Services
Designing the technical, organizational and process backbone of trustworthy security evaluation and certification schemes.
Introduction
A security evaluation and certification scheme is the framework that establishes — and maintains — trust in cybersecurity products, processes and services. With ENISA’s reinforced mandate under the EU Cybersecurity Act, scheme proliferation is now a structural feature of the regulatory landscape.
Internet of Trust helps organizations design schemes that are technically credible, market-feasible and regulator-acceptable: technical and organizational requirements, evaluation methodologies, lab accreditation criteria, and certification processes.
This page outlines the three-step definition method, the four-axis writing scope, deliverables from Protection Profiles to communication plans, and the engagement modes for new schemes, scheme updates and requirements analysis against CRA, NIS 2 and sectorial mandates.
EU Cybersecurity Act
ENISA mandate
EUCC
EUCS
CRA
NIS 2
Process
A three-step definition method, iterative by construction, calibrated to the scheme owner’s ambition and to the ecosystem of stakeholders it must serve.
01
Identify the scheme owner’s goals and outline its principles. Associate a representative stakeholder group to integrate market expectations, domain-specific technology and life-cycle constraints.
02
Address four axes: scope, evaluation methodology and test requirements, lab accreditation criteria, and accreditation/evaluation/certification processes — the scheme’s backbone.
03
Iterative or end-of-cycle stakeholder review. For some schemes, validation includes formal approval by evaluation authorities or certification bodies.
Delivery plan
Deliverables span the four scheme axes — scope, methodology, processes and stakeholder communication — ready to be adopted by evaluation authorities, certification bodies and accredited laboratories.
Protection Profiles, PP-Modules, requirement catalogs and detailed questionnaires defining what is in and out of scope.
How labs perform assessments, standardized test plans, reporting criteria and templates.
Detailed instructions and documentation templates for scheme users, evaluators, certifiers and auditors.
Presentations, white papers, FAQs and stakeholder onboarding material.
Engagement modes
Three engagement shapes covering new schemes, scheme processes and analysis of existing frameworks.
Mode 01
Define evaluation scope, the requirements products must meet, and the methodology labs use to verify compliance — Protection Profiles, security guidelines, test plans, attack catalogs.
Mode 02
Design the accreditation, evaluation and certification process backbone — workflows, templates, decision criteria and appeal mechanisms.
Mode 03
Study existing schemes against new regulations or functional specifications — identify gaps, propose updates, support the maintenance of national or sectorial schemes.
Field record
Past engagements cover Protection Profile drafting for IoT platforms and connected industrial control, scheme update assessments under the EU Cybersecurity Act, lab accreditation criteria for sectorial schemes, and process design for national certification authorities transitioning to EUCC alignment.
We’ll send you access by email.