2.1
Strengthening the European Union Agency for Network and Information Security
The European Union Agency for Network and Information Security (ENISA) has a key
role to play in strengthening EU cyber resilience and response but is constrained by its current
mandate. The Commission is therefore presenting an ambitious reform proposal, including a
permanent mandate for the agency.15 This will ensure that ENISA can provide support to
Member States, EU institutions and businesses in key areas, including the implementation of
the Directive on the Security of Network and Information Systems16 (the "NIS Directive") and
the proposed cybersecurity certification Framework.
The reformed ENISA will have a strong advisory role on policy development and
implementation, including promoting coherence between sectoral initiatives and the NIS
Directive and helping to set up Information Sharing and Analysis Centres in critical sectors.
ENISA will raise the bar and enhance the European preparedness by organising yearly panEuropean cybersecurity exercises combining response across different levels. It will also
support EU policy development on information and communications technology (ICT)
cybersecurity certification and play an important role in stepping up both operational
cooperation and crisis management across the EU. The agency will also serve as a focal point
for information and knowledge in the cybersecurity community.
A rapid and shared understanding of threats and incidents as they unfold is a prerequisite for
deciding whether joint mitigation or response action supported by the EU is needed. Such
information exchange requires the involvement of all relevant actors – EU bodies and
agencies, as well as Member States – at technical, operational and strategic levels. ENISA, in
cooperation with the relevant bodies at Member State and EU level, notably the network of
Computer security incident response teams17, CERT-EU, Europol and the EU Intelligence and
Situation Centre (INTCEN), will also contribute to EU-level situational awareness. This can
be fed into threat intelligence and policy-making in the context of regular monitoring of the
threat landscape and effective operational cooperation, as well as in response to large-scale
cross-border incidents.
2.2
Towards a Single Cybersecurity Market
The growth of the cybersecurity market in the EU – in terms of products, services and
processes – is held back in a number of ways. A key aspect is the lack of cybersecurity
certification schemes recognised across the EU to build higher standards of resilience into
products and to underpin EU-wide market confidence. The Commission is therefore putting
forward a proposal to set up an EU cybersecurity certification framework.18 The
Framework would lay down the procedure for the creation of EU-wide cybersecurity
certification schemes, covering products, services and/or systems, which adapt the level of
assurance to the use involved (be it critical infrastructures or consumer devices).19 It would
bring clear benefits to businesses by avoiding the need to go through several certification
processes when trading across borders, thereby limiting administrative and financial costs.
The use of schemes developed under this Framework would also help build consumers'
15
16
17
18
19
COM(2017) 477.
Directive 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a
high common level of security of network and information systems across the Union.
As provided for in article 9 of the NIS Directive.
COM(2017) 477.
A level of assurance indicates the degree of rigour of the security assessment and is usually commensurate to
the level of risk associated with this application areas or functions (i.e. higher level of assurance required for
ICT products or services used in high risk application areas or functions).
4