emendrix

Cybersecurity Act

32019R0881 · every event for this act · on EUR-Lex

Everything Regulation (EU) 2025/37 amended

in force 2025-02-04

32019R0881 → 02019R0881-20250204

Amended by Regulation (EU) 2025/37 32025R0037

Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services (Text with EEA relevance)

detected 2026-08-13

19 provisions touched — 19 substantive, 0 date-only, 1 disputed · 1 change without an explanation

Emendrix checks every change against three independent sources. Where they disagree it says so rather than picking a winner.

MODIFIED +45 −17 Art. 1 Subject matter and scope

applies from: unchanged

Point (b) now lists managed security services alongside ICT products, ICT services, and ICT processes as subject to the certification scheme framework, whereas the earlier version did not mention managed security services.

Cited: Art. 1, v1 · Art. 1, v2

text before / after

32019R088102019R0881-20250204

Article 1 Subject matter and scope 1. With a view to ensuring the proper functioning of the internal market while aiming to achieve a high level of cybersecurity, cyber resilience and trust within the Union, this Regulation lays down: (a) objectives, tasks and organisational matters relating to ENISA (the European Union Agency for Cybersecurity); and (b) a framework for the establishment of European cybersecurity certification schemes for the purpose of ensuring an adequate level of cybersecurity for ICT products, ICT services, ICT processes, and managed security services and ICT processes in the Union, as well as for the purpose of avoiding the fragmentation of the internal market with regard to cybersecurity certification schemes in the Union. The framework referred to in point (b) of the first subparagraph applies without prejudice to specific provisions in other Union legal acts regarding voluntary or mandatory certification. 2. This Regulation is without prejudice to the competences of the Member States regarding activities concerning public security, defence, national security and the activities of the State in areas of criminal law.

MODIFIED +678 −126 Art. 2 Definitions

applies from: unchanged

A new definition (14a) for 'managed security service' has been added, describing it as a service provided to a third party involving cybersecurity risk management activities such as incident handling, penetration testing, security audits and consulting.

The definitions of European cybersecurity certification scheme, national cybersecurity certification scheme, European cybersecurity certificate, technical specification, assurance level and conformity self-assessment have each been extended to also reference managed security services alongside ICT products, ICT services and ICT processes.

Cited: Art. 2, v2 · Art. 2, v1

text before / after

32019R088102019R0881-20250204

Article 2 Definitions For the purposes of this Regulation, the following definitions apply: (1) cybersecurity means the activities necessary to protect network and information systems, the users of such systems, and other persons affected by cyber threats; (2) network and information system means a network and information system as defined in point (1) of Article 4 of Directive (EU) 2016/1148; (3) national strategy on the security of network and information systems means a national strategy on the security of network and information systems as defined in point (3) of Article 4 of Directive (EU) 2016/1148; (4) operator of essential services means an operator of essential services as defined in point (4) of Article 4 of Directive (EU) 2016/1148; (5) digital service provider means a digital service provider as defined in point (6) of Article 4 of Directive (EU) 2016/1148; (6) incident means an incident as defined in point (7) of Article 4 of Directive (EU) 2016/1148; (7) incident handling means incident handling as defined in point (8) of Article 4 of Directive (EU) 2016/1148; (8) cyber threat means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons; (9) European cybersecurity certification scheme means a comprehensive set of rules, technical requirements, standards and procedures that are established at Union level and that apply to the certification or conformity assessment of specific ICT products, ICT services services, ICT processes or ICT processes; managed security services; (10) national cybersecurity certification scheme means a comprehensive set of rules, technical requirements, standards and procedures developed and adopted by a national public authority and that apply to the certification or conformity assessment of ICT products, ICT services and services, ICT processes or managed security services falling under the scope of the specific scheme; (11) European cybersecurity certificate means a document issued by a relevant body, attesting that a given ICT product, ICT service or service, ICT process or managed security service has been evaluated for compliance with specific security requirements laid down in a European cybersecurity certification scheme; (12) ICT product means an element or a group of elements of a network or information system; (13) ICT service means a service consisting fully or mainly in the transmission, storing, retrieving or processing of information by means of network and information systems; (14) ICT process means a set of activities performed to design, develop, deliver or maintain an ICT product or ICT service; (14a) managed security service means a service provided to a third party consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, such as incident handling, penetration testing, security audits and consulting, including expert advice, related to technical support; (15) accreditation means accreditation as defined in point (10) of Article 2 of Regulation (EC) No 765/2008; (16) national accreditation body means a national accreditation body as defined in point (11) of Article 2 of Regulation (EC) No 765/2008; (17) conformity assessment means a conformity assessment as defined in point (12) of Article 2 of Regulation (EC) No 765/2008; (18) conformity assessment body means a conformity assessment body as defined in point (13) of Article 2 of Regulation (EC) No 765/2008; (19) standard means a standard as defined in point (1) of Article 2 of Regulation (EU) No 1025/2012; (20) technical specification means a document that prescribes the technical requirements to be met by, or conformity assessment procedures relating to, an ICT product, ICT service service, ICT process or ICT process; managed security service; (21) assurance level means a basis for confidence that an ICT product, ICT service or service, ICT process or managed security service meets the security requirements of a specific European cybersecurity certification scheme, and indicates the level at which an ICT product, ICT service or service, ICT process or managed security service has been evaluated but as such does not measure the security of the ICT product, ICT service or service, ICT process or managed security service concerned; (22) conformity self-assessment means an action carried out by a manufacturer or provider of ICT products, ICT services services, ICT processes or ICT processes, managed security services, which evaluates whether those ICT products, ICT services or services, ICT processes or managed security services meet the requirements of a specific European cybersecurity certification scheme.

MODIFIED +72 −47 Art. 4 Objectives

applies from: unchanged

Paragraph 6 removes the commas that previously set off the phrases "with a view to avoiding the fragmentation of the internal market" and "with a view to increasing the transparency of the cybersecurity of ICT products, ICT services and ICT processes" from the surrounding sentences.

