The European Commission has issued a call for evidence and public consultation on a proposal for a regulation on horizontal cybersecurity requirements for digital products and ancillary services (an EU "Cyber Resilience Act"). This Act would complement the Network and Information Systems Directive and the Cybersecurity Act and would establish streamlined and harmonised requirements for the cybersecurity of digital products (both tangible and intangible) and ancillary services across their whole life cycle.

At this stage, the European Commission is considering alternative policy options – namely:

  • to maintain the status quo;
  • to introduce voluntary measures;
  • ad hoc regulatory intervention;
  • a mixed approach of mandatory and soft rules; or
  • a horizontal regulatory intervention (ie, the Cyber Resilience Act).

The call for evidence and consultation close on 25 May 2022.

For further information on this topic please contact Michael Bahar or Paula Barrett at Eversheds Sutherland by telephone (+44 20 7919 4500) or email ([email protected] or [email protected]). The Eversheds Sutherland website can be accessed at