SAFER CYBERSPACE ● network, excluding those already governed by other EU regulations, such as medical devices, aviation products and vehicles. Products must carry a CE marking, which certifies compliance with the regulation and with safety, health and environmental protection standards. This helps consumers identify secure products and protects both individuals and businesses from insecure digital products. Unlike NIS2, the CRA has a longer implementation timeline, with a deadline set for December 2027. The European Commission must first establish general standards (Type A) in collaboration with member states, followed by standards for more than 20 product categories (Type C). Companies that wish to conduct self-assessments for compliance must adhere to their category’s Type C standards. If everything proceeds as planned, the main standards will be ready by autumn 2026. CYBER SOLIDARITY ACT In December 2024, member states adopted the Cyber Solidarity Act to enhance the EU’s capacities to detect, prepare for and respond to significant and large-scale cybersecurity threats that affect more than two member states. The regulation, unveiled in January 2025, includes three key measures: a European cybersecurity alert system for real-time threat detection and response, a cybersecurity emergency mechanism to improve preparedness and response capabilities for large-scale cyber incidents, and a cybersecurity incident review mechanism for analysing major cyber incidents and CYBER SECURITY IN ESTONIA 2025 providing recommendations to strengthen EU cybersecurity. Last year also saw the adoption of two additional cybersecurity regulations: amendments to the Cybersecurity Act (CSA+), which addresses managed security services, and a regulation setting cybersecurity requirements for crossborder electricity flows. WHAT TO EXPECT IN 2025 Significant progress was made in cybersecurity regulation last year. In 2025, the EU will begin revising the Cybersecurity Act, which governs the role of the EU agency in charge of cyber security (ENISA) and the EU cybersecurity certification framework. The five-year-old regulation needs updating to reflect ENISA’s evolving responsibilities and to improve certification processes in the cybersecurity sector. The EU will also update its framework for responding to cyber incidents and crises, which was originally developed in 2017. The world has changed significantly since then, and greater focus is needed on preparedness and resilience. The European Commission has started the year actively, unveiling a proposal on 15 January for improving cyber security in the healthcare sector. While some critics argue that the EU’s cybersecurity efforts remain insufficient, most experts advocate for a regulatory pause to allow for the effective implementation of existing measures. Now, the EU and its member states, including Estonia, must focus on enforcing regulations and supporting stakeholders in meeting the new requirements. ● 51

Select target paragraph3