EUMSS: Three views on the EU’s draft Certification Scheme for Managed Security Services

Experts in incident response, cloud security and vulnerability management examine what the proposal could mean for providers and buyers.

In July 2026, the EU Agency for Cybersecurity (ENISA) published its draft certification scheme for managed security services, known as EUMSS. The public consultation closed on 13 September. The published scheme is still a draft, and its first service-specific profile focuses on incident response. It proposes common requirements for services covered by the scheme and three assurance levels: basic, substantial and high.

What should certification prove about a provider? How could it remain useful as threats and services change? And how should organisations use it when choosing a supplier? We put these questions to three specialists: Simon Jonker of Allurity company CSIS Security Group, Olov Norman of Allurity company Onevinn, and Maria Sivenkova of Allurity company SRLabs. Their answers follow in their own words.

Simon Jonker: What should the scheme prove?

Simon Jonker, Senior Director of MDR and IR at CSIS Security Group, addresses the purpose of the scheme, the difference between assurance levels and the decisions buyers will still need to make.

Terminology note: ENISA’s draft calls the entry assurance level “basic”. Simon uses “Low” in his answer below; his wording is retained as supplied.

1. What should certification actually prove about the quality and capability of an incident-response provider?

The draft sets a fair baseline around data integrity, ways of working and the capabilities associated with incident-response providers. However, given the impact of the certification — both in terms of competitiveness and participation in the European Cybersecurity Reserve — we should set higher expectations for our providers.

I believe the certification should be a baseline requirement for organisations choosing a vendor that can demonstrate strong incident-response capabilities. Reading through the draft, I do not think we should be afraid to set the expectations high.

The difference between the Low and High certification levels should be greater. The High level should ensure outstanding incident-response work, without succumbing to the risk of tailoring something favoring larger enterprises, while the Low level should represent a true entry level for IR providers. I do not believe either of these points is sufficiently reflected in the current proposal.

Partnerships, and working with other providers or companies that can deliver subservices supporting incident response (such as threat-actor negotiations, legal support or communications), should be another expectation. Instead of trying to do everything on your own, strategic partnerships around capability can help provide the best outcome for the client.

2. What should buyers still look for beyond certification?

Preventive measures. How do you, as a company, grow stronger before the incident happens? Readiness and resilience.

Likewise, certification will provide a baseline, but organisations should still be selective and understand their own requirements before asking vendors about solutions.

3. Is there anything important you believe the current proposal risks missing?

The draft, in its current form, is not at risk of missing one paramount element to its success — I believe it already is.

In an attempt to frame the underlying issue, I think an important question to ask in the draft is whether the scheme is being built to select the best providers for the European Cybersecurity Reserve or to create transparency around good IR providers, some of whom may also serve the Reserve.

A great deal of the text goes into defining proportionality, scope, capabilities and assurance levels. However, I believe we will only have a successful certification scheme if its purpose is stated explicitly, and I do not think the draft currently does that.

Olov Norman: What happens between assessments?

“An EUMSS certificate can show that a provider has met a defined security baseline. It cannot prove how that provider will perform against tomorrow’s zero-day. In cloud environments, resilience still depends on continuous adaptation, threat-informed engineering and response speed, not certification alone.”

Olov Norman, Cloud Security Success Manager at Onevinn, considers how a provider keeps its security service effective as environments and threats change. He draws on cloud security and managed detection and response; the current draft’s first service-specific certification profile is incident response.

​​Europe needs a more consistent way of assessing Managed Security Service Providers. Organisations operating across several markets currently face different national requirements, interpretations and assurance models. A common European approach is therefore both relevant and necessary, particularly as NIS2 increases scrutiny of cybersecurity supply chains and demand for demonstrable assurance.

But in cloud security, there is still an important distinction between passing an assessment and surviving a real-world attack.

The challenge with any certification scheme is that standardised controls inevitably describe a known baseline, while the threat landscape continues to evolve. Cloud environments change constantly: new services appear, identities and permissions evolve, configurations shift and attackers combine techniques across endpoints, identities and cloud services.

Security therefore cannot be treated as a completed compliance project. It must be operated as a continuous capability.

An EUMSS certificate can demonstrate that a provider has met defined requirements. It cannot guarantee how that provider will perform against tomorrow’s zero-day. In fast-moving cloud environments, resilience still depends on continuous adaptation, threat-informed engineering and response speed, not certification alone.

There are several trade-offs we should keep in mind.

First, there is a risk of incentivising process over protection. Certification naturally requires documentation, evidence and repeatable procedures. Those are valuable and necessary elements of a mature security service.

The problem arises when the audit itself becomes the objective.

If organisations begin optimising primarily for conformity, security teams may become overly cautious about changing established workflows. During a fast-moving incident, however, analysts may need to adjust detection logic, introduce new hunting queries, isolate affected resources or deviate from an existing playbook as new evidence emerges.

Good governance should make these decisions accountable. It should not make them unnecessarily slow.

