Skip to main content
Back to overview

NIS2 Certification: What Article 24 Actually Requires — and What EUMSS Means for MSPs

By NIS2Certify
nis2nis2-certificationarticle-24eucceumssmsp
NIS2 Certification: What Article 24 Actually Requires — and What EUMSS Means for MSPs

A procurement questionnaire lands on your desk. Question 14: "Please confirm your platform is NIS2 certified, and attach the certificate."

There is no such certificate. NIS2 certification does not exist as a conformity mark. NIS2 is a directive addressed to member states and to the entities they designate — not a badge you stick on a product.

The question is not stupid, though. It is badly worded. Behind it sits Article 24 of NIS2, a real obligation mechanism most consultants have never read, plus an EU certification framework that changed materially during 2026. Here is what actually applies.

Article 24 lets member states mandate certification — it does not create a certificate

The text is short, and worth knowing verbatim.

Article 24(1) says member states may require essential and important entities to use ICT products, services and processes — developed in-house or procured from third parties — that are certified under a European cybersecurity certification scheme adopted under Article 49 of Regulation (EU) 2019/881, the Cybersecurity Act. It adds that member states shall encourage the use of qualified trust services.

Two verbs, two very different weights. "May require" is a national option. "Shall encourage" is a nudge with no teeth.

Article 24(2) goes further. The Commission can adopt delegated acts specifying which categories of essential and important entities must use certified ICT or hold a certificate. Those acts are conditional: they are adopted where insufficient levels of cybersecurity have been identified, each must carry an implementation period, and each requires a prior impact assessment and consultation.

No such delegated act has been adopted. That is the most useful single fact to hand a client who is panicking about mandatory certification — the EU-wide mandate mechanism exists and is loaded, but it has not been fired.

Article 24(3) is the fallback. Where no appropriate scheme exists for a category the Commission wants to cover, it can ask ENISA to prepare a candidate scheme. That is exactly the route that produced the scheme managed service providers should be watching.

Only one European scheme is actually operational

Under the Cybersecurity Act the EU can adopt certification schemes. Exactly one has been adopted and is running: EUCC, the European Common Criteria-based scheme, established by Commission Implementing Regulation (EU) 2024/482 of 31 January 2024 and amended by Implementing Regulation (EU) 2024/3144.

EUCC covers ICT products — chips, smartcards, hardware, software. Not organisations. Not services. It is built on Common Criteria (ISO/IEC 15408) with the evaluation methodology in ISO/IEC 18045. Certificates have been issuable since February 2025, at two assurance levels: substantial and high.

Two details catch people out.

The standards transition. Until 31 December 2027, certificates can still be issued under the older Common Criteria 3.1 revision 5 family as well as under the CC:2022 / ISO/IEC 15408:2022 set. A certificate in your client's supplier pack may rest on either. Check which one before you treat it as current.

Mutual recognition is incomplete. EUCC certificates issued by a public certification body that is also a Common Criteria Recognition Arrangement authorising participant are recognised as before. Certificates from private certification bodies need an additional per-certificate oversight process by the national authority to carry the CCRA mark. If your client procures globally, a EUCC certificate is not an automatic worldwide passport.

The two schemes people assume exist do not. EUCS, the cloud services scheme, has been in draft since 2019 and remains unadopted, stuck on the sovereignty question around non-EU hyperscalers. EU5G is less mature still — no adopted scheme, no complete public draft. If a supplier claims their cloud is "EUCS certified," that is not currently possible.


The scheme that will hit MSPs is EUMSS

This is the part that matters if you sell security services rather than products.

On 15 January 2025 the Commission adopted an amendment to the Cybersecurity Act — Regulation (EU) 2025/37 — extending the certification framework to managed security services for the first time. The definition covers incident response, penetration testing, security audits and consultancy.

On 25 April 2025 the Commission formally requested ENISA to develop a candidate scheme. ENISA appointed an Ad Hoc Working Group, which held its kick-off on 13 October 2025. Draft candidate scheme v1.1 went out for public review, with the comment window closing on 13 September 2026.

