emendrix

Art. 57

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

National cybersecurity certification schemes and certificates

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+114 −36

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

Paragraph 1 now adds managed security services alongside ICT products, ICT services and ICT processes when describing what national schemes and related procedures cover, both for those ceasing to produce effects and those continuing to exist.

Paragraph 2 likewise now includes managed security services among the categories for which Member States shall not introduce new national cybersecurity certification schemes already covered by an in-force European scheme.

Cited: Art. 57, v2

text before / after

32019R088102019R0881-20250204

Article 57 National cybersecurity certification schemes and certificates 1. Without prejudice to paragraph 3 of this Article, national cybersecurity certification schemes, and the related procedures for the ICT products, ICT services and services, ICT processes and managed security services that are covered by a European cybersecurity certification scheme shall cease to produce effects from the date established in the implementing act adopted pursuant to Article 49(7). National cybersecurity certification schemes and the related procedures for the ICT products, ICT services and services, ICT processes and managed security services that are not covered by a European cybersecurity certification scheme shall continue to exist. 2. Member States shall not introduce new national cybersecurity certification schemes for ICT products, ICT services and services, ICT processes and managed security services already covered by a European cybersecurity certification scheme that is in force. 3. Existing certificates that were issued under national cybersecurity certification schemes and are covered by a European cybersecurity certification scheme shall remain valid until their expiry date. 4. With a view to avoiding the fragmentation of the internal market, Member States shall inform the Commission and the ECCG of any intention to draw up new national cybersecurity certification schemes.