The Main Challenge: Fragmented Cybersecurity Standards in Europe

If you ask any European-based enterprise operating across multiple EU countries about cybersecurity compliance, you’ll probably hear the same complaint: every client wants something different. One customer might require alignment with ENISA guidance, another insists on ISO/IEC 27001, while another demands an audit against IEC 62443.
For large companies, this can lead to wasted time and higher costs without clear benefits. For smaller companies, it may result in exclusion from entire markets. The impact goes beyond paperwork; it can slow innovation and reduce competitiveness.
Imagine an IoT device manufacturer. To sell a smart thermostat in Germany, they may need to show compliance with ETSI EN 303 645. In France, the regulator might want assurance under national criteria. In Italy, energy operators may ask for IEC-62443 evidence. Each test is slightly different, each audit costs more money, and by the time the company clears all hurdles, a faster competitor has already claimed the market.
For buyers, fragmentation introduces uncertainty. How can you be confident that an enterprise’s systems and processes meet compliance requirements, rather than relying on the most easily obtained certificate? This uncertainty can increase the likelihood of operational and technical vulnerabilities within critical supply chains.
This is where harmonization comes in. Europe’s policymakers have recognized that if the continent is to secure its digital infrastructure and remain globally competitive, it needs a unified approach.
Why NIS2 Compliance Creates Confusion in Procurement
Let’s play out a scenario.
A widely used vendor releases a software update. If proper digital signature protections are not in place, the firmware could be exploited, allowing attackers to disrupt operations. Within hours, a telecom backbone might slow, energy grid operators could experience cascading outages, and incident queues may fill rapidly.
Under the NIS2 Directive, both telecom and energy operators are obligated to report incidents within tight timeframes and prove they followed “state of the art” practices. But here’s the catch: what counts as “state of the art”? If Europe hasn’t harmonized its standards, one regulator might accept ISO/IEC 27001 certification, while another insists on IEC 62443.
The result? Confusion for buyers, European-based enterprises, and even national authorities. Everyone agrees compliance matters, but no one agrees on how to measure it.
EU Cybersecurity Laws: NIS2, RED-DA, and CRA Explained

