• About Us
  • Our Practice Areas
    • Banking & Financial Services
    • Competition & Antitrust
    • Digital & Tech
    • EU & International
    • Food & Drink
    • Green Transition
    • Healthcare, Life Sciences & Wellbeing
    • Trade & Investment (including EU-UK)
    • Transport, Travel & Logistics
  • Our Team
    • FIPRA International
    • Special Advisors
  • FIPRA Network
  • Latest News
  • Events
  • Careers
Skip to content

FIPRA

Search for:
Analysis

Connected but vulnerable: the EU’s plans to ramp-up cybersecurity standards 

Friday, 28 October 2022
Connected but vulnerable: the EU’s plans to ramp-up cybersecurity standards 

The upcoming International Internet Day celebrates one of the most important inventions in human history. On October 29th 1969, the first ever internet connection was made. Since then, the world has become hard to imagine without it.

It is estimated that 63% of the global population uses the internet1, with a growth user rate of 3.5% per year 2. For many, access to the net has become essential, making life without it seem almost unimaginable. And every year, the way it is used and what we use it for changes.  

Despite the many benefits, this growing exposure to the virtual world has also brought new types of risks. Digital and increasingly non digital products are subject to cyber-attacks. Just last week, a large German retail group’s IT system was hacked in Germany, France and Austria.  

“Indeed, if done right, the Cyber Resilience Act will increase transparency on products’ cybersecurity features across supply chains and will promote cyber-resilience globally”

SOPHIE MARANDON

The Cyber Resilience Act 

The current EU cybersecurity legislative framework does not cover most hardware and software products, especially non-embedded software on the web. As a result, we are unsure of the security of many digital products on the EU market. In 2021 alone, the global cost of cybercrime was EUR 5.5 trillion3.   

To tackle this growing concern, in 2021, Ursula Von der Leyen, President of the European Commission, announced plans to introduce common cybersecurity standards for digital products in the EU. This is a stepping stone in ensuring that the EU’s 2030 digital transformation targets are met.  

The European Commission presented the Cyber Resilience Act in September 2022. This is the first EU-wide legislation imposing cybersecurity standards by-design for networked ‘products with digital elements’ throughout their entire life cycle. Products with digital elements are defined as ‘any software or hardware product and its remote data processing solutions, including software or hardware components to be placed on the market separately’.  

Requirements for networked products 

The act proposes that all these products, with a few exceptions, can only be placed on the EU market if they comply with essential cybersecurity requirements, such as being delivered without known vulnerabilities.  

Moreover, manufacturers, importers and distributors will have to follow certain mandatory procedures. For example, manufacturers will be required to monitor and address vulnerabilities during their products’ entire life cycle.  

If adopted as currently drafted, conformity assessments for products in scope will need to be undertaken by manufacturers or third parties (appointed by national authorities). The act lists a range of products considered ‘critical’ that must undergo third-party conformity assessments to comply, as these products present higher risks. 

The Commission’s proposal will now go through the legislative procedure, during which the European Parliament and Council of the EU, the EU’s co-legislators, will have their say.  

These new rules will serve to address the lack of incentives to produce cyber-secure goods in the EU and in the world. Indeed, if done right, the Cyber Resilience Act will increase transparency on products’ cybersecurity features across supply chains and will promote cyber-resilience globally.  

[1] https://www.statista.com/statistics/617136/digital-population-worldwide/

[2] https://datareportal.com/global-digital-overview

[3] https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act

This is a short summary.  For the full analysis, please email sophie.marandon@fipra.com, stephen.crisp@fipra.com. 

Written by Sophie Marandon, with contributions from Stephen Crisp.

