o o o o 6 products and services. In the short term, the government will advocate the adoption of mandatory certification for specific product groups. That is, for products where the risk is greatest or products that have many problems in practice. In the long term, there must be a gradual expansion of mandatory certification or compliance with a CE mark for all internet-connected products should be implemented. In addition, the Netherlands will encourage the adoption of international standards, partnerships and frameworks. The Netherlands wants to proactively join relevant European and global standardisation and certification initiatives through the NEN standardisation platform. The Netherlands is also going pursue multilateral cooperation on standardisation for the Internet of Things, amongst others through the Global Forum on Cyber Expertise (GFCE). Together with public and private parties, the government will develop a monitoring system with information about the digital security of digital products, with specific attention to Internet of Things devices. The government will include international experiences in this. The government will enter into discussions with internet access providers about how they will contribute to combating insecure Internet of Things devices – analogues to the successful approach to botnets. Product testing is crucial to gain assurances on the digital security of devices. Based on use cases from various sectors, a pilot will be launched to gain knowledge and understanding on what a shared testing platform can offer. The development and commercialisation of innovative solutions can make an important contribution to making hardware and software digitally secure. Through the National Cyber Security Research Agenda III (NCSRA III), which is due to be published in 2018, the Netherlands will pursue the development of cybersecurity research aimed at the development and commercialisation of innovative solutions. In addition, various research tenders that o o o SBIR benut de creativiteit van ondernemers om maatschappelijke problemen op te lossen en daagt ondernemers uit om nieuwe producten te ontwikkelen en op de markt te brengen, zie https://www.rvo.nl/subsidies-regelingen/sbir. 7 o contribute to new, innovative, digitally secure hardware and software are ongoing as a result of application of the Small Business Innovation Research (SBIR)6. Furthermore, the government encourages open-source encryption by making additional resources available for this within the framework of NCSRA III. Finally, the government will organise dialogue sessions on innovative solutions to keep hardware and software secure or whether some solutions should be discontinued. This also refers to objectives under Ambition 5. Liability is an important financial incentive for suppliers to make and keep their hardware and software secure. The government is discussing focus areas, areas of improvement and potential solutions for liability with regard to digitally insecure hardware and software with stakeholders and academics. In addition, the Netherlands is actively participating in the liability and new technologies experts group and involves the contribution of Dutch stakeholders in this process. Furthermore, in the negotiations on the Proposal for a Directive on Digital Content and Digital Services, the Netherlands proposes to include an obligation to make security updates mandatory in all cases involving software supplied to a consumer. Setting minimum security requirements can keep insecure products off the market. The government will investigate which minimum requirements could be set for devices through the European Radio Equipment Directive.7 The government will investigate what additional measures are needed and desirable for the digital security of hardware and software when procured by central government. Supervision and enforcement encourages suppliers to comply with laws and regulations. The government will organise a national dialogue session for supervisory bodies to see what role they can play in the near future to promote the digital security of hardware and software, to create synergy between the various activities of the supervisory bodies and to examine how cooperation between supervisory bodies can be improved. Kamerstuk 26643, nr. 467 en Kamerstuk 24095, nr. 415. 28 | National Cyber Security Agenda A cyber secure Netherlands

Select target paragraph3