Labs, Certification Bodies & Scheme Operators

The assurance market is being redrawn. We help you own your part of it.

CRA notified-body slots, EUCC authorisations, wallet CAB accreditations, new schemes under a Cybersecurity Act in review — the biggest expansion of Europe’s conformity assessment market in decades is happening now, on a deadline. We work for the ecosystem’s operators: your scheme, your scope, your capacity.

LABS / ITSEF ISO 17025 CBs / NBs ISO 17065 AUTHORITIES NCCA · NAB SCHEME OWNERS public & private THE SCHEME

The landscape

Four seats at the assurance table. We've sat in all of them.

This page is not about getting certified. It is about building, operating and scaling the machinery that certifies everyone else.

Evaluation labs & ITSEFs

You face scope decisions with long payback periods: EUCC authorisation for AVA_VAN.4/5, RED and CRA testing capacity, SESIP and NESAS accreditations, wallet evaluation readiness. Each scope is an investment in people, methodology and accreditation audits — sequenced right, they compound; sequenced wrong, they cannibalise your senior evaluators. We help you choose scopes, build methodologies, train evaluators and pass witness assessments.

ISO 17025

SCOPE STRATEGY

Certification bodies — and aspiring notified bodies

The CRA notification window is open: notifying authorities operate since June 2026, and member states must ensure sufficient notified-body capacity by December 2026. Early NANDO listings will absorb the Class II and critical-product demand surge. We build your notification file, your competence matrix, your impartiality architecture and your assessment procedures — against the CRA’s Annex, not a generic 17065 template.

CRA ART. 35+

NANDO

National authorities: NCCAs, notifying authorities, regulators

You are standing up supervision for EUCC, preparing wallet certification schemes under Article 5c, notifying CABs under the CRA, and answering Brussels on scheme feedback — often with a team a fraction the size of the industry it oversees. We provide the technical depth behind the institutional role: scheme analysis, authorisation methodologies, peer-review preparation, and honest assessments of what your market can actually deliver.

NCCA

ART. 5c SCHEMES

Scheme owners: industry consortia, SDOs, programme operators

Private schemes are how the market moves faster than regulation — SESIP became EN 17927, NESAS became the EU5G substrate, ioXt administers the US Cyber Trust Mark. A scheme that wants that trajectory needs evaluation methodology, governance, lab qualification rules and a regulatory convergence strategy designed in from the start. We have written scheme documents that survived that journey.

SCHEME DESIGN

GOVERNANCE

The clock is running

Capacity decisions made this year set market position for a decade

Every date below is a demand shock for evaluation and certification capacity. The bodies ready before each one owns the queue behind it.

27 Feb 2026 DONE

SOG-IS transition closed

EUCC is the only European CC route. CBs and ITSEFs without EUCC accreditation and NCCA authorisation are out of the smartcard-and-secure-element market; those with it inherit the entire pipeline.

11 Jun 2026 OPEN

CRA notification machinery operational

Notifying authorities designated; conformity assessment bodies can file for notification. The queue has started.

Now – Dec 2026 WEEKS AWAY

Three accreditation races run in parallel

CRA notified-body files, EUDI wallet CAB accreditations for the December wallet deadline, and EUCC scope extensions — all drawing on the same accreditation bodies, the same technical assessors, and your same senior staff. Sequencing is strategy.

11 Dec 2026

Member states must ensure sufficient CRA NB capacity

A political commitment that translates into pressure on notifying authorities to process files — and an opening for well-prepared applicants.

2026–2027

Cybersecurity Act review reshapes the scheme pipeline

EUCS's fate, faster scheme-adoption mechanics, possibly new scheme requests (managed services, EU5G adoption). Scheme owners and authorities who engage in the review shape the rules they will operate under.

11 Dec 2027

CRA full application — demand peak

Every Class II and critical product needs a notified body; every default-category manufacturer wants reassurance. Simultaneously, CC 3.1 sunsets under EUCC. The capacity crunch is fully priced in — by those who prepared.

How we work

Six things we build for assurance operators

1

Scope & market strategy

Which accreditations, authorisations and notifications, in which order — modelled against demand curves per scheme, not ambition.