The list of items whose cybersecurity transparency is to be increased is expanded from ICT products, ICT services and ICT processes to also include managed security services.

Cited: Art. 4, v1 · Art. 4, v2

text before / after

32019R088102019R0881-20250204

Article 4 Objectives 1. ENISA shall be a centre of expertise on cybersecurity by virtue of its independence, the scientific and technical quality of the advice and assistance it delivers, the information it provides, the transparency of its operating procedures, the methods of operation, and its diligence in carrying out its tasks. 2. ENISA shall assist the Union institutions, bodies, offices and agencies, as well as Member States, in developing and implementing Union policies related to cybersecurity, including sectoral policies on cybersecurity. 3. ENISA shall support capacity-building and preparedness across the Union by assisting the Union institutions, bodies, offices and agencies, as well as Member States and public and private stakeholders, to increase the protection of their network and information systems, to develop and improve cyber resilience and response capacities, and to develop skills and competencies in the field of cybersecurity. 4. ENISA shall promote cooperation, including information sharing and coordination at Union level, among Member States, Union institutions, bodies, offices and agencies, and relevant private and public stakeholders on matters related to cybersecurity. 5. ENISA shall contribute to increasing cybersecurity capabilities at Union level in order to support the actions of Member States in preventing and responding to cyber threats, in particular in the event of cross-border incidents. 6. ENISA shall promote the use of European cybersecurity certification, certification with a view to avoiding the fragmentation of the internal market. ENISA shall contribute to the establishment and maintenance of a European cybersecurity certification framework in accordance with Title III of this Regulation, Regulation with a view to increasing the transparency of the cybersecurity of ICT products, ICT services services, ICT processes and ICT processes, managed security services, thereby strengthening trust in the digital internal market and its competitiveness. 7. ENISA shall promote a high level of cybersecurity awareness, including cyber-hygiene and cyber-literacy among citizens, organisations and businesses.

MODIFIED +188 −78 Art. 8 Market, cybersecurity certification, and standardisation

applies from: unchanged

The introductory text of paragraph 1 and point (b) now refer to managed security services in addition to ICT products, ICT services and ICT processes, when describing what ENISA supports and prepares candidate certification schemes for.

Paragraphs 3 and 5 likewise add managed security services alongside ICT products, ICT services and ICT processes in describing the scope of guidelines, good practices and standardisation activities.

Cited: Art. 8, v2

text before / after

32019R088102019R0881-20250204

Article 8 Market, cybersecurity certification, and standardisation 1. ENISA shall support and promote the development and implementation of Union policy on the cybersecurity certification of ICT products, ICT services services, ICT processes and ICT processes, managed security services, as established in Title III of this Regulation, by: (a) monitoring developments, on an ongoing basis, in related areas of standardisation and recommending appropriate technical specifications for use in the development of European cybersecurity certification schemes pursuant to point (c) of Article 54(1) where standards are not available; (b) preparing candidate European cybersecurity certification schemes (candidate schemes) for ICT products, ICT services and services, ICT processes and managed security services in accordance with Article 49; (c) evaluating adopted European cybersecurity certification schemes in accordance with Article 49(8); (d) participating in peer reviews pursuant to Article 59(4); (e) assisting the Commission in providing the secretariat of the ECCG pursuant to Article 62(5). 2. ENISA shall provide the secretariat of the Stakeholder Cybersecurity Certification Group pursuant to Article 22(4). 3. ENISA shall compile and publish guidelines and develop good practices, concerning the cybersecurity requirements for ICT products, ICT services services, ICT processes and ICT processes, managed security services, in cooperation with national cybersecurity certification authorities and industry in a formal, structured and transparent way. 4. ENISA shall contribute to capacity-building related to evaluation and certification processes by compiling and issuing guidelines as well as by providing support to Member States at their request. 5. ENISA shall facilitate the establishment and take-up of European and international standards for risk management and for the security of ICT products, ICT services services, ICT processes and ICT processes. managed security services. 6. ENISA shall draw up, in collaboration with Member States and industry, advice and guidelines regarding the technical areas related to the security requirements for operators of essential services and digital service providers, as well as regarding already existing standards, including Member States’ national standards, pursuant to Article 19(2) of Directive (EU) 2016/1148. 7. ENISA shall perform and disseminate regular analyses of the main trends in the cybersecurity market on both the demand and supply sides, with a view to fostering the cybersecurity market in the Union.

MODIFIED +625 −22 Art. 46 European cybersecurity certification framework

applies from: unchanged

Paragraph 1 now lists managed security services alongside ICT products, ICT services and ICT processes as part of the digital single market the framework aims to create.

Paragraph 2 adds a new statement that the framework shall also attest that evaluated managed security services meet specified security requirements protecting the availability, authenticity, integrity and confidentiality of data accessed, processed, stored or transmitted in providing those services, and that the services are provided continuously by staff with sufficient competence, expertise, experience and professional integrity.

The prior text of both paragraphs referred only to ICT products, ICT services and ICT processes, without any mention of managed security services.

Cited: Art. 46, v2 · Art. 46, v1

text before / after

32019R088102019R0881-20250204

Article 46 European cybersecurity certification framework 1. The European cybersecurity certification framework shall be established in order to improve the conditions for the functioning of the internal market by increasing the level of cybersecurity within the Union and enabling a harmonised approach at Union level to European cybersecurity certification schemes, with a view to creating a digital single market for ICT products, ICT services services, ICT processes and ICT processes. managed security services. 2. The European cybersecurity certification framework shall provide for a mechanism to establish European cybersecurity certification schemes and to attest that the ICT products, ICT services and ICT processes that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the functions or services offered by, or accessible via, those products, services and processes throughout their life cycle.In addition, it shall attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity and confidentiality of data which are accessed, processed, stored or transmitted in relation to the provision of those services, and that those services are provided continuously with the requisite competence, expertise and experience by staff with a sufficient and appropriate level of relevant technical knowledge and professional integrity.

MODIFIED +376 −108 Art. 47 The Union rolling work programme for European cybersecurity certification

applies from: unchanged

Paragraph 2 now adds managed security services, alongside ICT products, ICT services and ICT processes, or categories thereof, as items capable of benefiting from inclusion in a European cybersecurity certification scheme.

