REGULATION (EU) 2025/37 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL | 32025R0037 — European Union law | Esheria

REGULATION (EU) 2025/37 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

This regulation amends the EU cybersecurity certification framework to cover managed security services and adds rules for certification, security objectives, and ENISA/Commission procedures.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Regulation
Citation
32025R0037
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
ICT products and services certification conformity assessment consultancy conflicts cybersecurity governance managed security services testing laboratories

Publicly available, excluded from search-engine indexing

This page remains available for direct access and API use, but this release emits noindex,follow for the following reason:

  • The record does not meet this release's canonical indexing criteria. (market-indexing-disabled)

Statute overview

About this statute

This regulation amends the EU cybersecurity certification framework to cover managed security services and adds rules for certification, security objectives, and ENISA/Commission procedures. Conformity assessment bodies, their top management, and relevant staff must avoid activities that could compromise their independence or integrity, including consultancy services.