in force 2025-02-04 MODIFIED+625 −22§
Amended by Regulation (EU) 2025/37 32025R0037
applies from: unchanged
Paragraph 1 now lists managed security services alongside ICT products, ICT services and ICT processes as part of the digital single market the framework aims to create.
Paragraph 2 adds a new statement that the framework shall also attest that evaluated managed security services meet specified security requirements protecting the availability, authenticity, integrity and confidentiality of data accessed, processed, stored or transmitted in providing those services, and that the services are provided continuously by staff with sufficient competence, expertise, experience and professional integrity.
The prior text of both paragraphs referred only to ICT products, ICT services and ICT processes, without any mention of managed security services.
Cited: Art. 46, v2 · Art. 46, v1
text before / after
32019R0881 → 02019R0881-20250204
Article 46
European cybersecurity certification framework
1. The European cybersecurity certification framework shall be established in order to improve the conditions for the functioning of the internal market by increasing the level of cybersecurity within the Union and enabling a harmonised approach at Union level to European cybersecurity certification schemes, with a view to creating a digital single market for ICT products, ICT services services, ICT processes and ICT processes. managed security services.
2. The European cybersecurity certification framework shall provide for a mechanism to establish European cybersecurity certification schemes and to attest that the ICT products, ICT services and ICT processes that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the functions or services offered by, or accessible via, those products, services and processes throughout their life cycle.In addition, it shall attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity and confidentiality of data which are accessed, processed, stored or transmitted in relation to the provision of those services, and that those services are provided continuously with the requisite competence, expertise and experience by staff with a sufficient and appropriate level of relevant technical knowledge and professional integrity.