Paragraph 3's introductory wording and point (a) likewise now refer to managed security services alongside ICT products, ICT services and ICT processes when listing grounds for inclusion in the Union rolling work programme.

A new ground, point (ca), has been added to the list of justifications in paragraph 3, referring to technological developments and the availability and development of international cybersecurity certification schemes and international standards and standards used by the industry.

Cited: Art. 47, v2

text before / after

32019R088102019R0881-20250204

Article 47 The Union rolling work programme for European cybersecurity certification 1. The Commission shall publish a Union rolling work programme for European cybersecurity certification (the Union rolling work programme) that shall identify strategic priorities for future European cybersecurity certification schemes. 2. The Union rolling work programme shall in particular include a list of ICT products, ICT services and services, ICT processes and managed security services, or categories thereof thereof, that are capable of benefiting from being included in the scope of a European cybersecurity certification scheme. 3. Inclusion of specific ICT products, ICT services and ICT processes or categories thereof in the Union rolling work programme of specific ICT products, ICT services, ICT processes, or managed security services, or categories thereof, shall be justified on the basis of one or more of the following grounds: (a) the availability and the development of national cybersecurity certification schemes covering a specific category of ICT products, ICT services or services, ICT processes or managed security services and, in particular, as regards the risk of fragmentation; (b) relevant Union or Member State law or policy; (c) market demand; (ca) technological developments and the availability and development of international cybersecurity certification schemes and international standards and standards used by the industry; (d) developments in the cyber threat landscape; (e) request for the preparation of a specific candidate scheme by the ECCG. 4. The Commission shall take due account of the opinions issued by the ECCG and the Stakeholder Certification Group on the draft Union rolling work programme. 5. The first Union rolling work programme shall be published by 28 June 2020. The Union rolling work programme shall be updated at least once every three years and more often if necessary.

MODIFIED +587 −42 Art. 49 Preparation, adoption and review of a European cybersecurity certification scheme

applies from: unchanged

Paragraphs 1, 2 and 7 now refer to Article 51a alongside Articles 51, 52 and 54 when describing the requirements a candidate scheme must meet, and paragraph 7 also adds managed security services to the list of ICT products, services and processes a scheme may cover.

Paragraph 3 adds that stakeholder consultation must occur in a timely manner and that ENISA must inform the Commission how it complied with this when transmitting the candidate scheme.

Paragraph 4 adds a sentence describing the composition of the ad hoc working groups, specifying inclusion of experts from Member State public administrations, Union institutions, bodies, offices and agencies, and the private sector, subject to the procedures and discretion in Article 20(4).

Cited: Art. 49, v1 · Art. 49, v2

text before / after

32019R088102019R0881-20250204

Article 49 Preparation, adoption and review of a European cybersecurity certification scheme 1. Following a request from the Commission pursuant to Article 48, ENISA shall prepare a candidate scheme which that meets the applicable requirements set out in Articles 51, 51a, 52 and 54. 2. Following a request from the ECCG pursuant to Article 48(2), ENISA may prepare a candidate scheme which that meets the applicable requirements set out in Articles 51, 51a, 52 and 54. If ENISA refuses such a request, it shall give reasons for its refusal. Any decision to refuse such a request shall be taken by the Management Board. 3. When preparing a candidate scheme, ENISA shall consult all relevant stakeholders in a timely manner by means of a formal, open, transparent and inclusive consultation process. When transmitting the candidate scheme to the Commission pursuant to paragraph 6, ENISA shall provide information on the manner in which it has complied with this paragraph. 4. For each candidate scheme, ENISA shall establish an ad hoc working group in accordance with Article 20(4) for the purpose of providing ENISA with specific advice and expertise. Those ad hoc working groups shall, as appropriate and without prejudice to the procedures and discretion provided for in Article 20(4), include experts from the public administrations of the Member States, the Union institutions, bodies, offices and agencies, and the private sector. 5. ENISA shall closely cooperate with the ECCG. The ECCG shall provide ENISA with assistance and expert advice in relation to the preparation of the candidate scheme and shall adopt an opinion on the candidate scheme. 6. ENISA shall take utmost account of the opinion of the ECCG before transmitting the candidate scheme prepared in accordance with paragraphs 3, 4 and 5 to the Commission. The opinion of the ECCG shall not bind ENISA, nor shall the absence of such an opinion prevent ENISA from transmitting the candidate scheme to the Commission. 7. The Commission, based Commission may, on the basis of the candidate scheme prepared by ENISA, may adopt implementing acts providing for a European cybersecurity certification scheme for ICT products, ICT services and services, ICT processes and managed security services which meets the relevant requirements set out in Articles 51, 51a, 52 and 54. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 66(2). 8. At least every five years, ENISA shall evaluate each adopted European cybersecurity certification scheme, taking into account the feedback received from interested parties. If necessary, the Commission or the ECCG may request ENISA to start the process of developing a revised candidate scheme in accordance with Article 48 and this Article.

INSERTED +1,614 −0 Art. 49a Information and consultation on the European cybersecurity certification schemes

applies from: unknown (an inserted provision states its own application date only in prose)

Article 49a is a newly added provision setting out obligations to make certain information public and to allow information exchange and consultation among the Commission, ENISA, the European Parliament and the Council regarding European cybersecurity certification schemes.

It covers publication of the Commission's requests to ENISA to prepare or review a scheme, quarterly information sharing during scheme preparation, the possibility of inviting discussion on scheme functioning, and consideration of views expressed when the Regulation is evaluated under Article 67.

