Certification services
Certify your IT products to demonstrate compliance with a wide range of schemes and regulations relevant to your market.
Welcome to Brightsight CB
With decades of experience in the field, Brightsight is a trusted partner for numerous developers and manufacturers. You know us for our evaluation services, but did you know we also offer certification services through the newly established Certification Body within Brightsight?
Brightsight CB offers certification services of IT security products, helping you gain the trust and confidence of your customers.
Impartiality: our promise to you is simple
At Brightsight CB, impartiality and integrity are at the core of our business. Since both the ITSEF and the CB are part of Brightsight, we have implemented many strict measures to ensure impartiality.
Our promise to you is simple: we will never compromise on impartiality and integrity. Any infraction will have serious consequences for our accreditation and authorization status, ensuring that we remain a trusted and reliable partner for your certification needs.
Director Certification Body
"Impartiality and integrity are at the core of our business."
Our certification scope
Brightsight CB will enable you to demonstrate the compliance of your products with the following schemes and methodologies:
Introduction to EUCC

The European Union Cybersecurity Certification (EUCC) is a framework designed to enhance the security of digital products, services, and processes within the EU. It aims to establish a unified approach to cybersecurity certification, ensuring that certified products meet high security standards. Certification is possible at two assurance levels: Substantial and High.
EUCC is based on the international Common Criteria standard (ISO/IEC 15408). The EUCC provides a harmonised framework within the EU for assessing and certifying the security properties of IT products. An EUCC certificate is recognised throughout the EU, eliminating the need for certification per individual member state.
EUCC is closely linked to the Cybersecurity Act (CSA). The CSA establishes the framework for the EUCC, which is a certification scheme aimed at ensuring the cybersecurity of ICT products within the European Union.
The Rijksinspectie Digitale Infrastructuur (RDI) serves as the National Cybersecurity Certification Authority (NCCA) in the Netherlands. In this role, the RDI is responsible for overseeing the implementation of the EUCC framework at the national level.
Brightsight CB
On 20 November 2025, Brightsight CB obtained an accreditation as a Certification Body (CB) for the Common Criteria-based cybersecurity certification scheme (EUCC) by the Dutch National Accreditation Council, Raad voor Accreditatie (RvA).
On 2 December 2025, Brightsight got licensed by the Dutch NCCA as Conformity Assessment Body (CAB) in the role of a CB. This means Brightsight’s facility in Delft, the Netherlands is authorized not only to perform independent certification activities under the EUCC scheme, but also to issue certificates that are recognized under the the Common Criteria Recognition Arrangement (CCRA).
Within the EUCC scheme, Brightsight CB can certify the ICT products for the assurance levels Substantial and High up to EAL5+ within the following technical domains:
- Smartcards and similar devices (up to and including AVA_VAN.5)
- Hardware devices with security boxes (up to and including AVA_VAN.5)
- Generic software and network products (up to and including AVA_VAN.3)
Contact details
- Brightsight Delft Brassersplein 2 2612 CT Delft The Netherlands
- Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
Downloads
Ongoing EUCC certifications
| Assessment ID | Developer | TOE Name | Technical domain | Assurance level |
|---|---|---|---|---|
| 70033-01 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – eIDAS | Smart Cards & Similar Devices | High |
| 70033-02 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – ePass with BAC | Smart Cards & Similar Devices | High |
| 70033-03 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – ePass with LDS2 | Smart Cards & Similar Devices | High |
| 70037-01 | Cisco Systems Inc. | UCS-C Intersight | Generic software and network products | Substantial |
| 70010-01 | Entrust | nShield5s | Hardware Devices with Security Boxes | High |
| 70034-01 | ThinkLogical | KVM TLX Matrix Switch product series | Generic software and network products | High |
EUCC certificates
EUCC licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Brightsight ITSEF
EUCC assurance levels Substantial and High for the technical domains:
- Smartcards and similar devices, up to and including AVA_VAN.5 (location Madrid up to and including AVA_VAN.3)
- Hardware devices with security boxes, up to and including AVA_VAN.5 (location Madrid up to and including AVA_VAN.3)
- Generic software and network products, up to and including AVA_VAN.3
Licensed laboratories
Brightsight Delft
Brassersplein 2
2612 CT Delft
The Netherlands
Brightsight Barcelona
Plaça de Xavier Cugat 2
Edifici A, 2º-B
08174 Sant Cugat del Vallès (Barcelona)
Spain
Brightsight Meyreuil
Rue de la Belle du Canet
Arteparc Meyreuil – Immeuble F
13590 Meyreuil
France
Brightsight Graz
Mälzereigasse 4
8020 Graz
Austria
Brightsight Madrid
Trespaderne 29
Edificio Barajas I Barrio Aeropuerto
ES28042 Madrid
Spain
Introduction to SESIP

The Security Evaluation Standard for IoT Platforms (SESIP), published by GlobalPlatform and CEN CENELEC, provides an optimised version of the Common Criteria methodology applied to certification of IoT platforms and their components. Developers can trust that SESIP certified platforms and components will deliver the correct levels of security, enabling them to focus on their primary goal of delivering robust and secure products by design.