Latest News
  • News
    Gerd Götz joins FIPRA as a Special Advisor on Green Transition
    17 March 2023
  • Analysis
    PFAS: rooting ambitions for a toxic-free environment in a manageable process
    10 March 2023
  • News
    Erwin Dhondt  joins FIPRA as a Special Advisor for Health Security
    22 February 2023
  • Analysis
    EU’s small but vital step to shipping decarbonisation: the maritime ETS 
    9 February 2023
  • Analysis
    European Parliament’s New Year Resolution: build a powerful but child-friendly online gaming industry
    19 January 2023
  • FIPRA in Australia
    FIPRA in Australia
    is known locally as Richardson Coutts
    FIPRA in Australia
  • FIPRA in Austria
    FIPRA in Austria
    is known locally as Mastermind Public Affairs Consulting
    FIPRA in Austria
  • FIPRA in Belgium
    FIPRA in Belgium
    is known locally as Greenlane Public Affair
    FIPRA in Belgium
  • FIPRA in Canada
    FIPRA in Canada
    is known locally as Earnscliffe Strategy Group
    FIPRA in Canada
  • FIPRA in China
    FIPRA in China
    is known locally as Yuan Associates
    FIPRA in China
  • FIPRA in Croatia
    FIPRA in Croatia
    is known locally as Vlahovic Group
    FIPRA in Croatia
  • FIPRA in Czech Republic
    FIPRA in Czech Republic
    is known locally as PAN Solutions
    FIPRA in Czech Republic
  • FIPRA in Denmark
    FIPRA in Denmark
    is known locally as European Advisers
  • FIPRA in Estonia
    FIPRA in Estonia
    is known locally as META Advisory Group
    FIPRA in Estonia
  • FIPRA in France
    FIPRA in France
    is known locally as Cabinet Samman
    FIPRA in France
  • FIPRA in Georgia
    FIPRA in Georgia
    is known locally as BGI Advisory Services Group
    FIPRA in Georgia
  • FIPRA in Germany
    FIPRA in Germany
    is known locally as Miller & Meier Consulting
    FIPRA in Germany
  • FIPRA in Greece
    FIPRA in Greece
    is known locally as One Team S.A
    FIPRA in Greece
  • FIPRA in Hungary
    FIPRA in Hungary
    is known locally as CEC Group
    FIPRA in Hungary
  • FIPRA in India
    FIPRA in India
    is known locally as Chase India
    FIPRA in India
  • FIPRA in Ireland
    FIPRA in Ireland
    is known locally as Vulcan Consulting
    FIPRA in Ireland
  • FIPRA in Italy
    FIPRA in Italy
    is known locally as Telos A&S
    FIPRA in Italy
  • FIPRA in Japan
    FIPRA in Japan
    is known locally as GR Japan
    FIPRA in Japan
  • FIPRA in Korea
    FIPRA in Korea
    is known locally as FIPRA Korea
  • FIPRA in Latvia
    FIPRA in Latvia
    is known locally as Meta Advisory
    FIPRA in Latvia
  • FIPRA in Luxembourg
    FIPRA in Luxembourg
    is known locally as Huggard Consulting Group
    FIPRA in Luxembourg
  • FIPRA in Malta
    FIPRA in Malta
    is known locally as Maritimus Company Limited
    FIPRA in Malta
  • FIPRA in Mexico
    FIPRA in Mexico
    is known locally as InStrag
    FIPRA in Mexico
  • FIPRA in The Netherlands
    FIPRA in The Netherlands
    is known locally as Public Matters
    FIPRA in The Netherlands
  • FIPRA in Norway
    FIPRA in Norway
    is known locally as First House
    FIPRA in Norway
  • FIPRA in Poland
    FIPRA in Poland
    is known locally as CEC Group
    FIPRA in Poland
  • FIPRA in Portugal
    FIPRA in Portugal
    is known locally as Initium
  • FIPRA in Singapore
    FIPRA in Singapore
    is known locally as Landmark Public Affairs
    FIPRA in Singapore
  • FIPRA in Slovakia
    FIPRA in Slovakia
    is known locally as FIPRA Slovakia
  • FIPRA in Slovenia
    FIPRA in Slovenia
    is known locally as MC Public Affairs S.a.r.l.
    FIPRA in Slovenia
  • FIPRA in South Africa
    FIPRA in South Africa
    is known locally as Ethicore Political Lobbying
    FIPRA in South Africa
  • FIPRA in Spain
    FIPRA in Spain
    is known locally as Influence Spain
    FIPRA in Spain
  • FIPRA in Sweden
    FIPRA in Sweden
    is known locally as Hallvarsson & Halvarsson (H&H)
    FIPRA in Sweden
  • FIPRA in Switzerland
    FIPRA in Switzerland
    is known locally as Hirzel.Neef.Schmid.Counselors
    FIPRA in Switzerland
  • FIPRA in Tunisia
    FIPRA in Tunisia
    is known locally as Mediterranean Development Initiative
    FIPRA in Tunisia
  • FIPRA in Turkey
    FIPRA in Turkey
    is known locally as Stamina Public Affairs
    FIPRA in Turkey
  • FIPRA in Turkey
    FIPRA in Turkey
    is known locally as Stamina Public Affairs
  • FIPRA in Ukraine
    FIPRA in Ukraine
    is known locally as Stober Poltavets & Associates
    FIPRA in Ukraine
  • FIPRA in the United Kingdom
    FIPRA in the United Kingdom
    is known locally as Lexington
    FIPRA in the United Kingdom
  • FIPRA in the United States
    FIPRA in the United States
    is known locally as Alpine Group
    FIPRA in the United States
FIPRA Network

FIPRA

© FIPRA 2023.
All rights reserved.

Follow us on Twitter  Find us on LinkedIn

  • Privacy Policy
Explore
  • About Us
  • Our Practice Areas
  • Our Team
  • FIPRA Network
  • Latest News
  • Events
  • Careers
  • FIPRA Tools
  • Contact Us
Practice Areas
  • Banking & Financial Services
  • Competition & Antitrust
  • Digital & Tech
  • EU & International
  • Food & Drink
  • Green Transition
  • Healthcare, Life Sciences & Wellbeing
  • Trade & Investment (including EU-UK)
  • Transport, Travel & Logistics
Contact

info@fipra.com

Brussels Office  map
FIPRA International SRL
Rue de la Loi 227
Brussels 1040
+32 (0)2 613 28 28
Company number: 0733.774.811

London Office  map
FIPRA International Limited
201 Borough High Street
London
SE1 1JA
+44 (0)203 805 7770
Company number: 3936157