Skip to main content
Go to the home page of the European Commission (opens in new window)
English en
CORDIS - EU research results
CORDIS

Article Category

Article available in the following languages:

Building a digital environment that is transparent, accountable and resilient

The EU-funded CCAT project is increasing trust and resilience in the digital single market by adapting four academic tools for real-world use.

Europe’s new cybersecurity regulations are creating significant challenges for tech developers and organisations facing growing pressure to understand and implement new requirements. The CCAT(opens in new window) project is tackling this issue by adapting four open-source tools that enable continuous cybersecurity assessment of digital products and services.

Once is not enough

ICT product development in Europe is outpacing the implementation of the EU Cybersecurity Act(opens in new window) and Cyber Resilience Act(opens in new window). The fact that many products previously certified under existing security certification schemes continue to be reconfigured, integrated into larger systems and exposed to newly discovered vulnerabilities makes one thing very clear: one-time certification is not enough. What is needed is continuous and flexible security assessment to maintain both cybersecurity and regulatory compliance throughout the product life cycle. This is where the CCAT adaptation of four open-source tools – TLS-Scanner(opens in new window), SCRUTINY(opens in new window), ALVIE(opens in new window) and sec-certs(opens in new window) – comes in. Together, these tools make it possible to evaluate cybersecurity properties across different levels, including hardware, security-critical software, the transport layer security protocol and analytics for security-certified ICT products. All freely available on GitHub, they also provide practical, vendor-independent verification of security claims, support evaluation activities prior to formal security certification, facilitate compliance with evolving EU certification frameworks, and contribute to greater transparency and trust in cybersecurity assessment.

Iterative development, with people at the centre

“A key strength of CCAT lies in its human-centred approach,” states Vashek Matyas, professor and project coordinator from Masaryk University, Czechia. The tools are designed to be accessible and user friendly, making it easier for organisations to integrate them into their daily operations. At the same time, their open-source nature ensures that the tools can be inspected, extended and integrated without making users reliant on a single vendor. This approach promotes transparency in security assessments, enables adaptation to different industrial contexts, reduces deployment costs – thereby promoting wider uptake – and ensures long-term sustainability. Development of the four CCAT tools follows an iterative approach entailing three annual development cycles. Each cycle has four phases: assessing user needs, prioritising improvements, implementing updates to produce new tool versions, and testing updates to tools with users, with feedback informing the next cycle. The project’s initial development cycle ended in September 2026. CCAT is now entering its second cycle, which will focus on extending testing activities to a broader group of external users, whose feedback will inform further refinements and lead to the second tool’s release. This phase will also include more targeted promotion of the tools among ICT and cybersecurity solution providers, regulatory authorities, policymakers, certification laboratories and other potential users. Future training opportunities and resources are also consistently updated on the project website and social media channels. CCAT also intends to provide structured tutorials and training materials tailored to specific skill sets, supporting effective uptake and long-term use beyond the project’s duration. By combining open-source innovation, human-centred tool design and strong alignment with EU regulations, CCAT (Cybersecurity Certification and Assessment Tools) is helping organisations to build a more secure and resilient European digital environment. If you are interested in having your EU-funded project featured as a ‘Project of the Month’, please send us an email to editorial@cordis.europa.eu and tell us why!