Cited: Art. 49a, v2

text before / after

inserted text (02019R0881-20250204)

Article 49a
Information and consultation on the European cybersecurity certification schemes
1. The Commission shall make the information on its request to ENISA to prepare a candidate scheme or to review an existing European cybersecurity certification scheme as referred to in Article 48 publicly available.
2. During the preparation of a candidate scheme by ENISA pursuant to Article 49, the European Parliament, the Council or both may request the Commission, in its capacity as chair of the ECCG, and ENISA to present relevant information on a draft candidate scheme on a quarterly basis. Upon the request of the European Parliament or the Council, ENISA, in agreement with the Commission and without prejudice to Article 27, may make available to the European Parliament and to the Council relevant parts of a draft candidate scheme in a manner appropriate to the confidentiality level required, and where appropriate in a restricted manner.
3. In order to enhance the dialogue between the Union institutions and to contribute to a formal, open, transparent and inclusive consultation process, the European Parliament, the Council or both may invite the Commission and ENISA to discuss matters concerning the functioning of European cybersecurity certification schemes for ICT products, ICT services, ICT processes or managed security services.
4. The Commission shall take into account, where appropriate, elements arising from the views expressed by the European Parliament and by the Council on the matters referred to in paragraph 3 of this Article when evaluating this Regulation pursuant to Article 67.

MODIFIED +95 −0 Art. 51 Security objectives of European cybersecurity certification schemes for ICT products, ICT services and ICT processes

applies from: unchanged

The heading now adds the phrase "for ICT products, ICT services and ICT processes" after "European cybersecurity certification schemes".

The opening sentence of Article 51 similarly adds the words "for ICT products, ICT services or ICT processes" after the reference to a European cybersecurity certification scheme, while the list of security objectives in points (a) to (j) remains unchanged.

Cited: Art. 51, v2 · Art. 51, v1

text before / after

32019R088102019R0881-20250204

Article 51 Security objectives of European cybersecurity certification schemes for ICT products, ICT services and ICT processes A European cybersecurity certification scheme for ICT products, ICT services or ICT processes shall be designed to achieve, as applicable, at least the following security objectives: (a) to protect stored, transmitted or otherwise processed data against accidental or unauthorised storage, processing, access or disclosure during the entire life cycle of the ICT product, ICT service or ICT process; (b) to protect stored, transmitted or otherwise processed data against accidental or unauthorised destruction, loss or alteration or lack of availability during the entire life cycle of the ICT product, ICT service or ICT process; (c) that authorised persons, programs or machines are able only to access the data, services or functions to which their access rights refer; (d) to identify and document known dependencies and vulnerabilities; (e) to record which data, services or functions have been accessed, used or otherwise processed, at what times and by whom; (f) to make it possible to check which data, services or functions have been accessed, used or otherwise processed, at what times and by whom; (g) to verify that ICT products, ICT services and ICT processes do not contain known vulnerabilities; (h) to restore the availability and access to data, services and functions in a timely manner in the event of a physical or technical incident; (i) that ICT products, ICT services and ICT processes are secure by default and by design; (j) that ICT products, ICT services and ICT processes are provided with up-to-date software and hardware that do not contain publicly known vulnerabilities, and are provided with mechanisms for secure updates.

INSERTED +1,839 −0 Art. 51a Security objectives of European cybersecurity certification schemes for managed security services

applies from: unknown (an inserted provision states its own application date only in prose)

A new Article 51a is added, setting out security objectives that European cybersecurity certification schemes for managed security services are to be designed to achieve, covering staff competence and integrity, provider internal quality procedures, protection of processed data, timely restoration of availability and access after incidents, access limited to authorised persons, programs or machines, record-keeping of access and use, and secure-by-design and by-default ICT products, services and processes free of publicly known vulnerabilities.

Cited: Art. 51a, v2

text before / after

inserted text (02019R0881-20250204)

Article 51a
Security objectives of European cybersecurity certification schemes for managed security services
A European cybersecurity certification scheme for managed security services shall be designed to achieve, as applicable, at least the following security objectives:
(a) that the managed security services are provided with the requisite competence, expertise and experience, including that the staff tasked with providing those services have a sufficient and appropriate level of technical knowledge and competence in the specific field, sufficient and appropriate experience, and the highest degree of professional integrity;
(b) that the provider has appropriate internal procedures in place to ensure that the managed security services are provided at a sufficient and appropriate level of quality at all times;
(c) that data accessed, stored, transmitted or otherwise processed in relation to the provision of managed security services are protected against accidental or unauthorised access, storage, disclosure, destruction, other processing, or loss or alteration or lack of availability;
(d) that the availability of, and access to, data, services and functions is restored in a timely manner in the event of a physical or technical incident;
(e) that authorised persons, programs or machines are able to access only the data, services or functions to which their access rights refer;
(f) that a record is kept and is available for assessment, of the data, services or functions that have been accessed, used or otherwise processed, at what times and by whom;
(g) that the ICT products, ICT services and ICT processes deployed in the provision of the managed security services are secure by design and by default and, where applicable, include the latest security updates and do not contain publicly known vulnerabilities.

MODIFIED +314 −109 Art. 52 Assurance levels of European cybersecurity certification schemes

applies from: unchanged

Paragraphs 1, 3, 5, 6 and 7 of Article 52 now add references to managed security services alongside ICT products, ICT services and ICT processes wherever those categories are listed as subject to assurance levels, security requirements, and evaluation activities.

The prior version of these same paragraphs referred only to ICT products, ICT services and ICT processes, without mention of managed security services.

