
ENS, LINCE, CPSTIC, and Common Criteria: what they are and how they differ
23 de July de 2026Privileged access is the control layer that determines who can get in, what they can do, and what gets logged inside a country’s most sensitive infrastructure: energy, banking, public administration, defense, water, healthcare. Managing this access (PAM, Privileged Access Management) is, by definition, a critical function of national and corporate security.
This article looks in depth, with verified data, at why technological sovereignty in privileged access solutions has become a top-tier strategic criterion for critical infrastructure organizations, what concrete risks this dependency carries, and what procurement, security, and compliance teams should evaluate before selecting a vendor.
1. The reality of dependency: what the data says
European technological dependency isn’t a perception, it’s a figure documented by the European Commission itself. The EU depends on third countries for more than 80% of its main digital products, services, infrastructure, and intellectual property, a gap the Commission considers essential to close for reasons of long-term economic strength, security, and competitiveness.
This dependency is especially concentrated in the infrastructure layers that any privileged access solution is later built on top of. According to the Real Instituto Elcano, Europe depends on a small number of non-EU cloud infrastructure providers for more than 70% of its cloud services, the very layer on which much of the PAM software deployed across European organizations runs today.
Independent analyses of the privileged access management sector confirm the same trend at the product level. The vendors recognized as market leaders by the major cybersecurity analyst firms are, in their vast majority, headquartered outside the European Union, while vendors of European origin typically compete in “challenger” or “visionary” categories, with notably smaller market shares.
There’s also a relevant data point on the demand side: according to the “Digital Sovereignty in Europe 2026” report by Fundación Telefónica and Metroscopia, 66% of Spanish companies are unaware of any European technological alternative to the vendors they use, even though 69% of companies would prioritize a European option if it offered an equivalent service. In other words, demand for sovereignty exists, but the visibility of European alternatives and their real ability to compete on features remains the main obstacle.
2. Jurisdictional risk in privileged access solutions
Adopting a PAM solution isn’t a purely technical decision: it’s a jurisdictional one. Certain extraterritorial legal frameworks require some technology vendors to provide access to data and systems upon request from authorities outside the European framework, regardless of where the servers are physically hosted or what European data protection law establishes.
When the solution in question manages privileged credentials, remote sessions, and access to OT systems or classified infrastructure, this jurisdictional risk stops being a hypothetical compliance concern and becomes a central variable in the organization’s security strategy. It’s not only about where data resides at rest, but about who has, by law, the power to demand access to it, and under what judicial or administrative oversight procedure.
Key questions for the procurement team:
- Under what jurisdiction does the manufacturer and its parent company legally operate?
- Which authorities can, by law, request access to the data or systems managed by its solution?
- Are there documented precedents of extraterritorial access requests on similar products?
- Does the service contract include explicit guarantees of notification in the event of requests from third countries?
3. Structural dependency on the technology supply chain
Adopting a privileged access solution means inheriting the manufacturer’s entire chain of decisions: update priorities, support continuity, product evolution, and, ultimately, exposure to export or technology-supply restrictions that can shift depending on the geopolitical context of the vendor’s country of origin.
There are documented precedents of technology access restrictions applied unilaterally based on the buyer’s country of origin or the product’s end use. No organization managing essential infrastructure can afford to have its privileged access layer depend on decisions made outside the European legal and political framework.
This structural dependency also carries an indirect economic cost: every euro invested in licenses from an external vendor is a euro not reinvested in developing Europe’s own technological capabilities, or in its cybersecurity industrial base.
4. Talent and R&D: sovereignty is also built through engineering
The discussion on technological sovereignty tends to focus on data location, but there’s an earlier dimension that matters just as much: where the product is designed and built. When a critical solution’s development and roadmap sit outside Europe, so does the real capacity for auditing it, the ability to demand local regulatory adaptations, and the training of specialized talent within Europe’s own ecosystem.
Every R&D project carried out on European soil leaves behind something beyond the product itself: engineers trained in applied cryptography, identity management, and secure remote access architectures, who go on to enrich the rest of the ecosystem when they move to new projects. Keeping R&D in Europe isn’t just a matter of data control, it’s a direct investment in the continent’s long-term capacity to design, audit, and sustain its own critical cybersecurity infrastructure.
5. The European regulatory framework: from obstacle to competitive advantage
For a manufacturer born and certified under the European regulatory framework (Esquema Nacional de Seguridad, DORA, the NIS2 Directive, GDPR), these requirements aren’t a compliance layer bolted on after the fact, they’re the same framework the product is designed around from its inception. This directly simplifies audit, certification, and public tender processes for the organizations that adopt it.