2

Accreditation & notification files

ISO 17025/17065 systems, competence matrices, impartiality analyses, CRA notification dossiers — written to pass witness assessment, not just document review.

3

Evaluation methodology

Methodologies, attack-potential adaptations, test specifications and reporting templates for new scopes — EUCC, SESIP, RED, CRA, wallet schemes.

4

Scheme creation & drafting

Full scheme documents: requirements, assurance levels, lab qualification, certificate lifecycle, dispute and maintenance procedures, governance charters.

5

Evaluator & certifier training

Hands-on training built by people who have evaluated, certified and been audited — from CC fundamentals to scheme-specific practice.

6

Policy & regulatory engagement

CSA review positions, ECCG/SCCG input, scheme feedback to ENISA and the Commission — technically grounded, strategically aimed.

Independence is the product

We do not run a lab, own a CB or sell evaluations. That is precisely why labs, CBs, authorities and scheme owners can all hire us — including against each other’s assessments — without a conflict clause in sight.

PLATFORM CERT Labs / ITSEFs CBs / NBs Authorities Scheme owners SDOs / consortia EU institutions

For the specialists

The state of the assurance ecosystem, honestly

You know your own domain better than any consultant. Our value is the view across all of them — and the willingness to say uncomfortable things in writing.

The CRA notified-body market: economics and timing

The CRA creates the largest new conformity assessment market in Europe since the original New Approach directives — every important and critical product class funnels through notified bodies from December 2027, with Implementing Regulation 2025/2392 defining 26 categories of demand. The framework is deliberately front-loaded: notifying authorities since June 2026, a capacity obligation on member states by December 2026, precisely because the Commission fears a repeat of the MDR notified-body bottleneck.

The economics favour early movers disproportionately. Notification takes months even with a clean file; competence must be demonstrated per module and per product category; and manufacturers will book assessment slots the moment harmonised standards clarify their routes — late 2026 onward. A body notified in early 2027 sells into a seller’s market; one notified in 2028 buys market share against incumbents with reference clients.

The competence question is the real filter. CRA assessment spans secure development process review and product-level technical evaluation — a combination most existing product-safety NBs lack on the security side, and most security labs lack on the Module B/H procedural side. Partnerships and subcontracting structures are allowed but constrained; impartiality and competence-ownership rules bite exactly where bodies try to shortcut.

Our position: the winning play for most CBs is a narrow first notification — two or three Annex III categories where you can evidence real technical depth — filed now, extended later. A broad file signals shallow competence to any experienced assessor and slows the whole dossier. We build the narrow file that passes, and the extension roadmap behind it.

EUCC absorbed the SOG-IS world with less drama than feared — but the operational deltas are real and they surface in surveillance, not in initial accreditation. Certificate maintenance and patch management now follow scheme-defined processes rather than national custom; state-of-the-art documents (including composite evaluation for CC:2022) are living documents under ENISA governance; and the NCCA authorisation layer for level “high” adds a second oversight relationship that labs used to SOG-IS informality find bureaucratically heavier.

Two open fronts matter for planning. First, the CC:2022 migration: CC 3.1 evaluations remain acceptable only until end-2027, and the PP ecosystem is migrating unevenly — labs need evaluators fluent in both versions through the transition, which is a training and staffing problem more than a technical one. Second, mutual recognition: EUCC certificates circulate within the EU by regulation, but the relationship with CCRA recognition remains a live strategic question for labs serving global vendors — the answer differs by product category and target market, and getting it wrong strands a customer’s certification investment.

Our position: ITSEFs should treat CC:2022 fluency as this year’s differentiator — vendors are choosing labs now for evaluations that will land in 2027, and they are asking pointed questions about version competence. CBs should pressure-test their patch-management procedures before their first major certificate maintenance case does it for them, in front of the NCCA.

Article 5c wallet certification is the most compressed accreditation opportunity in the ecosystem: national schemes finalising through 2026, CABs accrediting against them in parallel, and a legal deadline — 24 December 2026 — that guarantees member states will need certified wallets faster than orderly process allows. No wallet is certified yet. Several member states have signalled they will miss the deadline; none has the luxury of missing it by much.

