Sittings · Document

opinion letter parliamentary committee (COM(2023)0208 – C90137/2023 – 2023/0108(COD)) 2023-09-21

Opinion on the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services

Committee on the Internal Market and Consumer Protection

21.9.2023

Mr Cristian Silviu Buşoi

Chair

Committee on Industry, Research and Energy

BRUSSELS

Subject: Opinion on the Proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services (COM(2023)0208 – C90137/2023 – 2023/0108(COD))

Dear Mr Chair,

Under the procedure referred to above, the Committee on the Internal Market and Consumer Protection has been asked to submit an opinion to your committee. At its meeting of 23 May 2023, the committee decided to send the opinion in the form of a letter. It considered the matter at its meeting of 19 September 2023 and adopted the opinion at that meeting.

At that meeting, it decided to call on the Committee on Industry, Research and Energy (ITRE), as the committee responsible, to incorporate the following suggestions into its legislative report.

Yours sincerely,

Anna Cavazzini

SUGGESTIONS

The Committee on Internal Market and Consumer Protection calls on the Committee on Industry, Research and Energy, as the Committee responsible, to take into account the following suggestions:

A. Whereas the Commission published a legislative proposal on managed security services that entails targeted amendments to the EU Cybersecurity Act on 18 April 2023;

B. Whereas on the legislative proposal for the EU Cybersecurity Act (2017/0225(COD)), the Committee on the Internal Market and Consumer Protection (IMCO) submitted an opinion under former Rule 54 of the Rules of Procedure to the responsible Committee on Industry, Research and Energy (ITRE) with shared competences on the cybersecurity certification framework, given IMCO´s clear competence in relation to certification schemes and, in general, standardisation, market surveillance and implementation of the Digital Single Market;

C. Whereas the EU Cybersecurity Act aims to achieve 1) a high level of cybersecurity, cyber resilience and trust in the EU by setting objectives, tasks and organisational matters for a strengthened and renamed European Union Agency for Cybersecurity (ENISA), with a new permanent mandate, and 2) a framework for voluntary European cybersecurity certification schemes for information and communications technology (ICT) products, services and processes;

D. Whereas the proposed targeted amendments to include managed security services to the scope of the EU Cybersecurity Act and add a definition of those services that is closely aligned to the definition under the NIS 2 Directive; whereas the amendments would enable the Commission by means of implementing acts to adopt European cybersecurity certification schemes for managed security services, in addition to ICT products, services and processes, which are already covered under the EU Cybersecurity Act;

E. Whereas managed security services play an increasingly important role in the prevention and mitigation of cybersecurity incidents;

1. Acknowledges that on 23 May 2022 the Council called for an increase of the overall level of cybersecurity in the EU by facilitating the emergence and development of trusted cybersecurity service providers; considers that, among others, the war in Ukraine, the current geopolitical context and continuous threats from third country regimes as well as a continuously growing market of digital technologies and digital transformation of processes in general have led to the need for a higher level of cybersecurity in the EU and its Member States; recommends that the Commission should take proactive measures to support the development of trusted cybersecurity service providers such as funding for research and development, training programmes to build cybersecurity skills, and incentives for businesses to invest in cybersecurity; suggests that the EU should strengthen its cooperation with NATO and other international partners to respond to cyber threats from third country regimes, including sharing of threat intelligence, joint exercises, and coordinated responses to cyber-attacks;

2. Stresses that the certification of managed security services, based on non-discriminatory rules and reflecting European and international standards, is essential for building and guaranteeing trust in the quality of those services, in particular with an aim for achieving a high level of consumer protection; notes that some Member States have already adopted certification schemes for managed security services and that therefore it is essential to avoid fragmentation in the internal market and inconsistencies, which may affect the cybersecurity industry and businesses, and to enable a harmonised approach through the creation of a European cybersecurity certification scheme for such services; asks that the cybersecurity certification framework should incorporate the best practices from existing national certification schemes and be developed in consultation with key stakeholders in the cybersecurity industry;

