“Since 2004” reads the plaque. That’s how long the European Union Agency for Cybersecurity or ENISA has been working to make Europe cyber secure. ENISA’s Heraklion office stands before us. It plays a vital role in the EU’s cybersecurity efforts.
ENISA contributes actively to European cybersecurity policy. It supports EU stakeholders and Member States. This support helps them respond to large-scale cyber incidents. These incidents often affect multiple countries. ENISA’s work ensures the Digital Single Market functions properly.
The European Union Agency for Cybersecurity collaborates closely with the private sector and Member States. Together they improve capabilities and deliver solutions. ENISA offers recommendations and independent advice on cybersecurity. It also helps develop and evaluate National Cybersecurity Strategies.
ENISA’s activities support policy making and implementation. It fosters cooperation and capacity building among CSIRTs. ENISA conducts studies on IoT and smart infrastructures. These studies address data protection issues. They also look at privacy-enhancing technologies. ENISA identifies the cyber threat landscape.
The European Union Agency for Cybersecurity engages in hands-on work. It collaborates directly with operational teams across the EU. ENISA brings together EU communities. It coordinates responses to large-scale cross-border cybersecurity incidents. The agency also draws up cybersecurity certification schemes.
ENISA supports the EU’s policy and law on network and information security. It assists Member States and EU institutions. ENISA helps them implement vulnerability disclosure policies. These policies are implemented on a voluntary basis.
Since 2019 ENISA prepares European cybersecurity certification schemes. These schemes serve as the basis for certifying products. They also certify processes and services. These certifications support the Digital Single Market.
The Cybersecurity Act took effect in June 2019. It strengthens ENISA’s ability. It helps Member States address cybersecurity threats. Businesses can certify their products meet EU standards. Initially, this certification is voluntary. It may become mandatory later.
The Cybersecurity Act has two main goals. First, it strengthens ENISA’s mandate. This allows ENISA to support Member States in tackling cyber threats. Second, it establishes an EU-wide cybersecurity certification framework. ENISA plays a key role in this framework.
Under the new Framework, ENISA coordinates the preparation of cybersecurity certification schemes. These are submitted to the European Commission. The Framework enables the issuance of European cybersecurity certificates. It also issues statements of conformity. These apply to ICT products, services, and processes. They are recognized in all EU Member States.
The European Union Agency for Cybersecurity offers businesses an opportunity. They can certify their products meet EU cybersecurity standards. Certification will be voluntary. EU or Member State law may specify otherwise. The EU Commission regularly assesses whether a scheme should become mandatory.
The certification scheme may specify security assurance levels. These levels include basic, substantial, or high. For the basic level, manufacturers can assess conformity themselves. For substantial or high levels, national authorities conduct the assessment.
EU Member States develop rules on penalties. These apply to infringements of the Framework. They also apply to infringements of EU cybersecurity certification schemes. The Cybersecurity Act aims to increase safety in the EU’s digital environment.
This legislative framework includes various elements. It includes the Directive on Security of Network and Information Systems. It also includes the proposed ePrivacy Regulation. The General Data Protection Regulation requires appropriate data security measures.
The European Union Agency for Cybersecurity stands as a critical player. It works tirelessly to protect Europe from cyber threats. Its Heraklion office is a key part of this mission.