Decoding the world of cybersecurity

EU cyber rules move into standards

ETSI and European Commission officials are tightening their work on cybersecurity and technology standards as Europe’s digital rules move from legislation into technical implementation.

EU cyber rules move into standards
Summary
  • ETSI and senior Commission officials have agreed closer work around cybersecurity, technological sovereignty, AI, 6G, and future product regulation.
  • Cyber Resilience Act implementation has increased the importance of technical standards that manufacturers can use to demonstrate conformity.
  • The quality and speed of standards work will shape how consistently Europe’s expanding technology rulebook operates in practice.

ETSI and senior European Commission officials are deepening cooperation on cybersecurity and digital standards as the European Union moves from writing technology legislation towards defining the technical specifications needed to implement it.

Representatives from ETSI, the Commission’s Directorate-General for Communications Networks, Content and Technology, and DG GROW met in Brussels this week to discuss competitiveness, cybersecurity, technological sovereignty, artificial intelligence, 6G, and the future of European standardisation.

The discussion included lessons from the Cyber Resilience Act and the forthcoming European Product Act package. Commission officials said standards need to keep pace with rapidly developing technologies, while ETSI set out an approach centred on innovation, standardisation, competition, and safeguarding.

Those discussions sit below the level of headline legislation but increasingly determine whether Europe’s digital rules are usable. The Cyber Resilience Act creates horizontal cybersecurity requirements for products with digital elements, but manufacturers need technical standards capable of translating legal obligations into testable engineering requirements and conformity processes.

Seventeen product-specific cybersecurity standards entered the formal public-enquiry process earlier this year. Cyber Insider reported in August that the work covered categories including identity and access management systems, hypervisors and container runtime systems, routers, modems, connected home products, smart meters, and security cameras.

The standards are important because harmonised European standards can provide a route for manufacturers to demonstrate conformity with legislative requirements. The practical details therefore affect product architecture, assurance, documentation, vulnerability management, and procurement long after the political negotiations that created the underlying law have finished.

Timing is another pressure. CRA vulnerability and incident reporting requirements began on 11 September 2026, while most of the regulation’s cybersecurity obligations apply from December 2027. Manufacturers are consequently preparing products, development processes, and support arrangements while parts of the supporting standards framework are still moving through approval.

The European Commission and ETSI also framed standardisation within technological sovereignty. That term can cover industrial policy, supply chains, infrastructure control, and Europe’s ability to influence the specifications underpinning global technology markets. ETSI officials argued that European influence depends less on placing a regional label on technology than on shaping standards that are deployed internationally.

That global dimension is particularly important in cybersecurity. Identity, electronic signatures, consumer IoT security, telecommunications, AI, and software components cross jurisdictions by design. European requirements that diverge sharply from widely used technical standards can increase implementation complexity; standards that gain international adoption can instead extend the practical influence of EU policy beyond the bloc.

The challenge is that standards processes tend to move more slowly than software development. AI services, connected products, and cloud architectures can change materially within a product cycle, while formal technical standards require consultation, consensus, testing, and maintenance.

The Brussels meeting does not itself create new compliance obligations. It does, however, underline where much of the implementation work now sits. Europe has spent several years expanding the legal responsibilities attached to digital products and services. Whether those rules produce consistent security outcomes increasingly depends on the specifications beneath them.

×