European Digital Certification Agency
Independent Certification for Secure and Trusted Technology
Building Trust in European Technology
The Agency assesses IT startups, digital products and technology companies against defined requirements for cybersecurity, data protection, operational reliability and responsible technology management.
Verify a certificate
Enter a certificate number to confirm its holder, scope and current status in the public register.
Every certificate carries a QR code linking to its entry in the register.
The Agency
An assessment, not an endorsement
The European Digital Certification Agency is an independent certification organisation established in 2023 and registered in Republic of Estonia. It examines how technology companies actually manage security, personal data, service continuity and the systems they build — and states what it found, in writing, against a published standard.
Certification is not a marketing exercise. An assessment establishes what an organisation does, evidences it, and identifies where it falls short. Where requirements are not met, the Agency says so and the certificate is not issued until they are.
More about the Agency, its governance and its independence rules →
Why organisations certify
- Shorten enterprise security reviews. A certificate with a published scope answers most of a customer's due diligence questionnaire before it is sent.
- Give investors evidence, not assurances. Technical due diligence is faster when controls have already been examined by a third party.
- Find weaknesses while they are cheap. The preliminary assessment identifies gaps before an audit, and long before an incident.
- Meet contractual and procurement requirements. Many buyers require documented, independently verified security controls from suppliers.
- Demonstrate data protection compliance. Assessment against EDCA-STD-02 covers the accountability obligations of Regulation (EU) 2016/679.
- Show status publicly and verifiably. Every certificate is listed in an open register that any third party can check.
Certification programmes
Six programmes, each governed by a published standard
An organisation may hold certification under more than one programme. Each assessment is bounded by a scope agreed in writing before it begins.
Startup Security Certification
An assessment designed for early-stage technology companies, proportionate to their size and stage, establishing that essential security and data protection controls are in place and operating.
Programme details → EDCA-P02 · EDCA-STD-03Software Product Certification
An assessment of a defined software product rather than the organisation as a whole, covering how the product is designed, built, tested and released, and how vulnerabilities are handled.
Programme details → EDCA-P03 · EDCA-STD-02Data Protection Certification
An assessment of the lawfulness, transparency and accountability of personal data processing, including data subject rights, international transfers and retention practice.
Programme details → EDCA-P04 · EDCA-STD-04Cloud Security Certification
An assessment of cloud and hosted infrastructure, covering configuration baselines, tenancy separation, network controls, secrets management and recovery capability.
Programme details → EDCA-P05 · EDCA-STD-05AI Governance Certification
An assessment of how artificial intelligence systems are governed: their intended purpose, the data behind them, human oversight, the information given to users, and monitoring after deployment.
Programme details → EDCA-P06 · EDCA-STD-07Crypto-Asset Service Certification
An assessment of organisations that hold, transfer, exchange or administer crypto-assets on behalf of others. It examines how private keys are generated and kept, who can move client funds and under what approval, whether client assets are segregated and reconcilable, and how counterparties and addresses are screened.
Programme details →Not sure which applies?
Describe what you build and where your data sits. The Agency will confirm the appropriate programme and level, at no cost and with no commitment.
Ask the Agency →Certification levels
Four levels, from first controls to sustained assurance
The level reflects the depth of the assessment and the maturity evidenced, not the size of the organisation. It is recorded in the certificate number itself.
EDCA Startup Ready
Confirms that an early-stage organisation has established the baseline security, data protection and governance controls expected of a technology company handling customer data.
Valid 24 monthsEDCA Security Verified
Confirms that security controls are not only documented but operating, evidenced by technical testing and a review of records covering a period of continuous operation.
Valid 24 monthsEDCA Advanced Compliance
Confirms a managed compliance function: risks, controls and obligations are tracked, measured and reported to management on a defined cycle, and the organisation can evidence improvement.
Valid 36 monthsEDCA Trusted Technology
The highest level issued by the Agency. Confirms mature, independently evidenced governance across security, data protection, resilience and responsible technology management, sustained over more than one certification cycle.
Valid 36 monthsFor startups
Proportionate to your stage
A twelve-person company is not assessed as though it were a bank. The EDCA Startup Ready level exists so that an early-stage team can evidence the controls that matter to its first enterprise customers, without pretending to a maturity it has not yet built.
The process in outline
- Application and scope review
- Preliminary assessment and gap analysis
- Certification audit
- Corrective action
- Decision by the Certification Committee
- Issue of certificate and publication in the register