independently verified security controls from suppliers.
  • Demonstrate data protection compliance. Assessment against EDCA-STD-02 covers the accountability obligations of Regulation (EU) 2016/679.
  • Show status publicly and verifiably. Every certificate is listed in an open register that any third party can check.

Certification programmes

Six programmes, each governed by a published standard

An organisation may hold certification under more than one programme. Each assessment is bounded by a scope agreed in writing before it begins.

EDCA-P01 · EDCA-STD-01

Startup Security Certification

An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.

Programme details →
EDCA-P02 · EDCA-STD-03

Software Product Certification

An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.

Programme details →
EDCA-P03 · EDCA-STD-02

Data Protection Certification

An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.

Programme details →
EDCA-P04 · EDCA-STD-04

Cloud Security Certification

An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.

Programme details →
EDCA-P05 · EDCA-STD-05

AI Governance Certification

An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.

Programme details →
EDCA-P06 · EDCA-STD-07

Crypto-Asset Service Certification

An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.

Programme details →

Not sure which applies?

Describe what you build and where your data sits. The Agency will confirm the appropriate programme and level, at no cost and with no commitment.

Ask the Agency →

Certification levels

Four levels, from first controls to sustained assurance

The level reflects the depth of the assessment and the maturity evidenced, not the size of the organisation. It is recorded in the certificate number itself.

Level I

EDCA Startup Ready

Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.

Valid 24 months
Level II

EDCA Security Verified

Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.

Valid 24 months
Level III

EDCA Advanced Compliance

Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.

Valid 36 months
Level IV

EDCA Trusted Technology

The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.

Valid 36 months

Full requirements for each level →

For startups

Proportionate to your stage

A twelve-person company is not assessed as though it were a bank. The EDCA Startup Ready level exists so that an early-stage team can evidence the controls that matter to its first enterprise customers, without pretending to a maturity it has not yet built.

What certification gives a startup

The process in outline

  1. Application and scope review
  2. Preliminary assessment and gap analysis
  3. Certification audit
  4. Corrective action
  5. Decision by the Certification Committee
  6. Issue of certificate and publication in the register

The full eight-stage process →