SESIP offers a scalable solution to reduce security fragmentation in IoT devices by allowing a single evaluation to provide evidence for multiple certification requirements. This simplifies the process and eliminates the need for multiple security evaluations. SESIP certification aligns with global standards such as IEC 62443-4-2, ISO 21434 and the Cyber Resilience Act.
Brightsight CB
Scope of license: SESIP 1-3
Brightsight CB for SESIP is located in Madrid, Spain. It has been designated by GlobalPlatform as SESIP Certification Body for assurance levels 1 to 3.
This facility is accredited by ENAC, the Spanish National Accreditation Body, under ISO 17065 (nº: 220/C-PR490) as a Certification Body (CB) for SESIP certification issuance.
These two roles operate impartially and independently, ensuring that Brightsight CB’s certification processes remain transparent and unbiased.
Contact details
- Trespaderne 29, Edificio Barajas I, Barrio Aeropuerto
28042 Madrid, Spain - Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
SESIP certificates
| SESIP-25/0001 | 10/06/2025 | 09/06/2026 | STM32MP13xx advanced Arm®-based 32-bit MPUs version 1.2 | STMicroelectronics | Brightsight ITSEF | SESIP3 | Certificate | Security Target |
No certificates match your search.
SESIP licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Fully Licensed Laboratories (ITSEFs):
SGS Brightsight Barcelona S.L.
Plaza Xavier Cugat 2
Sant Cugat del Valles
08174 Barcelona
Spain
Provisionally Licensed Laboratories (ITSEFs):
SGS Brightsight China LLC
Room 908, Building 3,
No. 18 Fengtai North Road, Fengtai District,
Beijing City 100071,
China
DPLS
Room 701, Building 7,
No. 98 West Lake Road Mentougou District,
Beijing City 100176,
China
Introduction to PSA Certified

PSA Certified, operated by GlobalPlatform, is the independent security evaluation scheme for Platform Security Architecture (PSA) based IoT systems. It establishes trust through a multi-level assurance program for chips containing a security component called a Root of Trust (PSA-RoT) that provides trusted functionality to the platform.
The multi-level scheme has been designed to help device makers and businesses get the level of security they need for their use case. It is aimed at IoT devices that need to protect against scalable software attacks. Developers submit their PSA-RoT to an approved test laboratory for evaluation and receive an Evaluation Technical Report (ETR). If the PSA-RoT is assessed as passed and approved by the independent Certification Body, a digital certificate will be issued on the PSA Certified website.
PSA Certified security evaluations can contain both hardware and software components of a device. There are three defined certification scopes: Chip, RTOS (System Software), and Device.
Brightsight CB
Scope of license: PSA Certified 1-4
Brightsight CB is appointed by Global Platform as PSA Certified certification body for Level 1-4.
Brightsight CB and Brightsight ITSEF operate impartially and independently, ensuring that Brightsight CB’s certification processes remain transparent and unbiased.
Contact details
- Trespaderne 29, Edificio Barajas I, Barrio Aeropuerto 28042 Madrid, Spain
- Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
PSA Certified certificates
The overview of all PSA Certified certificates is published on psacertified.org
PSA Certified licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Fully Licensed Laboratories (ITSEFs):
SGS Brightsight Barcelona S.L.
