ITI Outlines Recommendations for EU Cybersecurity Certification Scheme for Cloud Services

The Information Technology Industry Council (ITI) has released a policy paper outlining recommendations for the EU Cybersecurity Certification Scheme for Cloud Services (EUCS). ITI emphasizes the importance of a balanced and proportional approach to cloud certification requirements, calling on stakeholders to reconsider clauses on EU-ownership and data localisation. The association supports the goal of improving cybersecurity in the EU Digital Single Market, but remains concerned about elements of the draft EUCS scheme.

Key Takeaways:

  • ITI advises adopting a risk-based approach focused on technical requirements for cloud certification, aligning with ENISA's mandate under the EU Cybersecurity Act.
  • The association reiterates the importance of stakeholder engagement, calling on ENISA to conduct a consultation and assess the need, feasibility, lawfulness, and expected impact of ownership and data localisation requirements.
  • ITI stresses that the EU's WTO commitments and values of equal treatment, non-discrimination, and cooperation require the EU to remain open to like-minded partners.
  • The association advocates for a voluntary certification scheme, rather than imposing political choices through technical requirements.
  • ITI emphasizes the need to foster trust and stimulate cloud uptake through harmonised cybersecurity certification requirements.

Sources:

  • Information Technology Industry Council (ITI) policy paper
  • ENISA (European Union Agency for Network and Information Security)
  • European Commission
  • WTO (World Trade Organization)

Statistics:

  • None specific to the article, but the EUCS scheme is expected to impact the European Union's Digital Single Market.