confidence, with a certificate of conformity to inform and reassure purchasers and users about
the security properties of the products and services they buy and use. This would make high
standards for cybersecurity a source of competitive advantage. The result would build
increased resilience as ICT products and services would be formally evaluated against a
defined set of cybersecurity standards, which could be developed in close connection with the
broader ongoing work on ICT standards.20
The Framework's schemes would be voluntary and would not create any immediate regulatory
obligations on vendors or service providers. The schemes would not contradict any applicable
legal requirements, such as the EU legislation on data protection.
Once the Framework is established, the Commission will invite the relevant stakeholders to
focus on three priority areas:
Security in critical or high-risk applications21: systems that we depend on in our daily
activities, from our cars to the machinery in factories, from the largest of systems such as
airplanes or power plants to the smallest such as medical devices, are becoming
increasingly digital and interconnected. Therefore, core ICT components in such products
and systems would require rigorous security assessments.
Cybersecurity in widely-deployed digital products, networks, systems and services used
by private and public sector alike to defend against attacks and apply regulatory
obligations22 – such as email encryption, firewalls and Virtual Private Networks; it is
critical that the spreading use of such tools does not lead to new sources of risk or new
vulnerabilities.
The use of "security by design" methods in low-cost, digital, interconnected mass
consumer devices which make up the Internet of Things: schemes under the framework
could be used to signal that the products are built using state of the art secure development
methods, that they have undergone adequate security testing, and that the vendors have
committed to update their software in the event of newly discovered vulnerabilities or
threats.
These priorities should take particular account of the evolving cybersecurity threat landscape,
as well as the importance of essential services such as transport, energy, health care, banking,
financial market infrastructures, drinking water or digital infrastructure.23
While no ICT product, system or service can be guaranteed to be "100 %" secure, there are
several well-known and well-documented defects in the design of ICT products that can be
exploited for attacks. A "security by design" approach adopted by producers of connected
devices, IT software and equipment would ensure that cybersecurity is addressed before
putting new products on the market. This could be part of the "duty of care" principle, to be
further developed together with the industry, which could reduce product/software
vulnerabilities by applying a range of methods from design to testing and verification,
including formal verification where applicable, long term maintenance, and the use of secure
20
21
22
23
COM(2016) 176.
The exception would be where mandatory or voluntary certification is governed by other Union acts.
For example Directive (EU) 2016/1148, Regulation (EU) 2016/679, Directive (EU) 2015/2366 and other
proposed pieces of legislation such as the European Electronic Communications Code, each require that
organisations put in place appropriate security measures to address relevant cybersecurity risks.
The sectors within the scope of Directive 2016/1148 of the European Parliament and of the Council of 6 July
2016 concerning measures for a high common level of security of network and information systems across
the Union.
5