Cited: Art. 52, v2 · Art. 52, v1

text before / after

32019R088102019R0881-20250204

Article 52 Assurance levels of European cybersecurity certification schemes 1. A European cybersecurity certification scheme may specify one or more of the following assurance levels for ICT products, ICT services services, ICT processes and ICT processes: managed security services: basic, substantial or high. The assurance level shall be commensurate with the level of the risk associated with the intended use of the ICT product, ICT service service, ICT process or ICT process, managed security service, in terms of the probability and impact of an incident. 2. European cybersecurity certificates and EU statements of conformity shall refer to any assurance level specified in the European cybersecurity certification scheme under which the European cybersecurity certificate or EU statement of conformity is issued. 3. The security requirements corresponding to each assurance level shall be provided in the relevant European cybersecurity certification scheme, including the corresponding security functionalities and the corresponding rigour and depth of the evaluation that the ICT product, ICT service or service, ICT process or managed security service is to undergo. 4. The certificate or the EU statement of conformity shall refer to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of, or to prevent cybersecurity incidents. 5. A European cybersecurity certificate or EU statement of conformity that refers to assurance level basic shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate or that EU statement of conformity is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the known basic risks of incidents and cyberattacks. The evaluation activities to be undertaken shall include at least a review of technical documentation. Where such a review is not appropriate, substitute evaluation activities with equivalent effect shall be undertaken. 6. A European cybersecurity certificate that refers to assurance level substantial shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the known cybersecurity risks, and the risk of incidents and cyberattacks carried out by actors with limited skills and resources. The evaluation activities to be undertaken shall include at least the following: a review to demonstrate the absence of publicly known vulnerabilities and testing to demonstrate that the ICT products, ICT services or services, ICT processes or managed security services correctly implement the necessary security functionalities. Where any such evaluation activities are not appropriate, substitute evaluation activities with equivalent effect shall be undertaken. 7. A European cybersecurity certificate that refers to assurance level high shall provide assurance that the ICT products, ICT services and services, ICT processes or managed security services for which that certificate is issued meet the corresponding security requirements, including security functionalities, and that they have been evaluated at a level intended to minimise the risk of state-of-the-art cyberattacks carried out by actors with significant skills and resources. The evaluation activities to be undertaken shall include at least the following: a review to demonstrate the absence of publicly known vulnerabilities; testing to demonstrate that the ICT products, ICT services or services, ICT processes or managed security services correctly implement the necessary security functionalities at the state of the art; and an assessment of their resistance to skilled attackers, using penetration testing. Where any such evaluation activities are not appropriate, substitute activities with equivalent effect shall be undertaken. 8. A European cybersecurity certification scheme may specify several evaluation levels depending on the rigour and depth of the evaluation methodology used. Each of the evaluation levels shall correspond to one of the assurance levels and shall be defined by an appropriate combination of assurance components.

MODIFIED +304 −98 Art. 53 Conformity self-assessment

applies from: unchanged

Paragraphs 1 through 3 now add references to managed security services alongside ICT products, ICT services and ICT processes, extending the same wording pattern used for self-assessment, the EU statement of conformity, and the related documentation and submission obligations.

Paragraph 3 also changes the description of the national cybersecurity certification authority referenced in Article 58 from being merely referred to in that Article to being designated pursuant to it.

Cited: Art. 53, v1 · Art. 53, v2

text before / after

32019R088102019R0881-20250204

Article 53 Conformity self-assessment 1. A European cybersecurity certification scheme may allow for the conformity self-assessment under the sole responsibility of the manufacturer or provider of ICT products, ICT services services, ICT processes or ICT processes. managed security services. Conformity self-assessment shall be permitted only in relation to ICT products, ICT services and services, ICT processes or managed security services that present a low risk corresponding to assurance level basic. 2. The manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services may issue an EU statement of conformity stating that the fulfilment of the requirements set out in the scheme has been demonstrated. By issuing such a statement, the manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services shall assume responsibility for the compliance of the ICT product, ICT service or service, ICT process or managed security service with the requirements set out in that scheme. 3. The manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services shall make the EU statement of conformity, technical documentation, and all other relevant information relating to the conformity of the ICT products products, ICT services, ICT processes or ICT managed security services with the scheme available to the national cybersecurity certification authority referred designated pursuant to in Article 58 for the period provided for in the corresponding European cybersecurity certification scheme. A copy of the EU statement of conformity shall be submitted to the national cybersecurity certification authority and to ENISA. 4. The issuing of an EU statement of conformity is voluntary, unless otherwise specified in Union law or Member State law. 5. EU statements of conformity shall be recognised in all Member States.

MODIFIED +236 −87 Art. 54 Elements of European cybersecurity certification schemes

applies from: unchanged

Points (a), (j), (l), (o) and (q) of Article 54(1) now add managed security services alongside ICT products, ICT services and ICT processes as items covered by the listed elements of a scheme.

Point (g) now refers to the applicable security objectives referred to in Articles 51 and 51a, rather than only the security objectives referred to in Article 51.

Cited: Art. 54, v2 · Art. 54, v1

text before / after

32019R088102019R0881-20250204

Article 54 Elements of European cybersecurity certification schemes 1. A European cybersecurity certification scheme shall include at least the following elements: (a) the subject matter and scope of the certification scheme, including the type or categories of ICT products, ICT services and services, ICT processes or managed security services covered; (b) a clear description of the purpose of the scheme and of how the selected standards, evaluation methods and assurance levels correspond to the needs of the intended users of the scheme; (c) references to the international, European or national standards applied in the evaluation or, where such standards are not available or appropriate, to technical specifications that meet the requirements set out in Annex II to Regulation (EU) No 1025/2012 or, if such specifications are not available, to technical specifications or other cybersecurity requirements defined in the European cybersecurity certification scheme; (d) where applicable, one or more assurance levels; (e) an indication of whether conformity self-assessment is permitted under the scheme; (f) where applicable, specific or additional requirements to which conformity assessment bodies are subject in order to guarantee their technical competence to evaluate the cybersecurity requirements; (g) the specific evaluation criteria and methods to be used, including types of evaluation, in order to demonstrate that the applicable security objectives referred to in Article Articles 51 and 51a are achieved; (h) where applicable, the information which is necessary for certification and which is to be supplied or otherwise be made available to the conformity assessment bodies by an applicant; (i) where the scheme provides for marks or labels, the conditions under which such marks or labels may be used; (j) rules for monitoring the compliance of ICT products, ICT services and services, ICT processes or managed security services with the requirements of the European cybersecurity certificates or the EU statements of conformity, including mechanisms to demonstrate continued compliance with the specified cybersecurity requirements; (k) where applicable, the conditions for issuing, maintaining, continuing and renewing the European cybersecurity certificates, as well as the conditions for extending or reducing the scope of certification; (l) rules concerning the consequences for ICT products, ICT services and services, ICT processes or managed security services that have been certified or for which an EU statement of conformity has been issued, but which do not comply with the requirements of the scheme; (m) rules concerning how previously undetected cybersecurity vulnerabilities in ICT products, ICT services and ICT processes are to be reported and dealt with; (n) where applicable, rules concerning the retention of records by conformity assessment bodies; (o) the identification of national or international cybersecurity certification schemes covering the same type or categories of ICT products, ICT services and services, ICT processes, processes or managed security services, security requirements, evaluation criteria and methods, and assurance levels; (p) the content and the format of the European cybersecurity certificates and the EU statements of conformity to be issued; (q) the period of the availability of the EU statement of conformity, technical documentation, and all other relevant information to be made available by the manufacturer or provider of ICT products, ICT services services, ICT processes or ICT processes; managed security services; (r) maximum period of validity of European cybersecurity certificates issued under the scheme; (s) disclosure policy for European cybersecurity certificates issued, amended or withdrawn under the scheme; (t) conditions for the mutual recognition of certification schemes with third countries; (u) where applicable, rules concerning any peer assessment mechanism established by the scheme for the authorities or bodies issuing European cybersecurity certificates for assurance level high pursuant to Article 56(6). Such mechanism shall be without prejudice to the peer review provided for in Article 59; (v) format and procedures to be followed by manufacturers or providers of ICT products, ICT services or ICT processes in supplying and updating the supplementary cybersecurity information in accordance with Article 55. 2. The specified requirements of the European cybersecurity certification scheme shall be consistent with any applicable legal requirements, in particular requirements emanating from harmonised Union law. 3. Where a specific Union legal act so provides, a certificate or an EU statement of conformity issued under a European cybersecurity certification scheme may be used to demonstrate the presumption of conformity with requirements of that legal act. 4. In the absence of harmonised Union law, Member State law may also provide that a European cybersecurity certification scheme may be used for establishing the presumption of conformity with legal requirements.

