SAFER CYBERSPACE ●
network, excluding those already governed by
other EU regulations, such as medical devices,
aviation products and vehicles. Products must
carry a CE marking, which certifies compliance
with the regulation and with safety, health and
environmental protection standards. This helps
consumers identify secure products and protects both individuals and businesses from
insecure digital products.
Unlike NIS2, the CRA has a longer implementation timeline, with a deadline set for December
2027. The European Commission must first
establish general standards (Type A) in collaboration with member states, followed by standards for more than 20 product categories (Type
C). Companies that wish to conduct self-assessments for compliance must adhere to their category’s Type C standards. If everything proceeds
as planned, the main standards will be ready by
autumn 2026.
CYBER SOLIDARITY ACT
In December 2024, member states adopted the
Cyber Solidarity Act to enhance the EU’s capacities to detect, prepare for and respond to significant and large-scale cybersecurity threats
that affect more than two member states.
The regulation, unveiled in January 2025,
includes three key measures: a European cybersecurity alert system for real-time threat detection and response, a cybersecurity emergency
mechanism to improve preparedness and
response capabilities for large-scale cyber incidents, and a cybersecurity incident review mechanism for analysing major cyber incidents and
CYBER SECURITY IN ESTONIA 2025
providing recommendations to strengthen EU
cybersecurity.
Last year also saw the adoption of two additional cybersecurity regulations: amendments
to the Cybersecurity Act (CSA+), which addresses managed security services, and a regulation
setting cybersecurity requirements for crossborder electricity flows.
WHAT TO EXPECT IN 2025
Significant progress was made in cybersecurity
regulation last year. In 2025, the EU will begin
revising the Cybersecurity Act, which governs
the role of the EU agency in charge of cyber
security (ENISA) and the EU cybersecurity certification framework. The five-year-old regulation needs updating to reflect ENISA’s evolving
responsibilities and to improve certification
processes in the cybersecurity sector.
The EU will also update its framework for
responding to cyber incidents and crises, which
was originally developed in 2017. The world has
changed significantly since then, and greater
focus is needed on preparedness and resilience.
The European Commission has started the year
actively, unveiling a proposal on 15 January for
improving cyber security in the healthcare sector.
While some critics argue that the EU’s cybersecurity efforts remain insufficient, most
experts advocate for a regulatory pause to allow
for the effective implementation of existing
measures. Now, the EU and its member states,
including Estonia, must focus on enforcing regulations and supporting stakeholders in meeting the new requirements. ●
51