☰
ABOUT LES Blog
Services
Legal Services GDPR Compliance Strategic Project Proposals Policy & Research Consultancy HR Policy Advisory Cybersecurity Policy Advisory AI Policy & Regulatory Advisory
Publications
Law in Brief
Cyber Law
Cyber Law
AI Act
EU AI Act
Tools
Contract Review Assistant GDPR Compliance Policy Generator CyberLEX Global Privacy Audit Engine Compliance Handbook Compliance Comparator BizLaunch Tool
Contact

CyberLaw

EU Cybersecurity Act (Regulation EU 2019/881) | Directory – LES & Partners

EU Cybersecurity Act | Regulation (EU) 2019/881 β€” ENISA Mandate & EU Cybersecurity Certification Framework | In Force: 27 June 2019 | Full Legal Effect Across All EU Member States

Directory & Legal Summaries

Title I: General Provisions
  • Art. 1 CSASubject matter and scope
    Establishes the permanent mandate for ENISA (EU Agency for Cybersecurity) and sets up a European cybersecurity certification framework for ICT products, ICT services, and ICT processes.
  • Art. 2 CSADefinitions
    Defines core legal and technical statutory terms including 'cybersecurity', 'ICT product', 'ICT service', 'ICT process', 'cyber threat', 'European cybersecurity certification scheme', and 'assurance level'.
Title II: ENISA (European Union Agency for Cybersecurity)
Chapter I: Mandate and Objectives
  • Art. 3 CSAMandate of ENISA
    Grants ENISA a permanent mandate to achieve a high common level of cybersecurity across the Union, acting as a center of expertise and facilitator of cooperation.
  • Art. 4 CSAObjectives of ENISA
    Outlines core objectives: assisting Union institutions and Member States in policy development, operational cooperation, capability building, awareness, and certification.
Chapter II: Tasks of ENISA
  • Art. 5 CSADevelopment and implementation of policy and law
    Tasks ENISA with providing advice, opinions, and analyses regarding EU cybersecurity law and sector-specific policy developments.
  • Art. 6 CSACapacity-building
    Requires ENISA to support Member States in enhancing capabilities, developing national CSIRTs, providing cybersecurity training, and promoting cyber-hygiene.
  • Art. 7 CSAOperational cooperation at Union level
    Mandates support for operational cooperation within the CSIRTs network, handling cross-border incidents, coordinating large-scale exercises, and managing the secretariat.
  • Art. 8 CSAMarket, certification and standardisation
    Instructs ENISA to support the European cybersecurity market, analyze market trends, support certification scheme development, and promote standardisation.
  • Art. 9 CSAKnowledge and information
    Requires ENISA to perform threat analyses, collect public/voluntary incident information, and maintain a dedicated EU Information Hub portal.
  • Art. 10 CSAAwareness-raising and education
    Tasks ENISA with raising public awareness of cyber threats, running annual campaigns (e.g., European Cybersecurity Month), and encouraging security-by-design.
  • Art. 11 CSAResearch and innovation
    Requires ENISA to advise Union institutions on research priorities and needs in cybersecurity and liaise with research entities.
  • Art. 12 CSAInternational cooperation
    Authorizes ENISA to engage with third countries and international organisations (e.g., OECD, NATO) to promote common cybersecurity norms and international standards.
Chapter III: Governance of ENISA
  • Art. 14 CSAStructure of ENISA
    Establishes the administrative and management structure comprising a Management Board, Executive Board, Executive Director, Advisory Group, and Stakeholder Certification Group.
  • Art. 28 CSAENISA Advisory Group
    Creates an advisory body representing private industry, academia, consumer groups, and national data protection authorities to advise on work programs.
  • Art. 29 CSAStakeholder Cybersecurity Certification Group
    Sets up a dedicated expert group to assist the Commission and ENISA on strategic issues regarding cybersecurity certification.
Title III: Cybersecurity Certification Framework
  • Art. 46 CSAEuropean cybersecurity certification framework
    Establishes horizontal rules for Union-wide cybersecurity certification schemes to ensure uniform security assurance for ICT products, services, and processes.
  • Art. 47 CSAUnion rolling work programme for certification
    Requires the Commission to publish a multi-annual strategic work program identifying priority ICT categories for future certification schemes.
  • Art. 48 CSAPreparation and adoption of candidate schemes
    Outlines the procedure by which ENISA drafts candidate European cybersecurity certification schemes upon request from the Commission or ECCG.
  • Art. 51 CSASecurity objectives of certification schemes
    Specifies functional security targets including data confidentiality, integrity, availability, vulnerability remediation, security updates, and protection against unauthorized access.
  • Art. 52 CSAAssurance levels of certification schemes
    Defines three evaluation assurance levels for certified ICT assets: 'Basic', 'Substantial', and 'High', based on the rigor of testing and risk level.
  • Art. 53 CSAConformity self-assessment
    Permits manufacturers or providers to issue an EU Statement of Conformity under their sole responsibility, restricted strictly to assets designated with assurance level 'Basic'.
  • Art. 54 CSAElements of European cybersecurity certification schemes
    Mandates explicit contents for each adopted scheme: scope, standards reference, evaluation criteria, rules for issuing certificates, and post-market compliance rules.
  • Art. 55 CSANational cybersecurity certification schemes and certificates
    Establishes that EU cybersecurity schemes supersede conflicting national schemes, terminating duplicate national certifications once an EU scheme takes effect.
  • Art. 56 CSANational cybersecurity certification authorities
    Requires each Member State to designate a national authority responsible for supervising compliance, handling complaints, and monitoring certification bodies.
  • Art. 58 CSAConformity assessment bodies
    Sets accreditation criteria for independent third-party bodies evaluating and issuing certificates for 'Substantial' or 'High' assurance levels.
  • Art. 62 CSAEuropean Cybersecurity Certification Group (ECCG)
    Establishes the ECCG consisting of national representative authorities to advise the Commission and coordinate overall implementation of the framework.
  • Art. 65 CSAPenalties
    Mandates Member States to establish effective, proportionate, and dissuasive penalties for infringements of European certification schemes and obligations.

Solverwp- WordPress Theme and Plugin

LES & PARTNERS Footer