Cybersecurity professional looking at floating digital dashboards in a dark, high-tech environment

EUCC and Post-Quantum Cryptography: Building Security for What’s Next

The EU Cybersecurity Certification (EUCC) scheme, effective since February 2025, is a landmark in unifying cybersecurity standards across Europe. Built on the International Common Criteria (ISO/IEC 15408), EUCC offers companies a streamlined, trusted path to certify the cybersecurity of their ICT products, services, and processes throughout the EU.

At Keysight, we see the EUCC as more than a certification—it’s a turning point. The recognition of Post-Quantum Cryptography (PQC) algorithms in the Agreed Cryptographic Mechanisms (ACM) confirms that the move toward quantum readiness has already begun meaning organizations must prepare now.

Europe’s Post-Quantum Milestone: ACM Version 2.0

In April 2025, the European Cybersecurity Certification Group (ECCG), supported by the European Union Agency for Cybersecurity (ENISA), released Version 2.0 of the Agreed Cryptographic Mechanisms (ACM). This update is a pivotal moment in Europe’s shift toward quantum-resilient security.

For the first time, the ACM officially includes Post-Quantum Cryptography algorithms, such as:

These algorithms are now part of the recommended cryptographic toolbox for securing ICT products certified under the EUCC framework. This signals that PQC is no longer optional—it’s becoming expected.

What the Updated EUCC Guidelines Recommend

The EUCC cryptographic guidelines now support a risk-based approach. For products that require stronger assurance levels, ENISA encourages the use of quantum-resistant cryptography, including hybrid solutions that combine both traditional and PQC algorithms.

Leading organizations like ENISA and European Telecommunications Standards Institute (ETSI) continue to recommend hybrid cryptography—often called "double encryption"—as the safest path forward. This means combining existing encryption methods (like ECC or RSA) with Post-Quantum Cryptography to secure systems both now and in the future.

The EUCC also emphasizes flexibility and upgrade readiness. This ensures that the cryptographic systems organizations build today can be easily updated as standards and best practices evolve.

Why the Clock Is Ticking on Legacy Cryptography

With the inclusion of PQC in the ACM and the increasing momentum across Europe, legacy cryptography is now on the clock. The transition to quantum-safe security is underway, and organizations that delay will face higher risks and potentially disruptive certification challenges later.

Keysight recommends organizations:

How Keysight Can Help

Keysight is your trusted partner for navigating the transition to Post-Quantum Cryptography, especially in the context of EUCC certifications. With 25+ years of experience delivering complex security projects, Common Criteria accreditation since 2017, and more than 50 successful certification projects across Evaluation Assurance Levels (EAL) 2 to EAL 7, we bring proven expertise to every engagement.

Our team specializes in guiding organizations through the shift to quantum-safe cryptography, helping you design flexible, upgrade-ready security systems that can seamlessly adapt to evolving cryptographic standards and certification requirements.

The Path Forward Starts Now

The inclusion of PQC algorithms in the Agreed Cryptographic Mechanisms shows that quantum readiness is no longer a future issue—it’s happening today.

At Keysight, we are ready to help you:

To learn more about Keysight’s Common Criteria and Post-Quantum Cryptography services, visit our PQC Security page at https://www.keysight.com/us/en/cmp/2025/pqc-security.html or contact us directly at [email protected]

Related Posts

limit
3