The document presents Eurosmart's E-IoT-SCS certification scheme for IoT devices. The scheme aims to provide a risk-based, standardized certification process to evaluate IoT devices' security at the substantial assurance level, as defined in the EU Cybersecurity Act. This will help address issues like lack of security expertise and incentives for vendors, unknown risks, and the need for a common set of requirements. The certification process involves a vendor submitting a security profile for their device based on a questionnaire. This profile defines the device's security risks and goals. Certified assessment bodies then evaluate the device through conformity checks, vulnerability analysis, and other assurance activities tailored to the profile's risk level. Certifications can help improve trust among