惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Stack Overflow Blog
Stack Overflow Blog
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
量子位
A
About on SuperTechFans
G
Google Developers Blog
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Vercel News
Vercel News
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
U
Unit 42
Apple Machine Learning Research
Apple Machine Learning Research

Help Net Security

FIDO Alliance wants to keep AI agents from going rogue on online payments Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security
EU cybersecurity standards are at risk if supplier ban pa...
Mirko Zorz · 2026-04-16 · via Help Net Security

Today, the European standards body ETSI sent a formal position paper to the European Commission, calling for changes to the proposed Cybersecurity Act 2 (CSA2), the EU’s planned revision to its existing cybersecurity certification framework.

EU cybersecurity standards

The paper focuses on two provisions: a proposed expansion of ENISA’s role in developing technical specifications, and a clause in Article 100(4)(a) that would bar entities from countries designated as posing cybersecurity concerns from participating in European standardization work tied to Commission requests.

ETSI is one of three European Standardization Organizations (ESOs) recognized under EU law to develop harmonized standards. Its membership includes over 900 organizations across 64 countries.

The “high-risk supplier” exclusion

Under the CSA2 proposal, the European Commission would designate “high-risk suppliers” based on EU-level security risk assessments, including structural non-technical risks. Entities receiving that designation would be excluded from development, assessment, consultation, and decision-making on cybersecurity standards developed by ESOs under Article 10(1) of Regulation (EU) No 1025/2012.

Contributions to European standardization should not be subject to prohibitions established in Union legal acts. The organization points to WTO Agreement on Technical Barriers to Trade principles, which it adheres to, along with Regulation (EU) No 1025/2012, both of which require openness, consensus, and independence from special interests in standards development.

“ETSI’s Directives provide flexibility to address security-related needs on a case-by-case basis. The 2022 European Standardisation Strategy and related governance reforms were designed to mitigate undue influence from outside the EU, preserving openness, transparency, inclusiveness, impartiality, and independence from special interests. Undermining these principles would risk the proper functioning, collaborative nature, and credibility of the system, Martin Chatel, Chief Policy Officer at ETSI, told Help Net Security.

The paper draws on a recent parallel. In 2019, the U.S. Commerce Department’s Entity List imposed restrictions on certain companies’ participation in 5G and telecommunications standardization. ANSI responded by noting that a standard’s global relevance depends on how it was developed, not which entity developed it. NIST stated that standardization should enable U.S., EU, and Chinese companies to collaborate in a voluntary, industry-led environment where market forces and the best technical contributions prevail. The Bureau of Industry and Security eventually softened the restrictions.

ETSI’s concern is that a similar dynamic could play out at the ITU, ISO, and IEC, where suppliers designated “high-risk” by the Commission may still be permitted to contribute. A supplier excluded from European standardization work could remain active in shaping the international versions of the same standards, reducing European influence in those forums.

Any restrictions should be assessed on a case-by-case basis, coordinated with ETSI and the other ESOs, and applied proportionately, rather than established as a general legal basis in EU legislation.

ENISA’s proposed role in drafting specifications

Article 18 of the CSA2 grants ENISA authority to draft technical specifications and technical guidance to support the implementation of Union legislation, in addition to contributing to standardization activities and assisting the Commission in assessing harmonized standards.

ETSI welcomes ENISA’s participation in standardization work and supports an expanded advisory role for the agency. The concern is specifically with the drafting authority. ETSI’s position is that ENISA’s role should be limited to advising on the legal framework and providing technical guidance. Extending it to drafting technical specifications risks creating a parallel standard-setting structure inconsistent with the existing legal framework, under which drafting is entrusted to bodies governed by private law, with the Commission retaining a supervisory role.

As a model for what appropriate agency participation looks like, the paper points to ETSI’s Technical Committee on Lawful Interception (TC LI), which brings together governments, law enforcement agencies, mobile network operators, and equipment vendors to develop standards supporting common requirements. Chatel noted that ETSI’s existing structure already provides operational answers combining openness, speed, global impact, and European safeguards, and that this is precisely the capability Europe should preserve and reinforce in the current geopolitical environment.

Standards as a policy instrument

ETSI’s paper sets the argument in the context of Europe’s broader standardization strategy. The 2022 EU Strategy on Standardization sought to reduce strategic dependencies and prevent undue influence from non-European actors in cybersecurity standards, without compromising openness and impartiality. Regulation (EU) No 2022/2480 subsequently gave EU/EEA National Standardization Bodies exclusive authority over certain decisions, including the adoption of Commission standardization requests and final approval of harmonized standards.

ETSI describes its role as serving two complementary functions: responding to market needs from its membership and developing standards in direct support of EU legislation. The organization operates without subordination to other standardization bodies and is not bound by an “international-first” approach. Standards it has developed, including EN 303 645 for consumer IoT security and EN 304 223 for cybersecurity in AI systems, have been adopted internationally after originating from European processes.

The paper closes by recommending improved coordination between the Commission and ETSI to preserve transparency, legitimacy, and trust in the European standardization system, and to avoid unintended consequences for innovation, competitiveness, and European industry’s standing in international standardization.