BRUSSELS – Global tech trade association 91¿ì»îÁÖ, the 91¿ì»îÁÖ, reacted to the European Commission’s revision of the Cybersecurity Act (CSA), underlining that despite important steps toward harmonization and improvement in certification schemes and ENISA’s mandate, it fails to deliver meaningful simplification.

While the proposal reiterates a commitment to streamlining policies, new substantive simplification measures are limited.

“After the missed opportunity of the Digital Omnibus, the Cybersecurity Act falls short of concrete measures to cut compliance burdens and let organizations focus on bolstering security rather than red tape,” said Guido Lobrano, 91¿ì»îÁÖ Director General for Europe.

“The proposal signals intent, but the actual simplification measures are underwhelming,” added Mr. Lobrano.

ITI appreciates efforts to improve the European Cybersecurity Certification Framework (ECCF). Notably, the proposal addresses past challenges by emphasizing a more effective, risk-based approach, and does not contain explicit sovereignty-related constraints. However, despite the clear obligation to consult stakeholders during the certification development process, there are no references to a concrete vehicle to enable that. The 12-month deadline to develop a draft is double-edged: while it might lead to efficiencies, it also risks leading to timelines too compressed to enable meaningful stakeholder engagement.

The expanded ENISA mandate rightly recognizes the crucial role of the Agency for Europe’s cybersecurity and to promote international cooperation. The proposal also explicitly requires ENISA to engage with private sector stakeholders and permits the establishment of public-private partnerships - facilitating the co-development of guidance, certification, and capacity-building initiatives.

Cybersecurity is a cornerstone of tech sovereignty. In the current context, the EU is rightly seeking to strengthen its security and the resilience of the digital supply chain. The introduction of the Trusted ICT supply chain framework in the proposal in principle is in line with 91¿ì»îÁÖ’s recommendations to define clear, objective, and risk-based criteria for assessing “trusted technology providers” – and if implemented correctly, is likely to lead to further clarity in this respect. Where non-technical criteria are considered to determine trusted technology providers, they must be narrowly defined, proportionate, and complemented by a technical risk-based security approach.

Cybersecurity]" tabindex="0">Related [Cybersecurity]