The EU Legal Frameworks Regulating IoT Cybersecurity
摘要
This chapter maps out the different EU legal frameworks regulating IoT cybersecurity, taking into account insights from IoT industry stakeholders, including manufacturers, cybersecurity experts, and consumer advocacy groups/end-users. Such interdisciplinary perspectives could offer additional insights into the effectiveness of the regulatory measures analysed. The investigation first considers to what extent Directive EU 2016/1148 (NIS Directive), the first piece of EU legislation on cybersecurity, encompasses IoT cybersecurity and whether regulatory gaps exist. Then, the EU framework for cybersecurity certification introduced by Regulation (EU) 2019/881 (Cybersecurity Act) is scrutinised to assess whether it could eventually fill significant regulatory gaps and inconsistencies in the EU cybersecurity legal framework. Against the background of IoT manufacturers’ lack of legal obligations vis-à-vis the cybersecurity of their products, the EU Commission’s approach towards the ever-growing number of unsecure IoT devices in the Single Market consisted of revising different legal acts within EU product safety legislation to include essential cybersecurity requirements. Accordingly, the analysis focuses on several pieces of legislation which show, albeit from different angles, how cybersecurity is progressively linked to the safety regulation of (connected) products. These are: the Radio Equipment Directive (RED) and the Delegated Regulation (EU) 2022/30, the Medical Devices Regulation, the Machinery Regulation and the General Product Safety Regulation. Further, the NIS2 Directive is addressed, in particular, about the extent to which it would encompass the complexity raised by the IoT ecosystem. However, the resulting fragmented regulatory framework does not specifically and comprehensively tackle the problem of a Single Market flooded by unsecure connected (IoT) products. Therefore, the last part of the chapter casts light on the incoming EU Cyber Resilience Act (CRA), which will introduce horizontal cybersecurity requirements for products with digital elements.