Plaza Xavier Cugat 2
Sant Cugat del Valles
08174 Barcelona
Spain
Provisionally Licensed Laboratories (ITSEFs):
SGS Brightsight China LLC
Room 908, Building 3,
No. 18 Fengtai North Road, Fengtai District,
Beijing City 100071,
China
DPLS
Room 701, Building 7,
No. 98 West Lake Road Mentougou District, Fengtai District,
Beijing City 100176,
China
Introduction to ENS

Spain’s digital infrastructure is protected by a robust regulatory framework designed to safeguard information systems in the public sector, as well as private entities working alongside government bodies. At the heart of this landscape is the National Cryptologic Center (CCN), established by Royal Decree 421/2004 and operating under the National Centre of Intelligence (CNI).
The Spanish National Security Scheme (Esquema Nacional de Seguridad, or ENS) provides a framework of security requirements to safeguard information within electronic administration. Its goal is to ensure the protection of personal and confidential data exchanged through online channels, thereby strengthening trust in digital public services. Compliance with ENS standards demonstrates that your information systems are secure, reliable and meet both industry and governmental requirements.
The ENS divides system requirements into three security categories – High, Medium, and Basic – ensuring tailored security for each use case. The Basic category can be achieved by a self-declaration. The Medium and High categories require certification from an accredited Certification Body (CB).
To streamline compliance, the CPSTIC Product Catalogue – managed by the CCN – serves as an authoritative listing of security products and services for information and communication technology (ICT) systems under the ENS. It helps public and private entities find security products and services for information and communication technology (ICT) systems under the ENS.
Brightsight CB
Brightsight Certification Body (CB) supports the ENS certification process, including activities such as initial auditing, technical review and certificate issuance.
ENS certification is valid for up to two years, and per Article 38 of the ENS, all systems must undergo a comprehensive audit at least biennially to remain compliant. The certification process rigorously assesses your information systems against the principles and requirements set out in Annex II of Royal Decree 311/2022.
ENS certificates
The ENS certificates are published on the National Cryptographic Center (CCN) website.
Our certification process
Downloads
Introduction to CRA

The Cyber Resilience Act (CRA) is a European Union regulation that introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market.
The regulation establishes requirements covering the security of products throughout their lifecycle, including vulnerability handling, security updates and the management of cybersecurity risks. Its objective is to strengthen the cybersecurity of connected products and provide a common framework for manufacturers placing them on the European market.
The CRA will become progressively applicable, with reporting obligations starting from September 2026 and the full set of requirements applying from December 2027.
Depending on the product category and the applicable conformity assessment route, manufacturers may need to demonstrate compliance through a third party conformity assessment. This is where a qualified Conformity Assessment Body and, where required, a designated CRA Notified Body play a key role.
Use our CRA Readiness Check to get an initial indication of your product classification and understand the next steps towards CRA compliance.
Brightsight is becoming a CRA Notified Body
A Notified Body is an independent conformity assessment organisation designated by a national authority to carry out specific third party assessments under European Union legislation.
Under the Cyber Resilience Act, a Notified Body plays a key role for products that require independent third party conformity assessment. Depending on the applicable conformity assessment procedure, it can assess whether a product and its supporting evidence meet the relevant requirements of the CRA.
Brightsight has achieved ISO/IEC 17065 accreditation for CRA Module B, marking an important milestone towards becoming a designated CRA Notified Body.
Brightsight is currently applying for notification as a CRA Notified Body with the relevant national authorities and is starting the pilot phase under the applicable conditions of its accreditation. Successful completion of this process will enable Brightsight to progress towards formal designation as a CRA Notified Body
This milestone brings Brightsight one step closer to providing CRA Module B conformity assessment services and supporting manufacturers as they prepare for the new cybersecurity requirements.
CURRENT STATUS
ISO/IEC 17065 accreditation achieved Brightsight has achieved ISO/IEC 17065 accreditation for CRA Module B, marking an important milestone towards becoming a CRA Notified Body.
NEXT MILESTONE
Pilot conformity assessmentThe next step is to complete a pilot conformity assessment, applying Brightsight's Module B assessment process in practice under the applicable accreditation conditions.
