ITI Outlines Recommendations for EU Cybersecurity Certification Scheme for Cloud Services
The Information Technology Industry Council (ITI) has released a policy paper outlining recommendations for the EU Cybersecurity Certification Scheme for Cloud Services (EUCS). ITI emphasizes the importance of a balanced and proportional approach to cloud certification requirements, calling on stakeholders to reconsider clauses on EU-ownership and data localisation. The association supports the goal of improving cybersecurity in the EU Digital Single Market, but remains concerned about elements of the draft EUCS scheme.
Key Takeaways:
- ITI advises adopting a risk-based approach focused on technical requirements for cloud certification, aligning with ENISA's mandate under the EU Cybersecurity Act.
- The association reiterates the importance of stakeholder engagement, calling on ENISA to conduct a consultation and assess the need, feasibility, lawfulness, and expected impact of ownership and data localisation requirements.
- ITI stresses that the EU's WTO commitments and values of equal treatment, non-discrimination, and cooperation require the EU to remain open to like-minded partners.
- The association advocates for a voluntary certification scheme, rather than imposing political choices through technical requirements.
- ITI emphasizes the need to foster trust and stimulate cloud uptake through harmonised cybersecurity certification requirements.
Sources:
- Information Technology Industry Council (ITI) policy paper
- ENISA (European Union Agency for Network and Information Security)
- European Commission
- WTO (World Trade Organization)
Statistics:
- None specific to the article, but the EUCS scheme is expected to impact the European Union's Digital Single Market.