The recent draft ITRE report on CSA2 brings several welcome improvements, particularly on evidence, due process and judicial remedies. It also reopens a question left unresolved since 2019.

The first Cybersecurity Act set aside the idea of qualification, partly because of concerns that national processes would be applied unevenly across Europe. Should CSA2 now revisit that decision by establishing a common European qualification framework?

A de facto whitelist?

The draft ITRE report (PE 792.222) improves the Commission proposal. Information submitted by a national authority could trigger a Commission assessment, but would not alone justify placing a supplier on the EU high-risk list. Inclusion would require supplier-specific evidence, a right to be heard, a reasoned decision and access to judicial remedies.

These safeguards are welcome. They would reduce the risk of a supplier being excluded on the basis of an unsupported national assertion.

The proposed evaluation matrix nevertheless remains weak. Its methodology, criteria and weighting would benefit from being developed at a second stage by cybersecurity authorities and experts, rather than being settled primarily through political negotiations.

The current matrix gives favourable weight to suppliers from countries offering reciprocal market access, participating in certain procurement arrangements or having concluded agreements with the EU.

This does not formally create a whitelist. In practice, however, it comes close to doing so through a favourable rebuttable presumption based partly on the supplier’s country of origin and the EU’s trade relations with that country.

Cybersecurity must not become a bargaining chip in commercial negotiations. A trade agreement or geopolitical decisions are not evidence that a product is (cyber)secure. Conversely, the absence of such an agreement does not demonstrate that a product contains vulnerabilities or hidden functions.

The European market aims to remain open, but secured. Are we missing the target here? Access to sensitive uses must depend on independently verified evidence and not diplomatic status.

Qualification before geopolitical exclusion

European qualification processes would provide a more objective and technically credible answer.

Following the logic of schemes such as the French SecNumCloud, qualification should apply to a precisely defined product, service or operational perimeter, particularly in critical environments covered by NIS2. It should not amount to blanket approval of a company or of every solution it provides.

Qualification must go beyond a declaration of conformity. It should combine technical evaluation with an assessment of the operational and legal environment in which the solution is developed, maintained and delivered. A public cybersecurity authority would then take responsibility for determining whether the evaluated solution is suitable for sensitive or critical uses.

That solution may be a physical product, software placed on the market or software delivered as a service. This distinction is becoming increasingly artificial as products rely on remote processing, continuous updates and cloud components. CSA2 will not, by itself, resolve these blurred boundaries. A qualification framework should therefore follow the actual security perimeter and lifecycle of the solution, rather than depend on how it is commercially packaged.

Here again, trust would attach to evidence, a specific version and a controlled perimeter not to a supplier’s nationality.

The qualification framework should be developed with the same rigour as a European cybersecurity certification scheme. Member States, relevant stakeholders, evaluation bodies and independent technical experts should participate in defining its requirements, assessment methods and governance.

Evaluation laboratories and certification bodies would need appropriate accreditation and, for the highest levels, specific authorisation and supervision by national cybersecurity authorities. Clear delegation criteria, peer review and cooperation between those authorities would allow qualifications to be recognised across Europe without recreating the fragmentation feared in 2019.

Cybersecurity is a moving target. Qualification must therefore remain dynamic too.

Qualification must also be maintained. Vulnerabilities emerge; software, products and services change; supply chains evolve; and ownership or control may shift. A qualified solution cannot be treated as permanently trusted. Surveillance, reassessment following material changes, periodic renewal and the possibility of suspension or withdrawal are essential.

High assurance requires adversarial testing

The proposed legislative language on the highest assurance level remains ambiguous: it refers to penetration testing “where relevant” and allows it to be replaced when considered inappropriate. This ambiguity must be removed.

At the high-assurance level, penetration testing – or an equivalent method providing the same depth of adversarial assessment should always be required.

Testing a deployed service from the outside is not sufficient. Depending on the evaluated perimeter, the assessment should cover the relevant source code, static and dynamic analysis, third-party dependencies, the build chain, update mechanisms, privileged and remote access, cryptographic-key control and the correspondence between the evaluated source and the deployed binary or service.

This is not only a security requirement. It is a practical instrument of sovereignty. That is also why these assessments should remain within the remit of national cybersecurity certification authorities, whether performed directly or under their explicit and controlled delegation.

Examining the source code, update chain and access mechanisms allows Europe to assess the technology itself rather than rely on the nationality of its provider or declarations of trust. No evaluation can prove the absolute absence of a backdoor. It can, however, provide independent assurance that hidden functions have been actively investigated within a defined and controlled perimeter.

Sovereignty begins with the capacity to understand, test and monitor the technologies on which critical services depend.

Security also has a legal perimeter

Technical evaluation must be complemented by legal and operational requirements for critical uses. These should verify – not merely restate – GDPR implementation, data localisation, administrator access, encryption and key ownership, international transfers, subcontracting and exposure to extraterritorial laws.

This logic was explored during the development of EUCS through the idea of a possible “High+” layer: technical assurance would have been complemented by sovereignty or “immunity” requirements. Although “High+” was never established as a formal EUCS assurance level, the underlying question has not disappeared.

Annex II to the proposed Cloud and AI Development Act – although itself open to improvement – takes broadly the same direction. Its cloud sovereignty levels add criteria concerning establishment, ownership, jurisdiction, operational control, data location, personnel, software dependencies and exposure to third-country laws. For the relevant levels, these requirements complement cybersecurity certification under EUCS.

This distinction is important. Cybersecurity certification evaluates security properties; sovereignty also requires an assessment of legal, operational and strategic dependencies.

The CADA proposal already provides for audits (to be improved), national competent authorities, cross-border cooperation and periodic revision of its annexes. Its governance should nevertheless be strengthened to ensure that assessments are conducted consistently across Europe, that evaluators are properly supervised, that requirements remain current and that effective review and appeal mechanisms exist. The same principle should guide CSA2.

Europe does not need a political list of trusted suppliers. It needs a robust method for establishing trust. The market can remain open, but sensitive access must be earned through independent evaluation, accountable public oversight and continuous verification. European cyber sovereignty must be demonstrated.