EU Cybersecurity Act | Regulation (EU) 2019/881 β ENISA Mandate & EU Cybersecurity Certification Framework | In Force: 27 June 2019 | Full Legal Effect Across All EU Member States
Directory & Legal Summaries
Title I: General Provisions
-
Art. 1 CSASubject matter and scopeEstablishes the permanent mandate for ENISA (EU Agency for Cybersecurity) and sets up a European cybersecurity certification framework for ICT products, ICT services, and ICT processes.
-
Art. 2 CSADefinitionsDefines core legal and technical statutory terms including 'cybersecurity', 'ICT product', 'ICT service', 'ICT process', 'cyber threat', 'European cybersecurity certification scheme', and 'assurance level'.
Title II: ENISA (European Union Agency for Cybersecurity)
Chapter I: Mandate and Objectives
-
Art. 3 CSAMandate of ENISAGrants ENISA a permanent mandate to achieve a high common level of cybersecurity across the Union, acting as a center of expertise and facilitator of cooperation.
-
Art. 4 CSAObjectives of ENISAOutlines core objectives: assisting Union institutions and Member States in policy development, operational cooperation, capability building, awareness, and certification.
Chapter II: Tasks of ENISA
-
Art. 5 CSADevelopment and implementation of policy and lawTasks ENISA with providing advice, opinions, and analyses regarding EU cybersecurity law and sector-specific policy developments.
-
Art. 6 CSACapacity-buildingRequires ENISA to support Member States in enhancing capabilities, developing national CSIRTs, providing cybersecurity training, and promoting cyber-hygiene.
-
Art. 7 CSAOperational cooperation at Union levelMandates support for operational cooperation within the CSIRTs network, handling cross-border incidents, coordinating large-scale exercises, and managing the secretariat.
-
Art. 8 CSAMarket, certification and standardisationInstructs ENISA to support the European cybersecurity market, analyze market trends, support certification scheme development, and promote standardisation.
-
Art. 9 CSAKnowledge and informationRequires ENISA to perform threat analyses, collect public/voluntary incident information, and maintain a dedicated EU Information Hub portal.
-
Art. 10 CSAAwareness-raising and educationTasks ENISA with raising public awareness of cyber threats, running annual campaigns (e.g., European Cybersecurity Month), and encouraging security-by-design.
-
Art. 11 CSAResearch and innovationRequires ENISA to advise Union institutions on research priorities and needs in cybersecurity and liaise with research entities.
-
Art. 12 CSAInternational cooperationAuthorizes ENISA to engage with third countries and international organisations (e.g., OECD, NATO) to promote common cybersecurity norms and international standards.
Chapter III: Governance of ENISA
-
Art. 14 CSAStructure of ENISAEstablishes the administrative and management structure comprising a Management Board, Executive Board, Executive Director, Advisory Group, and Stakeholder Certification Group.
-
Art. 28 CSAENISA Advisory GroupCreates an advisory body representing private industry, academia, consumer groups, and national data protection authorities to advise on work programs.
-
Art. 29 CSAStakeholder Cybersecurity Certification GroupSets up a dedicated expert group to assist the Commission and ENISA on strategic issues regarding cybersecurity certification.
Title III: Cybersecurity Certification Framework
-
Art. 46 CSAEuropean cybersecurity certification frameworkEstablishes horizontal rules for Union-wide cybersecurity certification schemes to ensure uniform security assurance for ICT products, services, and processes.
-
Art. 47 CSAUnion rolling work programme for certificationRequires the Commission to publish a multi-annual strategic work program identifying priority ICT categories for future certification schemes.
-
Art. 48 CSAPreparation and adoption of candidate schemesOutlines the procedure by which ENISA drafts candidate European cybersecurity certification schemes upon request from the Commission or ECCG.
-
Art. 51 CSASecurity objectives of certification schemesSpecifies functional security targets including data confidentiality, integrity, availability, vulnerability remediation, security updates, and protection against unauthorized access.
-
Art. 52 CSAAssurance levels of certification schemesDefines three evaluation assurance levels for certified ICT assets: 'Basic', 'Substantial', and 'High', based on the rigor of testing and risk level.
-
Art. 53 CSAConformity self-assessmentPermits manufacturers or providers to issue an EU Statement of Conformity under their sole responsibility, restricted strictly to assets designated with assurance level 'Basic'.
-
Art. 54 CSAElements of European cybersecurity certification schemesMandates explicit contents for each adopted scheme: scope, standards reference, evaluation criteria, rules for issuing certificates, and post-market compliance rules.
-
Art. 55 CSANational cybersecurity certification schemes and certificatesEstablishes that EU cybersecurity schemes supersede conflicting national schemes, terminating duplicate national certifications once an EU scheme takes effect.
-
Art. 56 CSANational cybersecurity certification authoritiesRequires each Member State to designate a national authority responsible for supervising compliance, handling complaints, and monitoring certification bodies.
-
Art. 58 CSAConformity assessment bodiesSets accreditation criteria for independent third-party bodies evaluating and issuing certificates for 'Substantial' or 'High' assurance levels.
-
Art. 62 CSAEuropean Cybersecurity Certification Group (ECCG)Establishes the ECCG consisting of national representative authorities to advise the Commission and coordinate overall implementation of the framework.
-
Art. 65 CSAPenaltiesMandates Member States to establish effective, proportionate, and dissuasive penalties for infringements of European certification schemes and obligations.