For CABs this cuts both ways. The demand is certain and immediate — every member state wallet, plus commercial wallet providers seeking the same recognition. But the assessment target is genuinely hard: wallet schemes compose Cybersecurity Act certificates (EUCC for the WSCD layer), eIDAS implementing-act requirements, and ARF conformance, with assurance-level questions still being interpreted differently across member states. Early assessments will set precedents under deadline pressure — including precedents about how much composition from hardware certificates a wallet evaluation can lean on.

Our position: CABs entering this market should invest in the composition methodology first — it is where every early wallet assessment will either save months or lose them. Authorities designing national schemes should resist inventing national assurance interpretations: divergence now becomes the mutual-recognition dispute of 2028.

Having drafted, operated and evaluated against schemes, we hold a short list of design decisions that decide a scheme’s trajectory long before adoption metrics do. Level architecture: schemes scale when levels map to attacker capability and evaluation effort simultaneously — SESIP’s five levels work because a buyer can price them; schemes with aspirational levels nobody orders stall at level one. Lab economics: qualification requirements must make a lab’s business case close at realistic volume, or you get two captive labs and a bottleneck that kills vendor interest. Reusability: schemes that consume other schemes’ results (composition) and produce results others can consume (recognition) get adopted as infrastructure; walled gardens get adopted as marketing.

And the regulatory trajectory must be designed, not hoped for. SESIP became EN 17927 because standardisation was pursued deliberately; NESAS became the EU5G substrate because GSMA engaged ENISA early and consistently. A private scheme that wants regulatory convergence needs its documents structured for it from the first draft — requirements separable from governance, evaluation methodology citable as a standard, IP arrangements that permit institutional adoption.

Our position: design the scheme for its second owner. If your scheme documents cannot survive being handed to a standards body or a regulator without renegotiation, you have built a product, not a scheme — legitimate, but a different business with a different ceiling.

The CSA review lands amid visible strain: EUCS blocked for six years by the sovereignty dispute, exactly one scheme operational after seven years of the framework, and member states relitigating governance through the ECCG. The review’s live questions matter operationally — whether scheme adoption moves to a faster or more political mechanism, whether sovereignty requirements get a legal home (in schemes, in procurement law, or in the Cloud Sovereignty Framework’s orbit), whether managed security services and other candidates enter the pipeline, and how the framework interacts with CRA presumption-of-conformity mechanics.

For scheme operators and authorities, the review is not a spectator event. Positions filed now shape whether the next five years of European certification run through a functioning pipeline or another EUCS-style impasse. For labs and CBs, the planning consequence is concrete: scope investments should be robust to both a faster scheme pipeline (more schemes, sooner, thinner each) and a stalled one (national and private schemes filling the gap, as they demonstrably do).

Our position: the ecosystem’s revealed preference is pragmatism — where EU schemes stall, national schemes (SecNumCloud, C5, BSI-NESAS) and private schemes take the market and are later absorbed rather than displaced. Build and advise on that pattern, not on the org chart Brussels intends. We say this in our review submissions too.

Every deadline on this page draws from one pool: experienced security evaluators and certifiers, of whom Europe produces far fewer per year than the 2026–2027 demand curve requires. Labs poach; CBs and authorities lose staff to industry; every new scheme adds training overhead to the same people. Accreditation bodies face the same squeeze — technical assessors for witness audits are scheduled months out, which silently gates every notification and scope-extension plan in this document.

The honest arithmetic: a competent CC or CRA evaluator takes 18–24 months to develop under supervision. Anyone planning 2027 capacity is describing hiring and training decisions that needed to start already — or a subcontracting and partnership structure that satisfies impartiality rules while sharing scarce competence.

Our position: structured evaluator development is the highest-ROI investment in this market, and it is chronically underbought compared to accreditation consulting. We build training programmes and competence frameworks precisely because the files we write are worthless without people who can execute them. Budget both, or budget neither.

Peer-level advice, in writing, with our name on it

We have drafted schemes, passed accreditations, trained evaluators and answered NCCAs. Bring your hardest scoping question — the first working session is where we earn the second.

Contact us

Request this document

We’ll send you access by email.