Don’t do SECURITY. Do business SECURELY.

EU Cybersecurity Act enters into force

The EU Cybersecurity Act gives ENISA a permanent mandate and creates an EU-wide cybersecurity certification framework.

The EU Cybersecurity Act (Regulation (EU) 2019/881) enters into force today.

Key elements

  • ENISA, the EU Agency for Cybersecurity, receives a permanent mandate and stronger role.
  • A new European cybersecurity certification framework for ICT products, services and processes, with “basic”, “substantial” and “high” assurance levels.
  • Certification schemes will be developed for specific product and service types, with cloud services and Common Criteria-based product evaluation among the first candidates.

Certification under the framework is voluntary for now, but future EU legislation may require or rely on it. Technology suppliers selling into the EU should keep an eye on the schemes as they are developed.

Source: Regulation (EU) 2019/881 – Cybersecurity Act (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights