As a reminder, European Parliament and Council negotiators agreed on the European Cybersecurity Act on 10 December 2018.
While waiting for the European Parliament and Council to formally adopt the regulation, substantive preparations are taking place for the new cybersecurity certification framework.
The future cybersecurity certificates will be recognised throughout the EU, and the certification schemes will replace national cybersecurity certification requirements.
What’s your place in all this?
As you will see in Cullen International’s new infographic, industry stakeholders and EU member states can get involved at various stages in the planning and creation of EU certification schemes. However, the process is driven by the European Commission and implemented by the EU Cybersecurity Agency (ENISA).
But what’s covered by the framework?
The framework is for the creation of EU cybersecurity certification schemes for specific ICT products, services and processes, but our infographic takes you all the way from the general work programme to when certificates are issued under a scheme.
Manufacturers and service providers can decide whether or not to get certified (or make a self-assessment in certain cases), unless certification is required by national or EU laws.
Our certification framework infographic makes the path to certification simple.
To get a free download of Cullen International’s infographic, please just "Request Access" below.
If you are interested in more cybersecurity regulatory analysis, please contact us.
We will update the infographic if there are any changes to the Cybersecurity Act before it is formally adopted (expected spring 2019).
more news
18 March 26
Global trends in 5G and beyond
Our latest Global Trends benchmark covers 5G policies and regulations and their evolution towards 6G across 20 jurisdictions around the world.
16 March 26
Africa tightens oversight of IoT connectivity as roaming and SIM rules diverge
Cullen International’s latest benchmarks assess the regulatory frameworks affecting IoT and M2M services in Africa. The research examines three core areas: whether permanent roaming is permitted, requirements for authorisation and notification, and whether and how SIM cards should be registered.
12 March 26
National implementation of the EU Gigabit Infrastructure Act
The Gigabit Infrastructure Act (GIA) is a regulation and as such directly applicable in all member states without the need for transposition into national law. Despite being a regulation, the GIA often sets minimum requirements, on top of which member states can adopt additional measures to address country-specific circumstances. Our new benchmark shows the choices made by member states when implementing the GIA.