Albania has drafted a national cybersecurity certification scheme that defines security levels for information technology products, establishing mandatory certification and post-transparency obligations for manufacturers.
Albania Creates Mandatory Cybersecurity Certification for Tech Products
Manufacturers must certify products and disclose security information afterwards.
What changed
Mandatory certification for information technology products under a national scheme.
Post-transparency obligations require manufacturers to disclose cybersecurity information after certification.
Standardized security levels and evaluation criteria are established for IT products.
Who it affects
IT product manufacturers must obtain certification and disclose security information post-certification.
Providers of IT products are subject to the same post-transparency disclosure requirements.
What to do
Submit IT products for evaluation under the new national certification scheme.
Disclose required cybersecurity-related information after certification is granted.
Compliance Answer: Albania’s National Cybersecurity Certification Scheme
Direct Answer
Albania’s draft Decision of the Council of Ministers “On the Approval of the National Cybersecurity Certification Scheme, as well as the Security Levels of the Scheme” establishes a mandatory cybersecurity certification framework for information technology (IT) products. The scheme defines two security levels (“considerable” and “high”), imposes certification obligations on manufacturers, and introduces post-certification transparency and vulnerability management duties. Certification is valid for up to 5 years, with extensions requiring approval from the National Cyber Security Authority1, 2.
Regulation Analysis
1. Security Levels and Certification Requirements
The scheme mandates certification for IT products at two security levels, aligned with Common Criteria (CC) assurance levels (AVA_VAN):
- “Considerable” security level: Covers AVA_VAN 1 or 21.
- “High” security level: Covers AVA_VAN 3, 4, or 51.
Certification is required for products to demonstrate compliance with these levels, and the scheme distinguishes between standard and enhanced security component usage based on the certified level1.
| Regulation | Key Requirement | Threshold/Deadline | Authority |
|---|---|---|---|
| Security Levels (Art. 4) | Certification required for IT products at “considerable” (AVA_VAN 1–2) or “high” (AVA_VAN 3–5) levels1. | Not specified | Certification bodies1. |
| Certification Validity | Maximum validity of 5 years, extendable with approval1. | 5 years (extendable) | National Cyber Security Authority1. |
2. Certification Process and Obligations
a. Certification Steps
- Application: Manufacturers submit documentation to a certification body (authorized by the National Cyber Security Authority) and an IT Security Evaluation Facility (ITSEF)1, 2.
- Evaluation: ITSEF conducts technical assessments (e.g., structured interviews, pilot certifications) and issues a technical evaluation report1.
- Certification: The certification body issues a certificate (electronic format) and a certification report (publicly available, detailing security features, installation guidance, and evaluation results)1, 2.
- Public Disclosure: Manufacturers must make cybersecurity-related information publicly accessible in Albanian1.
b. Post-Certification Obligations
- Document Retention: Manufacturers must securely retain:
- Vulnerability Management:
- Manufacturers must monitor, analyze, and report vulnerabilities affecting certified products1.
- Immediate reporting to the certification body or National Cyber Security Authority is required for discovered vulnerabilities1.
- Cooperation with other cybersecurity authorities (e.g., EU authorities post-accession) for cross-border vulnerability disclosures1.
| Regulation | Key Requirement | Threshold/Deadline | Authority |
|---|---|---|---|
| Certification Report | Certification body issues a publicly available report (executive summary, security services, architecture, test results)1. | Not specified | Certification body1. |
| Vulnerability Reporting | Manufacturers must report vulnerabilities within 30 days of discovery; failure triggers suspension/withdrawal1. | 30 days | Certification body/National Authority1. |
| Document Retention | Manufacturers retain certification docs/product copies for 5 years post-withdrawal1. | 5 years | Certificate holder1. |
3. Monitoring and Compliance Enforcement
- Ongoing Monitoring: Certification bodies monitor:
- Random Audits: The National Cyber Security Authority selects certified products for random audits based on:
- Product category, assurance levels, certificate holders, or reported vulnerabilities1.
- Non-Compliance Consequences:
| Regulation | Key Requirement | Threshold/Deadline | Authority |
|---|---|---|---|
| Audit Selection | National Authority selects products for audit based on category, assurance level, or vulnerabilities1. | Not specified | National Cyber Security Authority1. |
| Non-Compliance | 30-day corrective action period; suspension/withdrawal for unresolved issues1. | 30 days | Certification body1. |
4. Transparency and Information Sharing
- Public Disclosure: Manufacturers must provide:
- Confidentiality: Vulnerability exploit details are not disclosed to the National Authority, but verification powers remain intact1.
5. EU Alignment and Future Integration
- The scheme references EU Regulation 2019/881 (Cybersecurity Act) and Implementing Regulation (EU) 2024/482 (EUCC scheme), signaling alignment with EU standards2.
- Post-EU accession, Albania’s National Cyber Security Authority will notify the European Cybersecurity Certification Group (ECCG) of:
Summary Answer
Albania’s draft National Cybersecurity Certification Scheme introduces a mandatory two-tier certification system (“considerable” and “high” security levels) for IT products, with validity up to 5 years1. Manufacturers must undergo technical evaluation by an ITSEF, retain documentation for 5 years post-withdrawal, and comply with vulnerability reporting obligations (30-day corrective action period)1. The National Cyber Security Authority enforces compliance through random audits and may suspend/withdraw certificates for non-compliance1. The scheme aligns with EU cybersecurity standards, including the EUCC scheme, and mandates public transparency in Albanian1, 2. Post-EU accession, Albania will coordinate with EU authorities on cross-border cybersecurity matters1.
Sources
- ↩ WTO TBT notification 25-09201 — Albania https://members.wto.org/crnattachments/2025/TBT/ALB/25_09201_00_e.pdf
- ↩ Draft –Decision of the Council of Ministers “On the Approval of the National Cybersecurity Certification Scheme, as well as the Security Levels of the Scheme” https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=Q:/G/TBTN25/ALB100.pdf&Open=True
