Computer & Communication Industry Association
PublishedJanuary 20, 2026

Cybersecurity Act: Focus on Security Standards Welcomed, But Industry Warns Against Exclusionary Amendments

Brussels, BELGIUM – The European Commission’s long-awaited revision of the EU Cybersecurity Act (CSA), presented today, is a welcome step towards harmonising technical security criteria across the European Union and securing Europe’s ICT supply chain. 

The Computer & Communications Industry Association (CCIA Europe) applauds the Commission’s decision to focus on technical security benchmarks and evidence-based certification, rather than introducing discriminatory ‘sovereignty’ restrictions.

By avoiding politically-motivated restrictions in cybersecurity certifications – which, for example, would have barred non-EU providers from high-level certification – the Commission signals its commitment to a competitive and open Digital Single Market.

However, CCIA Europe warns there is a real risk that EU Member States and Members of the European Parliament (MEPs) may attempt to introduce protectionist criteria during negotiations. 

Equally, the proposal leaves the definition of ‘high-risk countries’ broad. Clarifying this concept is essential to provide certainty and clarity for ICT vendors and customers. Metrics for high-risk status should be based on demonstrated, tangible, and objective factors; such as government interference, lack of effective judicial oversight, or the absence of security and law enforcement cooperation agreements. 

As the legislative process begins, EU co-legislators must ensure the CSA revision respects its original promise: the structural harmonisation of technical cybersecurity criteria. Geopolitical supply-chain risks should instead be addressed through dedicated forums, ensuring a clear distinction between high-risk countries and essential trade partners.

The following can be attributed to CCIA Europe’s Technology and Security Policy Manager, Mitchell Rutledge: 

“The Commission has taken the correct approach by anchoring the certification of digital services in technical, objective security criteria rather than bending to political intervention. The Cybersecurity Act has long needed a hard reboot that fixes fragmentation and delivers real-world certificates, not endless debate over blunt country-of-origin market exclusion.”

“We call on the EU institutions to continue to resist the protectionist urge to reinstate discriminatory restrictions that would harm the security of Europe’s digital ecosystem, instead providing a clear and predictable framework for how high-risk vendor assessments are conducted across Europe’s ICT supply chain.”

News

CCIA Report Finds the EU’s DMA Losing Appeal as Global Model for Digital Competition Policy

Washington – A new report from the CCIA Research Center finds that the European Union’s Digital Markets Act (DMA) is losing appeal as a global model for digital competition policy, with government...
reading-tablet
  • Press Releases
  • Competition
News

Tech Associations Present Semiconductor and Industrial Machinery Tariff Concerns in White House Letter

Washington - The Computer & Communications Industry Association joined 4 other tech trade associations in a letter to President Trump on how his proposed 232 tariffs on semiconductors, robots, and...
reading-tablet
  • Press Releases
    Tax
News

Hidden ‘Network Fee’ Backdoors in EU Digital Networks Act Exposed as Big Telcos Push for Mandatory Payments Behind Closed Doors

Brussels, BELGIUM – As Europe’s largest telecom operators gather in Brussels today, the Computer & Communications Industry Association (CCIA Europe) has launched a new policy explainer reveali...
reading-tablet
  • Press Releases
    Telecom
News

CCIA Europe Strengthens Brussels Team with Three New Appointments

Brussels, BELGIUM – The Computer & Communications Industry Association (CCIA Europe) has strengthened its Brussels office with new staff appointments across its policy and communications teams. ...
reading-tablet
  • Press Releases