time of shorter technology cycles. For example, this challenge can be met efficiently through greater involvement and accreditation of businesses and integrating them more thoroughly in the certification process. Scalable and delegated processes in accordance with BSI standards will be considered for this purpose. The Federal Government will advocate expanding the European and international agreements for IT security certification based on common criteria for evaluating security (Common Criteria, ISO/IEC 15408 and ISO/IEC 27000) in order to enable greater international recognition of these criteria. In certain areas, labelling IT security features of products and services is still a special challenge. To make the security of IT products and services more transparent for individuals and small and medium-sized businesses, the Federal Government will increase its activities related to IT security quality labels and certificates and will make suitable proposals, especially concerning shared systems for certification and a standardized system of labelling. In future, a single quality label should help prospective buyers tell easily and quickly which IT products and services are designed to be secure and thus help protect data. Such a label is intended to make cyber security easier to understand and achieve. Making digitalization secure Individual consumers and businesses expect government to evaluate and actively influence the changes brought by digitalization. Examples include the E-Health Act (E-Health-Gesetz) and the IT Security Act (IT-Sicherheitsgesetz). We must continue to pursue this approach, paying attention to new technologies, new business models and changing user behaviour as well as new threats and new European and international regulations, such as the EU’s Directive 2016/1148 on security of network and information systems. Requirements for the appropriate distribution of responsibilities and security risks on the Internet, for example by means of security requirements for makers of hard- and software and product liability rules for inadequate IT security, are being considered. The impacts of the use of digital technologies, especially on cyber security, should be taken into account already when drafting federal legislation and regulations. 13

Select target paragraph3