emendrix

Art. 67

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

Evaluation and review

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+218 −39

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

Paragraph 2 now adds a reference to the procedures leading to the adoption of European cybersecurity certification schemes and their evidence bases, and extends the list of items whose cybersecurity level is to be adequately ensured to include managed security services alongside ICT products, services and processes.

Paragraph 3 similarly extends the list of items covered by the essential cybersecurity requirements assessment to include managed security services, and changes the destination described as being entered from the Union market to the internal market.

Cited: Art. 67, v2

text before / after

32019R088102019R0881-20250204

Article 67 Evaluation and review 1. By 28 June 2024, and every five years thereafter, the Commission shall evaluate the impact, effectiveness and efficiency of ENISA and of its working practices, the possible need to modify ENISA’s mandate and the financial implications of any such modification. The evaluation shall take into account any feedback provided to ENISA in response to its activities. Where the Commission considers that the continued operation of ENISA is no longer justified in light of the objectives, mandate and tasks assigned to it, the Commission may propose that this Regulation be amended with regard to the provisions related to ENISA. 2. The evaluation shall also assess the impact, effectiveness and efficiency of the provisions of Title III of this Regulation Regulation, including the procedures leading to the adoption of European cybersecurity certification schemes and their evidence bases, with regard to the objectives of ensuring an adequate level of cybersecurity of ICT products, ICT services and services, ICT processes and managed security services in the Union and improving the functioning of the internal market. 3. The evaluation shall assess whether essential cybersecurity requirements for access to the internal market are necessary in order to prevent ICT products, ICT services and services, ICT processes and managed security services which do not meet basic cybersecurity requirements from entering the Union internal market. 4. By 28 June 2024, and every five years thereafter, the Commission shall transmit a report on the evaluation together with its conclusions to the European Parliament, to the Council and to the Management Board. The findings of that report shall be made public.