June 26, 2019

The European Cybersecurity Act is entering into force on June 27, 2019, thus setting the new mandate of ENISA, which is the EU Agency for Cybersecurity, and establishing the European cybersecurity certification framework. The European cybersecurity certification framework, the first of its kind, establishes the governance and rules for EU-wide certification of information communications technology (ICT) products, processes, and services.

The EU Cybersecurity Act gives ENISA, the EU Agency for Cybersecurity, more tasks and resources to assist EU member states in dealing with cyber-attacks. ENISA will improve the cybersecurity preparedness and resilience in EU, contributing to better information-sharing between EU member states through the network of Computer Security Incident Response Teams (CSIRTs) and by organizing regular pan-European cybersecurity exercises. 

Additionally, the Cybersecurity Act introduces for the first time EU-wide rules for cybersecurity certification. Companies in EU will benefit from having to certify their products, processes, and services only once and see their certificates recognized across EU. Under the framework, multiple schemes will be created for different categories of ICT products, processes, and services. Each scheme will specify, among  others, the type or categories of ICT products, services and processes covered, the purpose, the security standards that shall be met, and the evaluation methods.  The schemes will also indicate the period of validity for the certificates issued. ENISA, on request from EC or the European Cybersecurity Certification Group (composed by member states), will prepare the certification schemes that will then be adopted by EC through implementing acts. 

Regarding the certification framework, EC will prepare the first requests for ENISA to develop certification schemes and set-up the governance structure with the establishment of the relevant expert groups:

  • The European Cybersecurity Certification Group, comprising representatives from member states that will have to appoint the representatives from their competent authorities 
  • The Stakeholder Cybersecurity Certification Group, which will be responsible to advise ENISA and EC

 

Related Links

Keywords: Europe, EU, Banking, Insurance, Securities, Cybersecurity Act, ENISA, Cyber Risk, Cybersecurity Certification, Cyber Resilience, EC

Related Articles
News

US Agencies Consult on Capital Treatment of Land Development Loans

US Agencies (FDIC, FED, and OCC) issued a proposed rule on the treatment of loans that finance the development of land for purposes of the one- to four-family residential properties exclusion in the definition of high volatility commercial real estate (HVCRE) exposure in the regulatory capital rule.

July 12, 2019 WebPage Regulatory News
News

EBA Single Rulebook Q&A: Second Update for July 2019

Under the Single Rulebook question and answer (Q&A) updates for this week, EBA published answers to five questions related to supervisory reporting.

July 12, 2019 WebPage Regulatory News
News

ESMA Updates Manual for European Single Electronic Format in EU

ESMA updated the reporting manual for European Single Electronic Format (ESEF).

July 12, 2019 WebPage Regulatory News
News

FED Updates Supplemental Instructions for Reporting Form FR Y-9C

FED updated the supplemental instructions for FR Y-9C reporting.

July 12, 2019 WebPage Regulatory News
News

EBA Publishes Report on Monitoring Implementation of LCR in EU

EBA published its first report on the monitoring of the implementation of liquidity coverage ratio (LCR) in EU.

July 12, 2019 WebPage Regulatory News
News

APRA Applies Additional Capital Requirements to Three Australian Banks

APRA is applying additional capital requirements to three major banks in Australia to reflect higher operational risk identified in their risk governance self-assessments.

July 11, 2019 WebPage Regulatory News
News

IMF Report on 2019 Article IV Consultation on Euro Area Policies

IMF published its staff report in context of the 2019 Article IV consultation on euro area policies with member countries.

July 11, 2019 WebPage Regulatory News
News

FSB to Survey Practices on Cyber Incident Response and Recovery

FSB launched a survey on the industry practices on cyber incident response and recovery.

July 11, 2019 WebPage Regulatory News
News

ECB Appoints New Members of Supervisory Board

The Governing Council of ECB appointed Edouard Fernandez-Bollo, Kerstin af Jochnick, and Elizabeth McCaul as representatives to the Supervisory Board of ECB Banking Supervision, for a five-year non-renewable term.

July 11, 2019 WebPage Regulatory News
News

OSFI Consults on Applying Proportionality to Pillar 1 Rules in Canada

OSFI published a discussion paper seeks input on possible tailoring of the capital and liquidity requirements for small and medium-size deposit-taking institutions.

July 11, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 3435