MODIFIED +432 −127 Art. 56 Cybersecurity certification

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-02-04

The provision now adds managed security services alongside ICT products, ICT services and ICT processes throughout paragraphs 1, 3, 7 and 8, including in the list of items eligible for certification, subject to Commission assessment, submitted for certification, and covered by vulnerability-reporting obligations.

Paragraph 3 also inserts a specific date, 4 February 2025, tied to the inclusion of managed security services in the Commission's mandatory-certification assessment, and paragraph 3(d) now refers to the specific interests and needs of SMEs including microenterprises rather than simply SMEs.

Paragraph 7 also changes the reference to the national cybersecurity certification authority from one 'referred to' in Article 58 to one 'designated' pursuant to Article 58, compared with the earlier wording.

Cited: Art. 56, v2 · Art. 56, v1

text before / after

32019R088102019R0881-20250204

Article 56 Cybersecurity certification 1. ICT products, ICT services and services, ICT processes and managed security services that have been certified under a European cybersecurity certification scheme adopted pursuant to Article 49 shall be presumed to comply with the requirements of such scheme. 2. The cybersecurity certification shall be voluntary, unless otherwise specified by Union law or Member State law. 3. The Commission shall regularly assess the efficiency and use of the adopted European cybersecurity certification schemes and whether a specific European cybersecurity certification scheme is to be made mandatory through relevant Union law to ensure an adequate level of cybersecurity of ICT products, ICT services and services, ICT processes and, from 4 February 2025, managed security services in the Union and improve the functioning of the internal market. The first such assessment shall be carried out by 31 December 2023, and subsequent assessments shall be carried out at least every two years thereafter. Based on the outcome of those assessments, the Commission shall identify the ICT products, ICT services and services, ICT processes and managed security services covered by an existing certification scheme which are to be covered by a mandatory certification scheme. As a priority, the Commission shall focus on the sectors listed in Annex II to Directive (EU) 2016/1148, which shall be assessed at the latest two years after the adoption of the first European cybersecurity certification scheme. When preparing the assessment the Commission shall: (a) take into account the impact of the measures on the manufacturers or providers of such ICT products, ICT services or services, ICT processes or managed security services and on the users in terms of the cost of those measures and the societal or economic benefits stemming from the anticipated enhanced level of security for the targeted ICT products, ICT services services, ICT processes or ICT processes; managed security services; (b) take into account the existence and implementation of relevant Member State and third country law; (c) carry out an open, transparent and inclusive consultation process with all relevant stakeholders and Member States; (d) take into account any implementation deadlines, transitional measures and periods, in particular with regard to the possible impact of the measure on the manufacturers or providers of ICT products, ICT services services, ICT processes or ICT processes, managed security services, including SMEs; the specific interests and needs of SMEs, including microenterprises; (e) propose the most speedy and efficient way in which the transition from a voluntary to mandatory certification schemes is to be implemented. 4. The conformity assessment bodies referred to in Article 60 shall issue European cybersecurity certificates pursuant to this Article referring to assurance level basic or substantial on the basis of criteria included in the European cybersecurity certification scheme adopted by the Commission pursuant to Article 49. 5. By way of derogation from paragraph 4, in duly justified cases a European cybersecurity certification scheme may provide that European cybersecurity certificates resulting from that scheme are to be issued only by a public body. Such body shall be one of the following: (a) a national cybersecurity certification authority as referred to in Article 58(1); or (b) a public body that is accredited as a conformity assessment body pursuant to Article 60(1). 6. Where a European cybersecurity certification scheme adopted pursuant to Article 49 requires an assurance level high, the European cybersecurity certificate under that scheme is to be issued only by a national cybersecurity certification authority or, in the following cases, by a conformity assessment body: (a) upon prior approval by the national cybersecurity certification authority for each individual European cybersecurity certificate issued by a conformity assessment body; or (b) on the basis of a general delegation of the task of issuing such European cybersecurity certificates to a conformity assessment body by the national cybersecurity certification authority. 7. The natural or legal person who submits ICT products, ICT services or services, ICT processes or managed security services for certification shall make available to the national cybersecurity certification authority referred designated pursuant to in Article 58, where that authority is the body issuing the European cybersecurity certificate, or to the conformity assessment body referred to in Article 60 all information necessary to conduct the certification. 8. The holder of a European cybersecurity certificate shall inform the authority or body referred to in paragraph 7 of any subsequently detected vulnerabilities or irregularities concerning the security of the certified ICT product, ICT service or service, ICT process or managed security service that may have an impact on its compliance with the requirements related to the certification. That authority or body shall forward that information without undue delay to the national cybersecurity certification authority concerned. 9. A European cybersecurity certificate shall be issued for the period provided for in the European cybersecurity certification scheme and may be renewed, provided that the relevant requirements continue to be met. 10. A European cybersecurity certificate issued pursuant to this Article shall be recognised in all Member States.

