The European co-operation for Accreditation (EA) has been recognised by the European Commission (EC) as the official European accreditation infrastructure. The recognition of EA follows the adoption of Regulation (EC) No 765/2008 by the European Parliament and the European Council, which establishes the legal framework for accreditation in the EU.
EA and the European Commission (EC) cooperate closely for the development and the implementation of EU regulations that refer to accreditation and conformity assessment activities. The main communication channel for EA is the Directorate-General for Internal Market, Industry, Entrepreneurship and SMEs (DG GROW).
The number of regulations being developed or published over the past years is a clear indication of the confidence placed in accreditation and the European Accreditation infrastructure. It also demonstrates how well cooperation has evolved over the years, EA having adapted its internal organization to contribute at the right time. Confidence also exists in the almost daily interaction between EA and the EC services. It has helped ensure that EA can give its expertise about the benefit of using accreditation at the right stage of legislation development, sufficiently in advance for a sound and applicable set of requirements to be used in the various fields.
Here are a few examples to illustrate how accreditation in Cybersecurity, IT, and AI Regulations positively impacts your day-to-day life:
EU Cyber Resilience Act and EU Cyber Security Act
The EU Cyber Resilience Act (CRA) is a landmark regulation setting baseline cybersecurity rules for all digital products (hardware & software) sold in the EU, ensuring “security by design” with lifecycle requirements, updates, and incident reporting, while the EU Cybersecurity Act (CSA) is a broader framework establishing EU-wide certification schemes for products, services, and processes to build trust, with the CRA focusing specifically on the product level for market entry and upkeep.
Within the framework of the CRA, accreditation is crucial for bodies that carry out third-party conformity assessments for products of the “important” and “critical” classes and wish to act as “notified bodies”.
The CSA is establishing a voluntary EU certification framework (EU Cybersecurity Certification Framework). Accreditation is also a cornerstone of this system, ensuring trust in certificates and reports issued by certification bodies and ITSEFs (laboratories).
Artificial Intelligence
The EU AI Act is the world’s first comprehensive law for Artificial Intelligence, setting a global standard by regulating AI based on its risk level, banning unacceptable practices (like social scoring), imposing strict rules on high-risk systems (e.g., in health, employment), and promoting innovation for lower-risk AI. Its goal is to ensure AI in Europe is safe, trustworthy, human-centric, and respects fundamental rights.
Under the EU AI Act, accreditation ensures that conformity assessment bodies – acting as notified bodies – are competent and trustworthy, providing reliable certification for high-risk AI systems, supporting market access, regulatory oversight, and consumer protection, while fostering safe and trustworthy AI innovation in Europe.