Three major regulations are forcing Europe to align its cybersecurity standards:
- NIS2 Directive – Expands obligations for essential and important entities, including telecom, energy, healthcare, and transport. It imposes stricter breach reporting, supply chain security requirements, and tough penalties for non-compliance.
- Radio Equipment Directive (RED) Delegated Act – Adds cybersecurity requirements for wireless and IoT devices, including protections around data privacy, network resilience, and fraud prevention.
- Cyber Resilience Act (CRA) – A sweeping regulation that requires all connected products, consumer or industrial, to meet baseline cybersecurity requirements across their lifecycle, from design to updates and patching.
Taken together, these laws are more than just another set of regulations. They mark a turning point. Europe is shifting toward a truly horizontal, harmonized model where product security, organizational resilience, and regulatory oversight finally move in sync across sectors. The challenge is that in the short term, the overlap is messy. Companies are scrambling to make sense of requirements that sometimes align and sometimes do not.
Roles of ENISA, ETSI, and CEN-CENELEC in EU Cybersecurity
So, who actually sets the rules?
- ENISA (European Union Agency for Cybersecurity) – Issues guidance on NIS2 implementation and plays a major role in shaping cybersecurity certification schemes under the Cybersecurity Act.
- ETSI (European Telecommunications Standards Institute) – Develops telecom and IoT security standards. A notable example is ETSI EN 303 645, the baseline standard for consumer IoT devices, covering secure defaults, vulnerability disclosure, and update policies.
- CEN-CENELEC – Coordinates European standardization across industries, develops harmonized standards upon request from the European Commission ensuring that global frameworks like ISO/IEC 27001 or IEC 62443 are adapted for EU needs.
These bodies are not working in isolation. They are coordinating, but alignment takes time. Until harmonization fully takes hold, European-based enterprises and buyers will still have to navigate a patchwork of frameworks. At the same time, there is growing interest among TSOs, customers, and manufacturers in the PV sector in an ecological security initiative that encourages intelligence sharing and collaborative security planning.
EUCC and Emerging EU Cybersecurity Certification Schemes
Certification is supposed to solve the trust problem. If a product or service is certified once, it should be recognized everywhere in the EU. That’s the idea behind the EUCC (European Cybersecurity Certification Scheme for ICT Products), which replaces national Common Criteria schemes.
EUCC will allow products to be certified at different assurance levels, substantial, and high, depending on their risk profile. For example, an IoT gateway may only need a substantial level, while a telecom core router could require a high level.
But EUCC isn’t the only scheme. Others are in development for cloud services, 5G equipment, and Managed Security Services (MSS). The challenge? Until these schemes are operational and universally recognized, companies still face inconsistent requirements.
Telecom & 5G: Meeting NIS2 Cybersecurity Requirements
Telecom operators are already some of the most heavily regulated entities in Europe, with GDPR, eIDAS, and sector-specific laws in place. NIS2 adds another layer: stricter incident reporting deadlines, expanded supply chain oversight, and direct supervisory authority from regulators.
For 5G, the stakes are even higher. The technology is critical infrastructure, and security concerns extend beyond technical vulnerabilities to questions of vendor trustworthiness and geopolitical influence. Harmonization matters because telecom operators need a single framework to evaluate vendor compliance. Without it, a European-based enterprise providing 5G products or services may pass certification in one country but face rejection in another. Initiatives like the GSMA’s Mobile Cybersecurity Knowledge Base (MCKB) and Network Equipment Security Assurance Scheme (NESAS) are working to standardize security practices across the industry, offering a unified approach to 5G security assurance.
Energy & OT Security: EN IEC 62443 and CRA Profiles
Energy systems bring another challenge: the convergence of IT and OT (operational technology). Grid operators must secure both their corporate IT systems and their industrial control systems.
The EN IEC 62443 standard family provides a framework for OT security, with profiles for components, systems, and organizations. Under NIS2, operators are expected to adopt “appropriate” measures, but the CRA will likely formalize how IEC 62443 maps to EU compliance.
This matters because energy infrastructure is a prime target for ransomware, nation-state attacks, and supply chain compromises. Harmonized profiles will give buyers and European-based enterprises a common baseline, reducing risk across borders.
Challenges in EU Cybersecurity: Fragmentation, IT–OT Gaps, SME Burden
Of course, harmonization is easier said than done. Several challenges stand out:
- Fragmentation persists – National authorities still interpret EU law differently, leading to inconsistent enforcement.
- IT–OT divide – Many organizations struggle to bridge corporate IT governance with industrial OT security needs.
- SME burden – Smaller European-based enterprises may find compliance costs prohibitive, creating a risk that only larger companies can compete.
- Innovation vs. compliance tension – Startups worry that stringent certification demands could slow product launches, making it harder to compete globally.
If Europe doesn’t solve these challenges, it risks weakening its cybersecurity posture and stifling the very innovation it seeks to protect.
Framework for NIS2 and CRA Compliance in Europe
So, what does “good” look like? A practical compliance roadmap might look like this:
- Baseline controls – Establish cybersecurity hygiene anchored in globally recognized frameworks like ISO/IEC 27001, IEC 62443, or ETSI EN 303 645.
- Sector alignment – Map sector-specific regulations (telecom, energy, healthcare) against NIS2 and CRA requirements to avoid duplication.
- Certification readiness – Prepare for EUCC and other schemes by documenting controls, conducting gap assessments, and streamlining due diligence for European-based enterprises.
This approach ensures organizations aren’t just reacting to audits but building lasting resilience.
And here’s the motivating part: harmonized cybersecurity standards aren’t just about avoiding fines. They can become a market differentiator. The companies that prepare early, align with EU-wide frameworks, and demonstrate compliance transparently will win contracts faster and build stronger customer trust.
Behind on EU Cybersecurity Standards? Key 2025 Dates You Need to Act On Now