MODIFIED +114 −36 Art. 57 National cybersecurity certification schemes and certificates

applies from: unchanged

Paragraph 1 now adds managed security services alongside ICT products, ICT services and ICT processes when describing what national schemes and related procedures cover, both for those ceasing to produce effects and those continuing to exist.

Paragraph 2 likewise now includes managed security services among the categories for which Member States shall not introduce new national cybersecurity certification schemes already covered by an in-force European scheme.

Cited: Art. 57, v2

text before / after

32019R088102019R0881-20250204

Article 57 National cybersecurity certification schemes and certificates 1. Without prejudice to paragraph 3 of this Article, national cybersecurity certification schemes, and the related procedures for the ICT products, ICT services and services, ICT processes and managed security services that are covered by a European cybersecurity certification scheme shall cease to produce effects from the date established in the implementing act adopted pursuant to Article 49(7). National cybersecurity certification schemes and the related procedures for the ICT products, ICT services and services, ICT processes and managed security services that are not covered by a European cybersecurity certification scheme shall continue to exist. 2. Member States shall not introduce new national cybersecurity certification schemes for ICT products, ICT services and services, ICT processes and managed security services already covered by a European cybersecurity certification scheme that is in force. 3. Existing certificates that were issued under national cybersecurity certification schemes and are covered by a European cybersecurity certification scheme shall remain valid until their expiry date. 4. With a view to avoiding the fragmentation of the internal market, Member States shall inform the Commission and the ECCG of any intention to draw up new national cybersecurity certification schemes.

MODIFIED +179 −77 Art. 58 National cybersecurity certification authorities

applies from: unchanged

In paragraph 7, points (a), (b) and (h) now add managed security services alongside ICT products, ICT services and ICT processes as subjects of supervision, enforcement and cooperation, and point (a) also renumbers its cross-reference to Article 54(1), point (j).

Paragraph 9 likewise now includes managed security services among the matters on which authorities exchange information, experience and good practices, alongside ICT products, ICT services and ICT processes.

These additions of managed security services do not appear in the earlier text of Article 58.

Cited: Art. 58, v2 · Art. 58, v1

text before / after

32019R088102019R0881-20250204

Article 58 National cybersecurity certification authorities 1. Each Member State shall designate one or more national cybersecurity certification authorities in its territory or, with the agreement of another Member State, shall designate one or more national cybersecurity certification authorities established in that other Member State to be responsible for the supervisory tasks in the designating Member State. 2. Each Member State shall inform the Commission of the identity of the designated national cybersecurity certification authorities. Where a Member State designates more than one authority, it shall also inform the Commission about the tasks assigned to each of those authorities. 3. Without prejudice to point (a) of Article 56(5) and Article 56(6), each national cybersecurity certification authority shall be independent of the entities it supervises in its organisation, funding decisions, legal structure and decision-making. 4. Member States shall ensure that the activities of the national cybersecurity certification authorities that relate to the issuance of European cybersecurity certificates referred to in point (a) of Article 56(5) and in Article 56(6) are strictly separated from their supervisory activities set out in this Article and that those activities are carried out independently from each other. 5. Member States shall ensure that national cybersecurity certification authorities have adequate resources to exercise their powers and to carry out their tasks in an effective and efficient manner. 6. For the effective implementation of this Regulation, it is appropriate that national cybersecurity certification authorities participate in the ECCG in an active, effective, efficient and secure manner. 7. National cybersecurity certification authorities shall: (a) supervise and enforce rules included in European cybersecurity certification schemes pursuant to Article 54(1), point (j) of Article 54(1) (j), for the monitoring of the compliance of ICT products, ICT services and services, ICT processes and managed security services with the requirements of the European cybersecurity certificates that have been issued in their respective territories, in cooperation with other relevant market surveillance authorities; (b) monitor compliance with and enforce the obligations of the manufacturers or providers of ICT products, ICT services or services, ICT processes or managed security services that are established in their respective territories and that carry out conformity self-assessment, and shall, in particular, monitor compliance with and enforce the obligations of such manufacturers or providers set out in Article 53(2) and (3) and in the corresponding European cybersecurity certification scheme; (c) without prejudice to Article 60(3), actively assist and support the national accreditation bodies in the monitoring and supervision of the activities of conformity assessment bodies, for the purposes of this Regulation; (d) monitor and supervise the activities of the public bodies referred to in Article 56(5); (e) where applicable, authorise conformity assessment bodies in accordance with Article 60(3) and restrict, suspend or withdraw existing authorisation where conformity assessment bodies infringe the requirements of this Regulation; (f) handle complaints by natural or legal persons in relation to European cybersecurity certificates issued by national cybersecurity certification authorities or to European cybersecurity certificates issued by conformity assessment bodies in accordance with Article 56(6) or in relation to EU statements of conformity issued under Article 53, and shall investigate the subject matter of such complaints to the extent appropriate, and shall inform the complainant of the progress and the outcome of the investigation within a reasonable period; (g) provide an annual summary report on the activities conducted under points (b), (c) and (d) of this paragraph or under paragraph 8 to ENISA and the ECCG; (h) cooperate with other national cybersecurity certification authorities or other public authorities, including by sharing information on the possible non-compliance of ICT products, ICT services and services, ICT processes or managed security services with the requirements of this Regulation or with the requirements of specific European cybersecurity certification schemes; and (i) monitor relevant developments in the field of cybersecurity certification. 8. Each national cybersecurity certification authority shall have at least the following powers: (a) to request conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity to provide any information it requires for the performance of its tasks; (b) to carry out investigations, in the form of audits, of conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity, for the purpose of verifying their compliance with this Title; (c) to take appropriate measures, in accordance with national law, to ensure that conformity assessment bodies, European cybersecurity certificates’ holders and issuers of EU statements of conformity comply with this Regulation or with a European cybersecurity certification scheme; (d) to obtain access to the premises of any conformity assessment bodies or holders of European cybersecurity certificates, for the purpose of carrying out investigations in accordance with Union or Member State procedural law; (e) to withdraw, in accordance with national law, European cybersecurity certificates issued by the national cybersecurity certification authorities or European cybersecurity certificates issued by conformity assessment bodies in accordance with Article 56(6), where such certificates do not comply with this Regulation or with a European cybersecurity certification scheme; (f) to impose penalties in accordance with national law, as provided for in Article 65, and to require the immediate cessation of infringements of the obligations set out in this Regulation. 9. National cybersecurity certification authorities shall cooperate with each other and with the Commission, in particular, by exchanging information, experience and good practices as regards cybersecurity certification and technical issues concerning the cybersecurity of ICT products, ICT services services, ICT processes and ICT processes. managed security services.

