The 2019 European Cybersecurity Act renews and redefines the mandate of the European Union Agency for Cybersecurity (ENISA) which was originally created in 2004 as the European Network and Information Security Agency. The objective is to ensure a high level of cybersecurity, cyber resilience and trust across the EU and for this purpose builds on voluntary European cybersecurity certification schemes for ICT (Information and Communications Technology) products, services and processes. In 2024, the European Commission had issued a Delegated Act related to the adoption of the voluntary European common criteria-based cybersecurity certification scheme (EUCC)—the first scheme adopted at EU level. It introduces certificates for ICT products (i.e., hardware and software including components such as chips and smart cards) at the ‘substantial’ or ‘high’ assurance levels. Further cybersecurity certification schemes in the pipeline are the EU Cloud Services Scheme (EUCS) and 5G Cybersecurity Certification Scheme. In the present chapter, we will give a detailed summary of the Cybersecurity Act and ENISA’s role as established therein. Also, a summary of the above-mentioned Cybersecurity Certification Schemes will be given which constitute an additional pillar in addition to other Cybersecurity initiatives including the Radio Equipment Directive (RED) Articles 3(3)(d/e/f) on Cybersecurity and Privacy and the novel Cyber Resilience Act (CRA). Finally, interdependencies with other regulations are being discussed as it is for example the case for the renewed European Machinery Directive.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Introduction to the European Cybersecurity Act

  • Markus Mueck,
  • Christophe Gaie

摘要

The 2019 European Cybersecurity Act renews and redefines the mandate of the European Union Agency for Cybersecurity (ENISA) which was originally created in 2004 as the European Network and Information Security Agency. The objective is to ensure a high level of cybersecurity, cyber resilience and trust across the EU and for this purpose builds on voluntary European cybersecurity certification schemes for ICT (Information and Communications Technology) products, services and processes. In 2024, the European Commission had issued a Delegated Act related to the adoption of the voluntary European common criteria-based cybersecurity certification scheme (EUCC)—the first scheme adopted at EU level. It introduces certificates for ICT products (i.e., hardware and software including components such as chips and smart cards) at the ‘substantial’ or ‘high’ assurance levels. Further cybersecurity certification schemes in the pipeline are the EU Cloud Services Scheme (EUCS) and 5G Cybersecurity Certification Scheme. In the present chapter, we will give a detailed summary of the Cybersecurity Act and ENISA’s role as established therein. Also, a summary of the above-mentioned Cybersecurity Certification Schemes will be given which constitute an additional pillar in addition to other Cybersecurity initiatives including the Radio Equipment Directive (RED) Articles 3(3)(d/e/f) on Cybersecurity and Privacy and the novel Cyber Resilience Act (CRA). Finally, interdependencies with other regulations are being discussed as it is for example the case for the renewed European Machinery Directive.