years – potentially quadrupling previous levels – as part of new technological and industrial policies and the recovery agenda32. Cybersecurity must be integrated into all these digital investments, particularly key technologies like Artificial Intelligence (AI), encryption and quantum computing, using incentives, obligations and benchmarks. This can stimulate the growth of the European cybersecurity industry and provide the certainty needed to ease the phasing out of legacy systems. The European Defence Fund (EDF) will support European cyber defence solutions, as part of the European defence technological and industrial base. Cybersecurity is included in external financial instruments to support our partners, notably the Neighbourhood, Development and International Cooperation Instrument. Preventing the misuse of technologies, protecting critical infrastructure and ensuring the integrity of supply chains also enables the EU’s adherence to the UN norms, rules and principles of responsible state behaviour33. 1. RESILIENCE, TECHNOLOGICAL SOVEREIGNTY AND LEADERSHIP The EU’s critical infrastructure and essential services are increasingly interdependent and digitised. All Internet-connected things in the EU, whether automated cars, industrial control systems or home appliances, and the whole supply chains which make them available, need to be secure-by-design, resilient to cyber incidents, and quickly patched when vulnerabilities are discovered. This is fundamental to provide the EU’s private and public sector with the possibility to choose from the most secure infrastructures and services. The upcoming decade is the EU’s opportunity to lead in the development of secure technologies across the whole supply chain. Ensuring resilience and stronger industrial and technology capacities in cybersecurity should mobilise all necessary regulatory, investment and policy instruments. Cybersecurity by design for industrial processes, operations and devices can mitigate risks, potentially reduce costs to companies as well as to wider society, and thereby increase resilience. 1.1 Resilient infrastructure and critical services EU rules on the security of Network and Information Systems (NIS) are at the core of the Single Market for cybersecurity. The Commission proposes to reform these rules under a revised NIS Directive to increase the level of cyber resilience of all relevant sectors, public and private, that perform an important function for the economy and society 34. The review is necessary to reduce inconsistencies across the internal market by aligning scope, security and incident reporting requirements, national supervision and enforcement and the capabilities of competent authorities. A reformed NIS Directive will provide the basis for more specific rules that are also necessary for strategically important sectors, including energy, transport and health. In order to ensure a consistent approach as announced under the Security Union Strategy 2020-2025, 32 Investments in the whole digital technology supply chain, contributing to the digital transition or to addressing the challenges resulting from it, should amount to at least 20% - equivalent to €134.5 billion - of the €672.5 billion Recovery and Resilience Facility, consisting of grants and loans. EU funding in the 2021-2027 Multiannual Financial Framework envisaged for cybersecurity under the Digital Europe Programme, and for cybersecurity research under Horizon Europe, with special focus on support for SMEs, could amount to €2 billion overall, plus Member States and industry investment. 33 https://undocs.org/A/70/174 34 [insert reference to NIS proposal ] 5

Select target paragraph3