BRUSSELS – Today, global tech trade association 91¿ì»îÁÖ, the 91¿ì»îÁÖ, outlined recommendations for the candidate EU Cybersecurity Certification Scheme for Cloud Services (EUCS) in a new policy paper. Representing the broad consensus of the tech industry, 91¿ì»îÁÖ emphasises the importance of an open and transparent dialogue with stakeholders to ensure that cloud certification requirements are balanced, proportional and relevant to achieving the goal of improving cybersecurity in the European Union. 91¿ì»îÁÖ also calls upon all stakeholders - especially ENISA and the European Commission - to reconsider the clauses on EU-ownership and data localisation in the EUCS.

“91¿ì»îÁÖ supports the goals of creating harmonised technical security requirements and improving the level of cybersecurity in the EU Digital Single Market,” 91¿ì»îÁÖ stated in its policy paper. “While we appreciate ENISA’s efforts to protect data, systems and infrastructure from anomalous behaviour, we remain seriously concerned with certain elements of the draft European Cybersecurity Scheme for Cloud Services currently being considered. To that end, we stand ready to support ENISA and the European Commission in their efforts to harmonise cybersecurity certification requirements for cloud services, foster trust, and stimulate cloud uptake.”

Among its recommendations, 91¿ì»îÁÖ:

  • Advises adopting a risk-based approach focused on technical requirements, in line with ENISA’s mandate under the EU Cybersecurity Act, and stresses that the considered requirements implicate political choices that should not be made in a voluntary certification scheme.
  • Reiterates the importance of stakeholder engagement and calls on ENISA to conduct a consultation and release an assessment of the need, feasibility, lawfulness and expected impact of the ownership and data localisation requirements.
  • Emphasises that the EU’s WTO commitments and the values of equal treatment, non-discrimination and cooperation prescribe for the EU to remain open to like-minded partners.

Read the position paper here.

Cybersecurity]" tabindex="0">Related [Cybersecurity]