Skip to content
Home› Europe› European Parliament› Gazette› Regulation (EU) 2025/37 of the Euro...
DEFENCE INDUSTRY AND DUAL USE GAZETTE NOTIFICATION

Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services (Text with EEA relevance)

Date: 15th January 2025
Issued by European Parliament · Council of the European Union
Jurisdiction: European Union
European Union

Read or download the official PDF of this gazette notification issued by the European Parliament on 15th January 2025.

Official Gazette Notification Text

Official Transcript

Official Journal EN of the European Union L series 2025/37 15.1.2025 REGULATION (EU) 2025/37 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services (Text with EEA relevance) THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION, Having regard to the Treaty on the Functioning of the European Union, and in...

PolicyIndex Takeaway
Get AI summary →
  • ✓ Regulation (EU) 2025/37 amends Regulation (EU) 2019/881 to establish a framework for European cybersecurity certification schemes for managed security services (MSS).
  • ✓ The goal is to ensure an adequate level of cybersecurity for MSS in the Union and to avoid fragmentation of the internal market regarding cybersecurity certification schemes.
  • ✓ The regulation aims to enhance the functioning of the internal market by increasing the level of cybersecurity within the Union and enabling a harmonized approach at Union level to European cybersecurity certification schemes for ICT products, ICT services, ICT processes and managed security services.
  • ✓ Extends the scope of Regulation (EU) 2019/881 to include managed security services in the European cybersecurity certification framework (Article 1(1)).
  • ✓ Defines 'managed security service' as a service provided to a third party consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, such as incident handling, penetration testing, security audits and consulting, including expert advice, related to technical support (Article 2).

You might also want to explore

Get daily policy updates in your inbox

Choose the sectors and regulators you care about. We'll send only what matters to you.

No spam. Unsubscribe anytime.