MODIFIED +111 −65 Art. 59 Peer review

applies from: unchanged

Points (b) and (c) of Article 59(3)(1) now add managed security services alongside ICT products, ICT services and ICT processes as subject matter for the supervision and enforcement procedures described.

The internal cross-references in those two points were also reformatted, citing Article 58(7), point (a) and Article 58(7), point (b) instead of point (a) of Article 58(7) and point (b) of Article 58(7).

Cited: Art. 59, v2 · Art. 59, v1

text before / after

32019R088102019R0881-20250204

Article 59 Peer review 1. With a view to achieving equivalent standards throughout the Union in respect of European cybersecurity certificates and EU statements of conformity, national cybersecurity certification authorities shall be subject to peer review. 2. Peer review shall be carried out on the basis of sound and transparent evaluation criteria and procedures, in particular concerning structural, human resource and process requirements, confidentiality and complaints. 3. Peer review shall assess: (a) where applicable, whether the activities of the national cybersecurity certification authorities that relate to the issuance of European cybersecurity certificates referred to in point (a) of Article 56(5) and in Article 56(6) are strictly separated from their supervisory activities set out in Article 58 and whether those activities are carried out independently from each other; (b) the procedures for supervising and enforcing the rules for monitoring the compliance of ICT products, ICT services and services, ICT processes and managed security services with European cybersecurity certificates pursuant to Article 58(7), point (a) of Article 58(7); (a); (c) the procedures for monitoring and enforcing the obligations of manufacturers or providers of ICT products, ICT services or services, ICT processes or managed security services pursuant to Article 58(7), point (b) of Article 58(7); (b); (d) the procedures for monitoring, authorising and supervising the activities of the conformity assessment bodies; (e) where applicable, whether the staff of authorities or bodies that issue certificates for assurance level high pursuant to Article 56(6) have the appropriate expertise. 4. Peer review shall be carried out by at least two national cybersecurity certification authorities of other Member States and the Commission and shall be carried out at least once every five years. ENISA may participate in the peer review. 5. The Commission may adopt implementing acts establishing a plan for peer review which covers a period of at least five years, laying down the criteria concerning the composition of the peer review team, the methodology to be used in peer review, and the schedule, the frequency and other tasks related to it. In adopting those implementing acts, the Commission shall take due account of the views of the ECCG. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 66(2). 6. The outcomes of peer reviews shall be examined by the ECCG, which shall draw up summaries that may be made publicly available and which shall, where necessary, issue guidelines or recommendations on actions or measures to be taken by the entities concerned.

MODIFIED +218 −39 Art. 67 Evaluation and review

applies from: unchanged

Paragraph 2 now adds a reference to the procedures leading to the adoption of European cybersecurity certification schemes and their evidence bases, and extends the list of items whose cybersecurity level is to be adequately ensured to include managed security services alongside ICT products, services and processes.

Paragraph 3 similarly extends the list of items covered by the essential cybersecurity requirements assessment to include managed security services, and changes the destination described as being entered from the Union market to the internal market.

Cited: Art. 67, v2

text before / after

32019R088102019R0881-20250204

Article 67 Evaluation and review 1. By 28 June 2024, and every five years thereafter, the Commission shall evaluate the impact, effectiveness and efficiency of ENISA and of its working practices, the possible need to modify ENISA’s mandate and the financial implications of any such modification. The evaluation shall take into account any feedback provided to ENISA in response to its activities. Where the Commission considers that the continued operation of ENISA is no longer justified in light of the objectives, mandate and tasks assigned to it, the Commission may propose that this Regulation be amended with regard to the provisions related to ENISA. 2. The evaluation shall also assess the impact, effectiveness and efficiency of the provisions of Title III of this Regulation Regulation, including the procedures leading to the adoption of European cybersecurity certification schemes and their evidence bases, with regard to the objectives of ensuring an adequate level of cybersecurity of ICT products, ICT services and services, ICT processes and managed security services in the Union and improving the functioning of the internal market. 3. The evaluation shall assess whether essential cybersecurity requirements for access to the internal market are necessary in order to prevent ICT products, ICT services and services, ICT processes and managed security services which do not meet basic cybersecurity requirements from entering the Union internal market. 4. By 28 June 2024, and every five years thereafter, the Commission shall transmit a report on the evaluation together with its conclusions to the European Parliament, to the Council and to the Management Board. The findings of that report shall be made public.

MODIFIED ±0 Annex

applies from: unknown

Sources disagree — the EU's own amendment metadata found this change; the text comparison finds no difference in the provision's text and the amending act's instructions do not mention it. All are shown; none is overruled.

No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.

text before / after

No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.

Back to top ↑

The full entry, with the citation mapping v1 = 32019R0881, v2 = 02019R0881-20250204, is committed at eu/32019R0881/CHANGELOG.md.