(EU) No. 1025/2012 of the European Parliament and of the Council of 25 October 2012 on
European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and
Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC,
2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing
Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of
the Council (OJ 2012 L 316, p. 12).
Article 3. Cyber Security Principles
1. Cyber security is based on the following key cyber security principles:
1) non-discrimination of cyber space, which means that the provisions of legislation are
applied and benefits are stored both in physical and cyber space equally;
2) management of cyber security risk, which means that the applicable cybersecurity
measures must ensure that regularly assessed risks of cyber security entities are captured;
3) proportionality of cyber security, which means that legal, organisational and technical
cyber security measures, which are applied, shall not restrict the activities of cyber security
entities in cyber space more than required;
4) supremacy of public interest, which means that the applicable cyber security measures
shall first guarantee the protection of public interest, however, shall not, in principle, infringe on
consumer rights or limit their freedom in cyber space proportionally;
5) standardisation and technological neutrality, which means that when implementing
cyber security measures, cyber security entities shall be encouraged to follow the national, the
EU and other international communications and information systems’ cyber security standards
and specification, without demanding to apply any specific type of technology and without
giving it the priority;
6) subsidiarity, which means that cyber security entities, which operate information
systems and use them for the provision of services, are responsible for cyber security of
information systems as well as for services which are provided using such systems. In the areas
which fall within the exclusive competence of cyber security entities, the authorities which
develop and implement cyber security policy shall take measures solely when cyber security of
the communications and information systems and services provided using such systems cannot
be ensured by cyber security entities which manage such systems and use them for the provision
of services.
2. When applying legal provisions which regulate cyber security, consideration shall be
taken of the principles set forth in Article 3(1). These principles shall be inter-aligned and
coordinated; neither of them shall be given priority or prevalence.