Certification should therefore support operational agility, not gradually create an environment in which following the documented process becomes more important than reducing the actual risk.

Then there is the question of specialist innovation. Certification and conformity assessment introduce financial and administrative overhead. Large providers are generally better positioned to absorb those costs than smaller specialist MSSPs.

That matters in cybersecurity because innovation does not come only from the largest providers. Specialist companies often focus deeply on areas such as threat hunting, incident response, identity protection and cloud detection engineering. They can be technically agile and close to emerging attack techniques.

If certification becomes too expensive or administratively complex, Europe risks creating a market that favours scale over capability. The unintended consequence could be greater consolidation, fewer viable specialist providers and less diversity across the cybersecurity ecosystem.

Finally, there is the potential for certification bottlenecks.

As demand for formal assurance grows, so will demand for qualified conformity assessment bodies. Material changes to certified services may also require further assessment. The important question is how to maintain assurance without slowing down necessary security improvements.

A modern managed detection and response service cannot stand still between assessment cycles. Detection rules need to evolve. Threat intelligence must be operationalised. Automation has to be refined. New data sources and attack techniques need to be incorporated, and lessons from incidents should lead to continuous service improvements.

Certification therefore needs to accommodate controlled and continuous service evolution. Otherwise, the process could inadvertently slow down some of the improvements customers rely on.

None of this means that EUMSS has no value. A common European framework can reduce fragmentation, establish minimum expectations and give customers a clearer basis for evaluating Managed Security Service Providers.

But it must be recognised for what it is: a floor, not a ceiling.

For organisations navigating NIS2 and building genuine cyber resilience, certification should be the beginning of the supplier conversation, not the end of it.

The harder questions still matter: How quickly can the provider identify a new attack technique? How does it improve detections based on threat intelligence and lessons learned? What happens when an established playbook no longer works? How rapidly can it adapt protection across identities, endpoints, data and cloud services?

An audited certificate can provide confidence in a baseline. Genuine resilience comes from what happens every day after the audit.

Maria Sivenkova: How can buyers use the scheme?

“For regulated companies, EUMSS can turn obligations into buying criteria; for everyone else, it can turn fragmentation into efficiency.”

Maria Sivenkova, PhD, AIGP, specialises in vulnerability management. She considers what a common scheme could offer organisations with regulatory obligations and those buying services across several European markets.

The value of EUMSS will ultimately depend on how useful it is to the organisations buying managed security services.

For companies subject to NIS2 or DORA, the scheme could help translate regulatory expectations into more practical procurement criteria. I see particular value in three areas: supply-chain risk, incident response and vulnerability management.

First, a common European certification could give organisations a more consistent way to assess managed security service providers and support third-party risk management. Instead of starting every supplier assessment from scratch, buyers could use certification as one part of the evidence they consider.

Second, incident response is an area where regulatory obligations and operational capability meet very directly. Organisations need providers with clear escalation, communication and incident-handling processes so that the right information reaches the right people quickly.

Third, vulnerability management is especially close to my heart because this is the field I work in. The EUMSS baseline covers areas such as vulnerability handling, security advisories, remediation, monitoring and disclosure. These are not abstract compliance topics. They affect how quickly weaknesses are identified, communicated and addressed in practice.

For companies outside the direct scope of NIS2 or DORA, the value proposition is different. Here, EUMSS could help reduce friction.

Buying managed security services across several EU countries can mean dealing with different national requirements and assessment approaches. A common European scheme could make providers easier to assess, reduce duplicated due diligence and help multinational organisations apply more consistent expectations across their operations.

There is also a supply-chain dimension. Companies that are not directly regulated may still serve customers that are. Those customers increasingly expect evidence that cyber risks are being managed throughout the supply chain. Certified services could give suppliers another way to demonstrate that their security arrangements have been independently assessed.

So the reasons to care about EUMSS are not the same for every organisation. For regulated companies, it could help turn regulatory expectations into more concrete procurement decisions. For others, the benefit may lie in reducing complexity, improving consistency and making security assurance easier to demonstrate.

What these perspectives mean for buyers

The three contributors approach EUMSS from different positions, but their answers lead back to the same decision: what evidence does an organisation need from an incident response provider? The draft could give buyers a shared reference point. 

Certification needs to be meaningful without being mistaken for a complete measure of cyber resilience.

The scope of the assessed service, the meaning of its assurance level and the provider’s ability to respond as circumstances change would still need close attention.

ENISA’s draft says EUMSS certification may provide evidence relevant to selected NIS2 requirements; it does not establish NIS2 compliance. Buyers should assess any future certificate alongside their own risks, supplier requirements and the service they are actually purchasing.

Source and scope: This article draws on ENISA’s EUMSS candidate scheme, draft v1.1, published 24 July 2026, and the three contributors’ supplied responses. Their answers appear above without changes to their wording.

To explore the expertise behind these perspectives, read about CSIS incident response and Onevinn cloud security. You can also contact Allurity about your organisation’s needs.