3. Highlights that managed security service providers, in areas such as incident response, penetration testing, security audits and consultancy, play an important role in assisting entities in their efforts to prevent, detect, respond to or recover from cyber incidents; considers that as more and more companies struggle to maintain various complex software systems and interconnected corporate networks, they are necessarily relying on managed security service providers and therefore such providers should be considered an essential element in the EU’s cybersecurity ecosystem; notes however that managed security service providers have also themselves been the target of cyberattacks and may pose a particular risk because of their close integration in the operations of their customers;

4. Recalls the importance of the recently adopted NIS 2 Directive to ensure a greater level of cyber resilience throughout the Union; calls for the rapid adoption and implementation of implementing acts under this Directive in order to ensure that providers of managed security services comply with the Directive’s requirements on cybersecurity risk-management measures;

5. Recommends that managed security service providers should be required to adhere to relevant cybersecurity standards and undergo regular reviews to ensure their systems are secure to protect not only the providers themselves but also the entities they serve; considers that such reviews should assess the providers' compliance with the EU-wide cybersecurity certification framework and their ability to protect both their systems and those of their customers from cyber threats;

6. Welcomes the legislative proposal on managed security services, which aims to improve the quality of managed security services and to increase their comparability to the benefit of a proper functioning of the internal market and implementation of the Digital Single Market; stresses that certification of managed security services is relevant in the selection process for the EU Cybersecurity Reserve and is also a significant quality and trust indicator for private and public entities that aim to purchase such services;

7. Notes that the proposal strengthens the role of ENISA, which should support and promote the development and implementation of Union policy on cybersecurity certification of ICT products, services, processes and managed security services, by regularly monitoring developments in related areas of standardisation and recommending technical specifications, where standards are not available; suggests that ENISA should be given additional resources and authority to carry out its expanded role, including funding for research and development, and a clear mandate to coordinate with national cybersecurity agencies and industry stakeholders; underlines the essential role of computer security incident response teams (CSIRTs) in achieving predictable and safe digital space for businesses and citizens;

8. Calls on the Commission and ENISA to support and ensure consistent implementation of the European cybersecurity certification scheme based on non-discriminatory rules and reflecting European and international standards for the conformity self-assessment by the manufacturer or provider of ICT products, services, processes or managed security services, in accordance with the EU Cybersecurity Act; believes that the implementation should help to offset the costs of accreditation and encourage more manufacturers or providers to participate in the scheme;

9. Stresses that each certification scheme should be designed in such a way as to stimulate and encourage all actors involved in the sector concerned to develop and adopt regularly updated security standards, technical norms and security-by-design and privacy-by-design principles, at all stages of the product or service lifecycle; highlights that input from civil society and independent security researchers relevant stakeholders needs to be taken into account in a more systematic way when developing such principles; considers that the certification schemes should be consistent with other European cybersecurity certification schemes adopted in accordance with the EU Cybersecurity Act and should avoid disproportionate burden on providers; recommends that certification schemes should include clear and detailed guidelines on how to implement security-by-design and privacy-by-design principles, where such guidelines are in accordance with the provisions setting out the framework for European cybersecurity schemes in the EU Cybersecurity Act; suggests that, where necessary and proportionate, certification schemes should consist of a mechanism for continuous improvement, such as regular reviews and updates of the security standards and technical norms; considers that the mechanism should take into account the latest developments in cybersecurity threats and technologies; encourages that each certification scheme should include measures to promote transparency and accountability, such as public disclosure of certification results and penalties for non-compliance;

10. Calls for the introduction of an voluntary EU Trust Label for certified ICT products, services, processes and managed security services; highlights in this regard that the label could help raise awareness of cybersecurity across the internal market and give companies with good cybersecurity credentials a competitive edge; suggests that the EU Trust Label should be designed to be easily recognisable and understandable by consumers and businesses;

11. Recommends the Commission and ENISA to establish a dedicated research and development program for cybersecurity; recommends that the Commission and ENISA should establish a cybersecurity risk assessment framework for businesses containing guidelines on how to identify, assess, and mitigate cybersecurity risks, and could be tailored to different sectors and sizes of companies; suggests that the Commission and ENISA should offer help and assistance to the Member States to establish a cybersecurity incident reporting mechanism for consumers and businesses to facilitate the collection of data on cybersecurity incidents, which could be used to improve cybersecurity policies and practices.