NOTIFICATION PHASE
Notification as a CRA Notified Body Following the successful completion of the pilot phase and the applicable next steps, Brightsight will proceed with the notification process through the Dutch notifying authority (RDI).
FINAL MILESTONE
CRA Notified Body designation Formal designation by the national authority and recognition as a CRA Notified Body across the EU.
Module B: Classic Product Evaluation
Module B, also known as EU Type Examination, is a product focused conformity assessment procedure under the Cyber Resilience Act.
The assessment focuses on evaluating whether a specific product meets the applicable CRA requirements. Depending on the product and its applicable conformity assessment route, this can include the review of the product’s cybersecurity characteristics, technical documentation and evidence supporting compliance with the relevant essential requirements.
Under Module B, the conformity assessment focuses on the product itself and its supporting evidence. This may include:
- Security testing and technical evaluation relevant to the product and its cybersecurity characteristics.
- Conformity assessment against the applicable CRA requirements.
- Review of technical documentation and supporting evidence required for the assessment.
- Assessment of the applicable essential requirements under the Cyber Resilience Act.
The exact scope of the assessment depends on the product, its classification and the applicable CRA requirements.
Depending on the applicable CRA conformity assessment route, Module B may be relevant for:
- Critical products
- Important Class I products
- Important Class II products
- Default products, where the applicable conformity assessment route requires third party involvement
Module H: Full Quality Assurance
Module H is a conformity assessment procedure that takes a broader approach than Module B. Rather than focusing on the assessment of an individual product, Module H evaluates the manufacturer’s quality assurance system and its ability to consistently ensure compliance with the applicable Cyber Resilience Act requirements.
The assessment may cover the processes and systems used throughout the product lifecycle, including areas such as product development, cybersecurity management, vulnerability handling and ongoing quality assurance.
Module H is part of Brightsight’s broader roadmap towards CRA Notified Body designation.
While Brightsight’s current CRA milestone and accreditation scope focus on Module B, the company continues to develop its capabilities and roadmap for Module H.
Brightsight CB
Scope: Cyber Resilience Act (CRA) Module B
Brightsight CB has achieved ISO/IEC 17065 accreditation for CRA Module B, marking an important milestone towards becoming a CRA Notified Body.
Module B covers EU Type Examination, a product focused conformity assessment procedure under the Cyber Resilience Act.
Brightsight CB and Brightsight ITSEF operate impartially and independently, ensuring that conformity assessment activities remain transparent and unbiased.
Contact details
- Brightsight Delft, Brassersplein 2,
2612 CT Delft, The Netherlands - Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
Downloads
Introduction to EUCC

The European Union Cybersecurity Certification (EUCC) is a framework designed to enhance the security of digital products, services, and processes within the EU. It aims to establish a unified approach to cybersecurity certification, ensuring that certified products meet high security standards. Certification is possible at two assurance levels: Substantial and High.
EUCC is based on the international Common Criteria standard (ISO/IEC 15408). The EUCC provides a harmonised framework within the EU for assessing and certifying the security properties of IT products. An EUCC certificate is recognised throughout the EU, eliminating the need for certification per individual member state.
EUCC is closely linked to the Cybersecurity Act (CSA). The CSA establishes the framework for the EUCC, which is a certification scheme aimed at ensuring the cybersecurity of ICT products within the European Union.
The Rijksinspectie Digitale Infrastructuur (RDI) serves as the National Cybersecurity Certification Authority (NCCA) in the Netherlands. In this role, the RDI is responsible for overseeing the implementation of the EUCC framework at the national level.
Brightsight CB
On 20 November 2025, Brightsight CB obtained an accreditation as a Certification Body (CB) for the Common Criteria-based cybersecurity certification scheme (EUCC) by the Dutch National Accreditation Council, Raad voor Accreditatie (RvA).
On 2 December 2025, Brightsight got licensed by the Dutch NCCA as Conformity Assessment Body (CAB) in the role of a CB. This means Brightsight’s facility in Delft, the Netherlands is authorized not only to perform independent certification activities under the EUCC scheme, but also to issue certificates that are recognized under the the Common Criteria Recognition Arrangement (CCRA).
