On 13 September 2017, the European Commission published a joint communication outlining their views to build a strong cybersecurity for the EU. The document underlines how the growth of the cybersecurity market in the EU – in terms of products, services and processes – is prevented by the lack of cybersecurity certification schemes recognised across the EU to build higher standards of resilience into products and to underpin EU-wide market confidence. For this reason, the European Commission is working on a proposal to set up an EU cybersecurity certification framework.
Whereas certification is a key factor for IT security across value chains, Small Business Standards (SBS) acknowledges that the voluntary uptake of existing certification schemes among SMEs is
insufficient. This is certainly due to cultural issues such as the lack of awareness among the smaller organisations. However, other important factors that undermine the uptake of existing certification schemes are their excessive cost and complexity. Small businesses often perceive cyber security measures as too expensive to implement and/or admit their confusion regarding concrete implementation measures to take. There is a need to keep both the financial and administrative burdens to an acceptable level considering the size of the companies.