Albania Establishes National Cybersecurity Certification Scheme

Albania has drafted a national cybersecurity certification scheme that defines security levels for information technology products, establishing mandatory certification and post-transparency obligations for manufacturers.

ALBANIA – CYBERSECURITY

Albania Creates Mandatory Cybersecurity Certification for Tech Products

Manufacturers must certify products and disclose security information afterwards.

What changed

Mandatory certification for information technology products under a national scheme.

Post-transparency obligations require manufacturers to disclose cybersecurity information after certification.

Standardized security levels and evaluation criteria are established for IT products.

Who it affects

IT product manufacturers must obtain certification and disclose security information post-certification.

Providers of IT products are subject to the same post-transparency disclosure requirements.

What to do

Submit IT products for evaluation under the new national certification scheme.

Disclose required cybersecurity-related information after certification is granted.

Albania — national cybersecurity certification scheme

Compliance Answer: Albania’s National Cybersecurity Certification Scheme

Direct Answer

Albania’s draft Decision of the Council of Ministers “On the Approval of the National Cybersecurity Certification Scheme, as well as the Security Levels of the Scheme” establishes a mandatory cybersecurity certification framework for information technology (IT) products. The scheme defines two security levels (“considerable” and “high”), imposes certification obligations on manufacturers, and introduces post-certification transparency and vulnerability management duties. Certification is valid for up to 5 years, with extensions requiring approval from the National Cyber Security Authority1, 2.

Regulation Analysis

1. Security Levels and Certification Requirements

The scheme mandates certification for IT products at two security levels, aligned with Common Criteria (CC) assurance levels (AVA_VAN):

  • “Considerable” security level: Covers AVA_VAN 1 or 21.
  • “High” security level: Covers AVA_VAN 3, 4, or 51.

Certification is required for products to demonstrate compliance with these levels, and the scheme distinguishes between standard and enhanced security component usage based on the certified level1.

RegulationKey RequirementThreshold/DeadlineAuthority
Security Levels (Art. 4)Certification required for IT products at “considerable” (AVA_VAN 1–2) or “high” (AVA_VAN 3–5) levels1.Not specifiedCertification bodies1.
Certification ValidityMaximum validity of 5 years, extendable with approval1.5 years (extendable)National Cyber Security Authority1.

2. Certification Process and Obligations

a. Certification Steps

  1. Application: Manufacturers submit documentation to a certification body (authorized by the National Cyber Security Authority) and an IT Security Evaluation Facility (ITSEF)1, 2.
  2. Evaluation: ITSEF conducts technical assessments (e.g., structured interviews, pilot certifications) and issues a technical evaluation report1.
  3. Certification: The certification body issues a certificate (electronic format) and a certification report (publicly available, detailing security features, installation guidance, and evaluation results)1, 2.
  4. Public Disclosure: Manufacturers must make cybersecurity-related information publicly accessible in Albanian1.

b. Post-Certification Obligations

  • Document Retention: Manufacturers must securely retain:
    • Certification documentation (submitted to the certification body/ITSEF)1.
    • A copy of the certified IT product1.
    • Retention period: 5 years post-certificate withdrawal1.
  • Vulnerability Management:
    • Manufacturers must monitor, analyze, and report vulnerabilities affecting certified products1.
    • Immediate reporting to the certification body or National Cyber Security Authority is required for discovered vulnerabilities1.
    • Cooperation with other cybersecurity authorities (e.g., EU authorities post-accession) for cross-border vulnerability disclosures1.
RegulationKey RequirementThreshold/DeadlineAuthority
Certification ReportCertification body issues a publicly available report (executive summary, security services, architecture, test results)1.Not specifiedCertification body1.
Vulnerability ReportingManufacturers must report vulnerabilities within 30 days of discovery; failure triggers suspension/withdrawal1.30 daysCertification body/National Authority1.
Document RetentionManufacturers retain certification docs/product copies for 5 years post-withdrawal1.5 yearsCertificate holder1.

3. Monitoring and Compliance Enforcement

  • Ongoing Monitoring: Certification bodies monitor:
    • Manufacturer compliance with obligations (e.g., vulnerability management)1.
    • Product compliance with security requirements1.
    • Protection profiles (security specifications for product categories)1.
  • Random Audits: The National Cyber Security Authority selects certified products for random audits based on:
    • Product category, assurance levels, certificate holders, or reported vulnerabilities1.
  • Non-Compliance Consequences:
    • 30-day corrective action period for violations (e.g., failure to report vulnerabilities)1.
    • Suspension or withdrawal of certification for unresolved non-compliance1.
    • Repeated violations trigger mandatory certificate withdrawal1.
RegulationKey RequirementThreshold/DeadlineAuthority
Audit SelectionNational Authority selects products for audit based on category, assurance level, or vulnerabilities1.Not specifiedNational Cyber Security Authority1.
Non-Compliance30-day corrective action period; suspension/withdrawal for unresolved issues1.30 daysCertification body1.

4. Transparency and Information Sharing

  • Public Disclosure: Manufacturers must provide:
    • Certificate validity information1.
    • Publicly accessible cybersecurity details (e.g., security features, installation guidance)1.
    • Historical certification data for traceability1.
  • Confidentiality: Vulnerability exploit details are not disclosed to the National Authority, but verification powers remain intact1.

5. EU Alignment and Future Integration

  • The scheme references EU Regulation 2019/881 (Cybersecurity Act) and Implementing Regulation (EU) 2024/482 (EUCC scheme), signaling alignment with EU standards2.
  • Post-EU accession, Albania’s National Cyber Security Authority will notify the European Cybersecurity Certification Group (ECCG) of:
    • Certificate extensions beyond 5 years1.
    • Cross-border vulnerability investigations1.

Summary Answer

Albania’s draft National Cybersecurity Certification Scheme introduces a mandatory two-tier certification system (“considerable” and “high” security levels) for IT products, with validity up to 5 years1. Manufacturers must undergo technical evaluation by an ITSEF, retain documentation for 5 years post-withdrawal, and comply with vulnerability reporting obligations (30-day corrective action period)1. The National Cyber Security Authority enforces compliance through random audits and may suspend/withdraw certificates for non-compliance1. The scheme aligns with EU cybersecurity standards, including the EUCC scheme, and mandates public transparency in Albanian1, 2. Post-EU accession, Albania will coordinate with EU authorities on cross-border cybersecurity matters1.

Sources

  1. WTO TBT notification 25-09201 — Albania https://members.wto.org/crnattachments/2025/TBT/ALB/25_09201_00_e.pdf
  2. Draft –Decision of the Council of Ministers “On the Approval of the National Cybersecurity Certification Scheme, as well as the Security Levels of the Scheme” https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=Q:/G/TBTN25/ALB100.pdf&Open=True

Create your account