A draft, a September date, and one service profile
On 24 July ENISA put the draft EU Managed Security Services scheme, known as EUMSS, out for public comment. Juhan Lepassaar, the agency's executive director, framed the purpose in a single line: "Common baselines can guarantee a level of confidence in services offered." The consultation runs through an EU Survey portal and closes on 13 September 2026.
The legal basis is Article 48(1) of the Cybersecurity Act as amended by Regulation (EU) 2025/37, which the Commission adopted on 15 January 2025 specifically to allow European certification of services rather than only products. The Commission asked ENISA to build the candidate scheme on 25 April 2025. ENISA opened a call for experts on 25 June 2025, and the dedicated ad hoc working group held its kick-off on 13 October 2025.
What emerged nine months later is narrower than the mandate. The present draft addresses the Incident Management Lifecycle vertical, and within it a single service profile: Incident Response.
The five the law names, the one the draft covers
The amended Act's definition of managed security services reaches five activities: security monitoring and incident detection, incident response, penetration testing, security audits, and cybersecurity consultancy. The draft scheme certifies the second of those. The other four are not excluded in principle, because the structure is explicitly built to take further service profiles, but they are not in version one.
That ordering deserves a moment. Incident response is the service you invoke after something has already gone wrong. Security monitoring and incident detection is the service you pay for every month so that it does not. A provider will shortly be able to say, accurately, that it holds an EU certificate for managed security services while the continuous part of its contract with you has never been assessed under the scheme.
This is less a criticism of the sequencing than a warning about how the mark will be read. Certification marks travel further and faster than their scope statements.
Why basic and high say nothing about the platform
The scheme uses a layered design. A horizontal layer sets baseline requirements that apply to every managed security service certified under it, and a vertical layer carries the requirements specific to each service profile. The horizontal baseline covers secure service and platform design, deployment and transition management, availability and continuity management, operational service management, and continuous improvement and technology maintenance.
Three assurance levels exist: basic, substantial and high. The detail worth extracting from the draft is that those horizontal baseline requirements are a mandatory prerequisite for every certified service profile and are the same at all three levels. The level varies the vertical layer, not the foundation. Read plainly, a provider certified at high has demonstrated more about how it runs an incident response engagement, and exactly as much as a basic provider about how its platform is designed and kept available.
Eighteen months to a draft, and the anchor buyer is Brussels
Count the calendar. From the legal basis on 15 January 2025 to a draft open for comment on 24 July 2026 is eighteen months. Comments close on 13 September. Adoption follows. Providers supplying the EU Cybersecurity Reserve then have two years from implementation in which to hold the certificate.
That last clause is the mechanism, and it is worth naming precisely. For the private market the scheme is voluntary. For providers supplying the EU's own reserve of incident response capacity it is not. The EU has made itself the anchor buyer and left the mark optional for everyone else, which is the standard route by which a voluntary scheme becomes a de facto tender requirement without anyone legislating one. Expect EUMSS to appear as a scoring line in public procurement well before it is comprehensive.
What to ask your provider before 13 September
Three things are worth settling now. First, ask which service profile your provider intends to certify against, and whether the service you actually buy sits inside it. If your contract is monitoring and detection, the honest answer today is that it does not. Second, ask which assurance level they will seek, and make them explain what that changes, given that the baseline does not move between levels.
Third, treat the consultation as a live input rather than a notice. Comments close on 13 September and the scope of version one is exactly what is open. Buyers are consistently underrepresented in scheme consultations compared with providers and conformity assessment bodies. In Britain the NCSC's Cyber Incident Response scheme already assures this same work, so a UK provider selling into the EU will hold one mark at home and need another for European tenders. Under NIS2 the supply chain obligation already sits with you, which makes the scope of this scheme something you cannot delegate to a vendor.
Read next: Europe Will Grade Frontier AI Itself Now | A Sovereign Vendor Licences Back Its Own Code