This advantage grows as the European regulatory framework tightens: the transposition of NIS2, the development of the DORA Regulation for the financial sector, the evolution of ENS itself, and the progressive entry into force of the Cyber Resilience Act (CRA), which requires security by design and vulnerability disclosure for any product with digital elements sold in the EU, are steadily raising the traceability, access control, and auditability requirements demanded of any technology vendor operating on essential infrastructure.
6. Risk by sector: what’s at stake depending on the activity
| Sector | What privileged access manages | Specific risk |
| Energy | SCADA/OT systems, distribution networks | Disruption of critical supply |
| Banking and insurance | Core banking systems, financial data | Data exposure and operational continuity under DORA |
| Public administration | Citizen management systems, case files | ENS compliance and personal data protection |
| Defense | Classified systems, tactical networks | Highest-tier access control requirements |
| Water and infrastructure | Industrial control systems | Continuity of essential services to the population |
| Healthcare | Clinical records, hospital systems | Confidentiality of health data and continuity of care |
7. Evaluation checklist for procurement and security teams
Before selecting a privileged access vendor for critical infrastructure, it’s recommended to systematically evaluate:
| Criterion | Key question |
| Jurisdiction | Under what legal framework does the manufacturer operate? |
| Development origin | Where is the product designed and maintained? |
| Continuity | What guarantees exist against geopolitical or commercial shifts? |
| Certification | Does it hold certifications under European regulation? |
| Auditability | Can the code be audited and regulatory adaptations be demanded? |
| Support | Are technical support and the engineering team accessible and responsive under a European SLA? |
| Regulatory scalability | Does the manufacturer already comply with the anticipated evolution of NIS2, DORA, and CRA? |
8. The Endurance case: certified Spanish engineering
In a market where most of the leading names operate outside the European Union’s jurisdictional framework, Cosmikal offers a concrete alternative. Endurance, a Remote Shielded Workspace solution, combines PAM, VDI, IAM, and DLP capabilities into a single product, with proprietary engineering designed, developed, and supported entirely in Spain.
Endurance is listed in the Catálogo de Productos Cualificados de Seguridad de las Tecnologías de la Información y las Comunicaciones (CPSTIC) maintained by Spain’s Centro Criptológico Nacional (CCN-CERT), a qualification that certifies its alignment with the Esquema Nacional de Seguridad from the product’s own design. This same CCN evaluation, given its status as a national certification body recognized by NATO, has also enabled Endurance’s inclusion in the NATO Information Assurance Product Catalogue (NIAPC), the reference catalogue the Alliance uses to identify technologies that meet its information assurance requirements.
Cosmikal is a leading Spanish cybersecurity technology developer and the manufacturer of the entirety of its solutions, backed by its own engineering team, with direct capacity to respond to the audit and regulatory compliance requirements of every critical infrastructure client.
Want to assess how Endurance covers your organization’s technological sovereignty and regulatory compliance criteria? Get in touch with our team.
9. Frequently asked questions
How dependent is Europe on non-European vendors for digital technology?
According to the European Commission, the EU depends on third countries for more than 80% of its main digital products, services, infrastructure, and intellectual property. a dependency that also affects the cloud infrastructure underpinning much of the cybersecurity software deployed across Europe.
What is a European manufacturer of privileged access management (PAM) solutions?
It’s a company that designs, develops, and maintains its own privileged access management technology under European jurisdiction, without depending on licenses, code, or infrastructure from third parties outside the EU’s regulatory framework.
Why does a PAM manufacturer’s jurisdiction matter?
Because it determines which authorities can, by law, request access to the data and systems managed by the solution, regardless of where the servers are hosted.
What certifications should a PAM solution for critical infrastructure in Spain hold?
It should be listed in CCN-CERT’s Catálogo de Productos Cualificados de Seguridad de las Tecnologías de la Información y las Comunicaciones (CPSTIC) and comply with the Esquema Nacional de Seguridad (ENS).
How does NIS2 affect the choice of a privileged access vendor?
NIS2 expands the number of sectors and entities required to implement auditable privileged access controls, which demands vendors capable of demonstrating European regulatory compliance from the product’s design stage.
What’s the difference between a manufacturer and an integrator in cybersecurity?
A manufacturer designs and develops its own original technology, while an integrator combines or resells third-party products. This difference is key to a solution’s auditability and real technological sovereignty.
Can an organization migrate from a non-European vendor to a European one without disrupting operations?
Yes, provided the European manufacturer offers planned migration processes and compatibility with existing systems; it’s advisable to require a detailed migration plan as part of the evaluation process.