Within the EUCC scheme, Brightsight CB can certify the ICT products for the assurance levels Substantial and High up to EAL5+ within the following technical domains:
- Smartcards and similar devices (up to and including AVA_VAN.5)
- Hardware devices with security boxes (up to and including AVA_VAN.5)
- Generic software and network products (up to and including AVA_VAN.3)
Contact details
- Brightsight Delft Brassersplein 2 2612 CT Delft The Netherlands
- Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
Downloads
Ongoing EUCC certifications
| Assessment ID | Developer | TOE Name | Technical domain | Assurance level |
|---|---|---|---|---|
| 70033-01 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – eIDAS | Smart Cards & Similar Devices | High |
| 70033-02 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – ePass with BAC | Smart Cards & Similar Devices | High |
| 70033-03 | TOPPAN Security S.r.l. | SOMA-ck025 Electronic Document – ePass with LDS2 | Smart Cards & Similar Devices | High |
| 70037-01 | Cisco Systems Inc. | UCS-C Intersight | Generic software and network products | Substantial |
| 70010-01 | Entrust | nShield5s | Hardware Devices with Security Boxes | High |
| 70034-01 | ThinkLogical | KVM TLX Matrix Switch product series | Generic software and network products | High |
EUCC certificates
EUCC licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Brightsight ITSEF
EUCC assurance levels Substantial and High for the technical domains:
- Smartcards and similar devices, up to and including AVA_VAN.5 (location Madrid up to and including AVA_VAN.3)
- Hardware devices with security boxes, up to and including AVA_VAN.5 (location Madrid up to and including AVA_VAN.3)
- Generic software and network products, up to and including AVA_VAN.3
Licensed laboratories
Brightsight Delft
Brassersplein 2
2612 CT Delft
The Netherlands
Brightsight Barcelona
Plaça de Xavier Cugat 2
Edifici A, 2º-B
08174 Sant Cugat del Vallès (Barcelona)
Spain
Brightsight Meyreuil
Rue de la Belle du Canet
Arteparc Meyreuil – Immeuble F
13590 Meyreuil
France
Brightsight Graz
Mälzereigasse 4
8020 Graz
Austria
Brightsight Madrid
Trespaderne 29
Edificio Barajas I Barrio Aeropuerto
ES28042 Madrid
Spain
Introduction to SESIP

The Security Evaluation Standard for IoT Platforms (SESIP), published by GlobalPlatform and CEN CENELEC, provides an optimised version of the Common Criteria methodology applied to certification of IoT platforms and their components. Developers can trust that SESIP certified platforms and components will deliver the correct levels of security, enabling them to focus on their primary goal of delivering robust and secure products by design.
SESIP offers a scalable solution to reduce security fragmentation in IoT devices by allowing a single evaluation to provide evidence for multiple certification requirements. This simplifies the process and eliminates the need for multiple security evaluations. SESIP certification aligns with global standards such as IEC 62443-4-2, ISO 21434 and the Cyber Resilience Act.
Brightsight CB
Scope of license: SESIP 1-3
Brightsight CB for SESIP is located in Madrid, Spain. It has been designated by GlobalPlatform as SESIP Certification Body for assurance levels 1 to 3.
This facility is accredited by ENAC, the Spanish National Accreditation Body, under ISO 17065 (nº: 220/C-PR490) as a Certification Body (CB) for SESIP certification issuance.
These two roles operate impartially and independently, ensuring that Brightsight CB’s certification processes remain transparent and unbiased.
Contact details
- Trespaderne 29, Edificio Barajas I, Barrio Aeropuerto
28042 Madrid, Spain - Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
SESIP certificates
| SESIP-25/0001 | 10/06/2025 | 09/06/2026 | STM32MP13xx advanced Arm®-based 32-bit MPUs version 1.2 | STMicroelectronics | Brightsight ITSEF | SESIP3 | Certificate | Security Target |
No certificates match your search.
SESIP licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Fully Licensed Laboratories (ITSEFs):
SGS Brightsight Barcelona S.L.