Read that again if you run an MSP or MSSP. The EU is building a certification scheme for what you sell. Its stated purpose is to fix fragmented national requirements and enable cross-border service provision, which works in your favour. But it will also become the yardstick your clients' procurement teams reach for, and the thing Article 24 can eventually be used to mandate.

The draft is public. The comment window has closed, but reading it and mapping your service catalogue against it now is a cheap exercise with an obvious payoff. Nobody gets certified against a scheme they read for the first time on the day it is adopted. If you are still working out how the double obligation applies to you, start with NIS2 for MSPs and MSSPs.

Certification is evidence, not compliance

Here is the distinction that does the real work in an audit.

Article 21 obliges entities to take appropriate and proportionate technical, operational and organisational measures. Article 24 offers certification as one way to demonstrate compliance with particular requirements of Article 21. Demonstrate — not substitute.

A EUCC certificate on a firewall tells a supervisor that the product was evaluated against a defined security target at a defined assurance level. It says nothing about whether your client configured it correctly, patched it, monitored it, or included it in the risk analysis Article 21(2)(a) requires. Supervisors ask for operating evidence, not product paperwork. Our breakdown of the ten Article 21 measures shows how little of that surface any product certificate can cover.

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control

The same logic applies to ISO 27001. A certified ISMS is strong supporting evidence and will shorten an audit considerably, but it does not map one-to-one onto Article 21 — we covered that gap in NIS2 vs. ISO 27001.

Where certification genuinely moves the needle is supply chain. Article 21(2)(d) puts supplier security squarely inside the duty of care, and a certified component is far easier to defend there than a vendor assurance letter. That is where to use it — and where not to overreach. Demanding "EU-certified" cloud today writes an unsatisfiable clause into a contract. See what NIS2 does to supplier contracts for the wording that holds up.

What member states are actually doing with Article 24

The national option is being exercised unevenly, and the certification landscape underneath it shifted during 2026.

Germany. The NIS2 implementation act has been in force since 6 December 2025. Section 30 BSIG sets the risk management measures; Section 31 requires operators of critical facilities to demonstrate implementation to the BSI every three years, with the first proof due from particularly important entities by December 2028. Separately, Section 61 BSIG gives the BSI power to order audits, inspections and certifications and to require the resulting evidence. That is Article 24 with teeth attached.

Italy. ACN closed the national certification scheme that had run since 2004 on 27 February 2026. OCSI now operates as ACN's certification body for EUCC, under guidelines adopted by Directive Decree 12053 of 3 February 2025.

France. ANSSI stopped issuing new SOG-IS certificates on the same date, 27 February 2026, and is migrating in-scope products to EUCC while retaining CSPN and the Visa de sécurité for the domestic market.

The practical consequence: a supplier certificate issued under a national scheme in 2025 and a EUCC certificate issued in 2026 are not the same artefact, and the older one has a shelf life. Ask for the issue date and the scheme name, not just the logo on the PDF.

NIS2 Implementation Status by Country (2025–2026)

Fully in force

Belgium
Croatia
Hungary
Lithuania
Latvia
Italy
6 countries

Adopted — late 2025

Germany
Czech Republic
Finland
3 countries

In progress — expected 2026

Netherlands
France
Spain
Poland
Austria
Sweden
Ireland
7 countries

Three moves to make this week

Stop answering "is it NIS2 certified" with yes or no. Answer with what you actually hold: a EUCC certificate and its assurance level, an ISO 27001 certificate and its scope statement, a national scheme certificate and its expiry date, or an honest none-of-the-above plus the operating evidence that covers the same ground. Clients respect the second answer once you explain why the first does not exist.

Audit your supplier requirement templates for unsatisfiable clauses. Any demand for EUCS or EU5G certification should come out today. Replace it with specific control requirements and evidence obligations you can actually verify.

If you deliver managed security services, read the EUMSS draft and map your delivery model to it. You have a window before this becomes a procurement gate, and it will not stay open indefinitely.

The organisations that will struggle are not the ones without certificates. They are the ones that bought certificates instead of building the evidence trail Article 21 actually asks for, and only discover the difference when a supervisor asks how the certified product is operated.

If you want to know where your client's evidence actually stands against Article 21 before someone else asks, run a free NIS2 readiness scan and work from the gaps.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 Certification: What Article 24 Really Requires