be seen as a strong argument to invest in the EU, thereby helping to achieve the ambitious
goals of the Digital Single Market to create growth and jobs.
A strong commitment is needed to achieve the above, notably through:
i) Stepping up cooperation to enhance preparedness and deal with cyber incidents
Existing and agreed cooperation mechanisms need to be strengthened to increase the EU’s
resilience and preparedness, including for a possible pan-European cybersecurity crisis. These
cooperation mechanisms should be comprehensive, spanning the life cycle of an incident from
prevention to prosecution. Effective cooperation among Member States and practical
implementation of security requirements for critical operators will also demand robust
technical solutions from the cybersecurity industry.
At the same time, ensuring resilience of critical cyber assets throughout the EU will require
continuous efforts to find cross-sectoral synergies and to mainstream cyber requirements in all
relevant EU policies. The Commission will consider the need to update the 2013 EU
Cybersecurity Strategy in the near future.
ii) Addressing challenges facing Europe’s cybersecurity Single Market
The Digital Single Market (DSM) strategy7 recognised that specific gaps still exist in the fastmoving area of technologies and solutions for online network security. At the same time,
market studies show that the EU internal market is still geographically fragmented as far as
supply of cybersecurity products and services is concerned8. This Communication sets out a
number of market-oriented policy measures to address these Single Market gaps and
challenges.
iii) Nurturing industrial capabilities in the field of cybersecurity
In the EU Cybersecurity Strategy and in the DSM strategy, the Commission committed to
promote increased supply of products and services by the EU cybersecurity industry.
Consequently, the Commission is also adopting a decision paving the way to a contractual
arrangement on Public Private Partnership (cPPP) on cybersecurity, which will seek to
advance a cutting-edge European cybersecurity research and innovation agenda for increased
competitiveness.
2. TAKING COOPERATION, KNOWLEDGE AND CAPACITY TO THE NEXT LEVEL
The EU Cybersecurity Strategy and in particular the forthcoming NIS Directive9 will pave the
way towards improved EU-level cooperation across Member States. The swift and effective
implementation of the Directive will be key in view of the increasing digitalisation of
economic and societal life (also taking into account the cloud, the Internet of things, and
machine-to-machine communication), growing cross-border interconnection and the fast7
COM(2015) 192.
See SWD(2016) 216.
9
The NIS Directive will require Member States to identify a range of operators of essential services in fields such as energy, transport,
finance and health, to address cybersecurity risks, and also to ensure that certain digital service providers take appropriate measures to
address such risks.
8
3