Several regulatory and standards milestones have already occurred. Missing them isn’t just a paperwork problem; it has real operational, strategic, and reputational consequences. Here’s what’s already happened and why acting now is critical:
RED Cybersecurity Requirements Effective (August 2025)
The Delegated Act (EU) 2022/30 for radio equipment is now in force. European-based enterprises that did not align devices with baseline security controls may face product rejections or delays. Buyers who failed to reference RED in RFPs could experience procurement bottlenecks or inconsistencies in enterprise assurance.
Implication: Non-compliant devices may be barred from EU markets, and procurement cycles are slower due to missing or unclear evidence.
First EUCC Certificates Issued (April 2025)
The EU Cybersecurity Certification Scheme (EUCC) went live, with the first certificates issued by ANSSI. Organizations that delayed pursuing EUCC certification are now behind competitors who can demonstrate verified EU-wide compliance.
Implication: Late adopters risk losing contracts, credibility, and market trust. Customers increasingly expect EUCC-aligned proof of security for ICT products.
ENISA NIS2 Technical Guidance Published (June 2025)
ENISA’s Technical Implementation Guidance and mapping tables provided the practical bridge from law to action. Teams that ignored these resources are scrambling to operationalize NIS2 controls for audits, risk management, and evaluations of European-based enterprises.
Implication: Organizations without early ENISA alignment face gaps in compliance documentation, slower audit cycles, and a higher likelihood of supervisory questions.
CRA Horizontal & Vertical Standards in Development (Ongoing 2025-2026)
The CRA is triggering an unprecedented wave of standardization efforts across Europe, with horizontal and vertical standards currently under development through CEN-CENELEC, and ETSI. Horizontal standards aim to provide a consistent baseline for all products with digital elements, covering principles for cyber resilience, generic security requirements, and processes such as vulnerability handling and secure update management. These standards establish the “common language” that manufacturers, evaluators, and regulators can rely on to demonstrate compliance with the CRA’s essential requirements. Their horizontal nature ensures that security by design, risk management, and lifecycle practices apply uniformly across the diverse digital ecosystem.
In parallel, vertical standards target specific product categories considered important or critical under the CRA. These include standards for embedded and standalone browsers, password managers, VPN products, firewalls, intrusion detection systems, network management, hypervisors, and secure hardware elements such as microcontrollers or FPGAs. Many of these are being developed as modular security profiles, often drawing from existing frameworks like IEC 62443. The combination of horizontal and vertical standards will allow manufacturers to align both with overarching cybersecurity principles and with product-specific controls. By 2026, the EU standardization community is expected to deliver a harmonized solutions of standards that will become the backbone of conformity assessment under the CRA.
Implication: Delayed preparation increases the risk of failing CRA alignment checks and scrambling to update products mid-cycle.
EUCS and EU5G Schemes – Draft Stage (Mid-2025 onward)
Cloud and 5G certifications were still politically sensitive and under development. Buyers who did not track progress or leave room for flexibility in contracts may now face delays or renegotiations.
Implication: Rigid contract language tied to pending schemes creates legal and operational friction. Early monitoring could have avoided this.
Monday Action Plan: Practical Steps for your Security Compliance

Big compliance projects can feel like they belong to next quarter or next year. But NIS2 and the CRA aren’t waiting, and neither should you. The good news: you can start moving the needle by Monday morning.
Step 1. Refresh your RFP templates.
Update your procurement and vendor-management playbooks to explicitly reference ENISA’s NIS2 mapping table. Where relevant, add anchors like ETSI EN 303 645 for consumer IoT, 3GPP TS 33.501 or MCKB for 5G networks, or EN IEC 62443 for industrial controls. This isn’t just box-ticking; it ensures European-based enterprises align with your requirements and positions you as a buyer who demands future-proof compliance.
Building on this, complying with the security requirements of ETSI EN 303 645 and IEC 62443 has actually become a relatively mature framework and consensus for achieving NIS2 compliance, especially within the photovoltaic (PV) sector. For manufacturers of smart inverters or grid-tied energy systems, demonstrating alignment with ETSI EN 303 645 covers essential cybersecurity for connected devices, while IEC 62443 provides the deep-dive into operational technology security crucial for energy infrastructure. This dual approach offers a clear, actionable path for the PV industry to meet NIS2’s “state of the art” requirements, streamline audits, and build trust in a rapidly expanding market.
Step 2. Build a certificate chooser into proposals.
European-based enterprises should stop treating certification like an afterthought. Start by including a simple chooser in your proposals: CSPN vs EUCC today, with a placeholder for EUCS once the final scheme text is released. That one change signals to regulators and customers that you’re actively tracking harmonization, and it helps your sales teams close faster by reducing back-and-forth.
Step 3. Insert digital-trust SLAs that go beyond uptime.
Don’t just promise 99.9% availability. Bake in security-specific service level agreements: patch-release latency, coordinated vulnerability disclosure (CVD) response time, SBOM publication cadence, and crypto agility roadmaps. Tie these commitments directly to ENISA’s NIS2 expectations so they’re not optional extras; they’re compliance-driven. This makes trust measurable and auditable.
Step 4. Map today’s products to tomorrow’s CRA categories.
The Cyber Resilience Act isn’t vague anymore; draft horizontals are already forming. Track ETSI’s European Standards for cyber (EUSR) and CENELEC JTC13, TC 65X profiles now. Then, pre-map your product portfolio (routers, VPN gateways, SIEM platforms, browsers, password managers) to the likely EN numbers they’ll inherit.
By tackling even a few of the Monday steps, you start turning regulation into a competitive advantage. The rules are complex, but they also create clarity: security, resilience, and trust are now market expectations. The sooner you align, the stronger your position when customers, regulators, and competitors are all watching.









Leave a Reply