emendrix

Art. 46

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

European cybersecurity certification framework

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+625 −22

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

Paragraph 1 now lists managed security services alongside ICT products, ICT services and ICT processes as part of the digital single market the framework aims to create.

Paragraph 2 adds a new statement that the framework shall also attest that evaluated managed security services meet specified security requirements protecting the availability, authenticity, integrity and confidentiality of data accessed, processed, stored or transmitted in providing those services, and that the services are provided continuously by staff with sufficient competence, expertise, experience and professional integrity.

The prior text of both paragraphs referred only to ICT products, ICT services and ICT processes, without any mention of managed security services.

Cited: Art. 46, v2 · Art. 46, v1

text before / after

32019R088102019R0881-20250204

Article 46 European cybersecurity certification framework 1. The European cybersecurity certification framework shall be established in order to improve the conditions for the functioning of the internal market by increasing the level of cybersecurity within the Union and enabling a harmonised approach at Union level to European cybersecurity certification schemes, with a view to creating a digital single market for ICT products, ICT services services, ICT processes and ICT processes. managed security services. 2. The European cybersecurity certification framework shall provide for a mechanism to establish European cybersecurity certification schemes and to attest that the ICT products, ICT services and ICT processes that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the functions or services offered by, or accessible via, those products, services and processes throughout their life cycle.In addition, it shall attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity and confidentiality of data which are accessed, processed, stored or transmitted in relation to the provision of those services, and that those services are provided continuously with the requisite competence, expertise and experience by staff with a sufficient and appropriate level of relevant technical knowledge and professional integrity.