2025 European Cybersecurity Certification Conference - Part 4

2025 European Cybersecurity Certification Conference - Part 4

🎙 ENISAvideos 👥 4K 📅 August 22, 2025 ⏱ 73 min 👁 230 📄 conference panel discussion 🧭 2026-08-17
Available in: English (current) Français

Keywords

risk-based approachEUCCvulnerability handlingconformity assessmentcertification schemes

Summary

This panel discussion, part of the 2025 European Cybersecurity Certification Conference, focuses on how cybersecurity certification supports risk management. Moderator Eric Vetilar introduces the concept that certification demonstrates fulfillment of requirements derived from risk identification. Panelists include Sylvia Lu from ANSSI, Helga Kudsman from BSI, and Gabor Hornak from NXP. Sylvia Lu presents ANSSI’s certification and qualification schemes, including Common Criteria, CSPN, and various service schemes, emphasizing how they address different use cases such as protecting assets, sensitive data, and national security. Helga Kudsman discusses the importance of vulnerability handling post-certification, highlighting BSI’s efforts in patch management and quick re-certification processes. Gabor Hornak introduces the new EUCC guideline on vulnerability management and disclosure, detailing the process from initial investigation to remediation, with strict timelines and the possibility of extensions. The discussion then explores how certification helps in risk-based approaches, with examples of attack potential levels and the need for continuous risk assessment. The panel concludes that certification provides transparency and assurance, but risk owners must be educated and involved in managing vulnerabilities throughout the product lifecycle.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The panel provides valuable insights into the practical application of cybersecurity certification for risk management. The speakers, representing national authorities and industry, offer concrete examples of how certification schemes are designed to address specific risks, such as ANSSI’s qualification schemes for managed security services. The discussion on vulnerability handling is particularly valuable, as it addresses a critical gap in the certification lifecycle. The argumentation is solid, grounded in real-world experience and referencing official guidelines like the EUCC vulnerability handling guideline. However, the discussion remains at a high level, with limited quantitative analysis of risk reduction or cost-benefit. The panel effectively argues that certification is a risk-based tool, but does not delve into the challenges of quantifying risk in cybersecurity, which is acknowledged but not resolved.

Scientific Rigor, Source Quality, Title Accuracy

The content demonstrates high scientific rigor, with panelists citing official frameworks and guidelines such as the EUCC, Common Criteria, and NIS2. The sources are authoritative, coming from national cybersecurity agencies and industry experts. The title accurately reflects the content, as it is a recording of a conference session. The discussion is well-structured, with each speaker providing expertise on their respective areas. The panel does not explicitly cite external sources, but the references to EUCC guidelines and standards are implicit. The adequacy between title and content is strong, as the video is clearly part of a series covering the conference. Overall, the scientific quality is high, with no evident biases or unsupported claims.

252 words

Title / Content Match

Title accurately reflects content: a recorded session from the 2025 European Cybersecurity Certification Conference.

Quality & Reliability

8/10

Panel of experts from national authorities (ANSSI, BSI) and industry (NXP) discussing risk-based approach in cybersecurity certification, referencing official EUCC guidelines and processes. High expertise, but limited depth due to time constraints.

Key Moments

Cited Sources

  • EUCC vulnerability handling guideline — Referenced by Gabor Hornak as a public guideline on vulnerability management and disclosure for EUCC.

Concurring Sources

  • ENISA Cybersecurity Certification — Supports the discussion on EUCC and certification schemes.

Contribution & Novelties

The panel provides an original perspective on integrating risk management into cybersecurity certification, particularly through the new EUCC vulnerability handling guideline. It highlights the importance of post-certification vulnerability management, a topic often overlooked. The discussion offers practical insights from national authorities and industry, emphasizing the need for continuous risk assessment and the involvement of risk owners.

Pour aller plus loin :

  • EUCC scheme — Official information on the European Cybersecurity Certification scheme.
  • Common Criteria — International standard for IT security certification.
  • NIS2 Directive — EU legislation on cybersecurity measures.

89 words

Radar Profile

The radar profile shows high scores in quality and reliability, with moderate scores in quantity and technical level. This indicates a focused, expert discussion with limited breadth but strong depth in specific areas.

Reliability 8/10