Plaza Xavier Cugat 2
Sant Cugat del Valles
08174 Barcelona
Spain
Provisionally Licensed Laboratories (ITSEFs):
SGS Brightsight China LLC
Room 908, Building 3,
No. 18 Fengtai North Road, Fengtai District,
Beijing City 100071,
China
DPLS
Room 701, Building 7,
No. 98 West Lake Road Mentougou District,
Beijing City 100176,
China
Introduction to PSA Certified

PSA Certified, operated by GlobalPlatform, is the independent security evaluation scheme for Platform Security Architecture (PSA) based IoT systems. It establishes trust through a multi-level assurance program for chips containing a security component called a Root of Trust (PSA-RoT) that provides trusted functionality to the platform.
The multi-level scheme has been designed to help device makers and businesses get the level of security they need for their use case. It is aimed at IoT devices that need to protect against scalable software attacks. Developers submit their PSA-RoT to an approved test laboratory for evaluation and receive an Evaluation Technical Report (ETR). If the PSA-RoT is assessed as passed and approved by the independent Certification Body, a digital certificate will be issued on the PSA Certified website.
PSA Certified security evaluations can contain both hardware and software components of a device. There are three defined certification scopes: Chip, RTOS (System Software), and Device.
Brightsight CB
Scope of license: PSA Certified 1-4
Brightsight CB is appointed by Global Platform as PSA Certified certification body for Level 1-4.
Brightsight CB and Brightsight ITSEF operate impartially and independently, ensuring that Brightsight CB’s certification processes remain transparent and unbiased.
Contact details
- Trespaderne 29, Edificio Barajas I, Barrio Aeropuerto 28042 Madrid, Spain
- Email: brs.certification@sgs.com
Tel: +31 15 269 25 00
Web: www.brightsightcb.com
Our certification process
PSA Certified certificates
The overview of all PSA Certified certificates is published on psacertified.org
PSA Certified licensed laboratories
Brightsight CB is working with the following licensed evaluation laboratories (ITSEFs).
Fully Licensed Laboratories (ITSEFs):
SGS Brightsight Barcelona S.L.
Plaza Xavier Cugat 2
Sant Cugat del Valles
08174 Barcelona
Spain
Provisionally Licensed Laboratories (ITSEFs):
SGS Brightsight China LLC
Room 908, Building 3,
No. 18 Fengtai North Road, Fengtai District,
Beijing City 100071,
China
DPLS
Room 701, Building 7,
No. 98 West Lake Road Mentougou District, Fengtai District,
Beijing City 100176,
China
Introduction to ENS

Spain’s digital infrastructure is protected by a robust regulatory framework designed to safeguard information systems in the public sector, as well as private entities working alongside government bodies. At the heart of this landscape is the National Cryptologic Center (CCN), established by Royal Decree 421/2004 and operating under the National Centre of Intelligence (CNI).
The Spanish National Security Scheme (Esquema Nacional de Seguridad, or ENS) provides a framework of security requirements to safeguard information within electronic administration. Its goal is to ensure the protection of personal and confidential data exchanged through online channels, thereby strengthening trust in digital public services. Compliance with ENS standards demonstrates that your information systems are secure, reliable and meet both industry and governmental requirements.
The ENS divides system requirements into three security categories – High, Medium, and Basic – ensuring tailored security for each use case. The Basic category can be achieved by a self-declaration. The Medium and High categories require certification from an accredited Certification Body (CB).
To streamline compliance, the CPSTIC Product Catalogue – managed by the CCN – serves as an authoritative listing of security products and services for information and communication technology (ICT) systems under the ENS. It helps public and private entities find security products and services for information and communication technology (ICT) systems under the ENS.
Brightsight CB
Brightsight Certification Body (CB) supports the ENS certification process, including activities such as initial auditing, technical review and certificate issuance.
ENS certification is valid for up to two years, and per Article 38 of the ENS, all systems must undergo a comprehensive audit at least biennially to remain compliant. The certification process rigorously assesses your information systems against the principles and requirements set out in Annex II of Royal Decree 311/2022.
ENS certificates
The ENS certificates are published on the National Cryptographic Center (CCN) website.
Our certification process
Downloads
Start your certification process with Brightsight
Get in touch with our experts today to learn how we can help you with your specific certification process.
Download our GPG key to send encrypted message to the CB.