New cybersecurity requirements in the EU
In March 2025, the European Commission published a draft implementing regulation that formulated technical descriptions of the categories of products that are classified18 as important and critical and will be subject to the Union's cybersecurity requirements. The adoption of the draft is expected to increase the requirements and cost for companies to enter the European market.
Из выпуска мониторинга No. 3 (15), March 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The EU experience
In March 2025, the European Commission published a draft implementing regulation that formulated technical descriptions of the categories of products that are classified1 as important and critical and will be subject to the Union's cybersecurity requirements. The adoption of the draft is expected to increase the requirements and cost for companies to enter the European market.
The formation of cybersecurity requirements in the EU began as early as the adoption of the 2020 Cybersecurity Strategy. It was proposed to develop requirements for cyber risk management in companies and individual infrastructure facilities, as well as requirements for cybersecurity of end products (goods and software) used by companies and consumers. The increased focus on end products is due to the paradigm shift in data storage, processing and transmission: from storage and processing in centralized data warehouses to the development of edge computing, i.e. when data is processed directly on the device.
In October 2024, the EU adopted the Regulation on horizontal cybersecurity2 requirements, which requires all manufacturers and importers of goods with “digital elements” to implement product3 cybersecurity standards. Such goods include software or hardware products that have remote data processing functionality. In other words, any product that involves connection to the Internet (or other network) for data processing is subject to the regulation. The regulation covers both consumer products (e.g. smart home products) and industrial ones.
The Regulation identifies 3 categories of products that are subject to increased cybersecurity requirements:
1) Important products (class 1) - routers, password manager programs, VPNs, etc. Such products are subject to the requirements of compliance with the European cybersecurity standard, but without certification of such compliance, or, if there is no such standard, with the general requirements to be established by the EC.
2) Important products (Class 2) firewalls; hypervisors, etc. These products are also subject to compliance requirements, but compliance must be certified by a third-party organization (e.g., a business association).
3) Critical products - smart cards (bank cards; identity cards; cards used as electronic wallets or key storage devices), smart meter4 gateways used for electricity measurement, etc. These products are already subject to European Common Criteria (EUCC) certification requirements, which imply certification only by organizations that have received special accreditation from government agencies.
For the remaining product categories, the manufacturer will independently assess cybersecurity risks. The EC estimates that up to 90% of all products will fall into this category. The requirements of the regulation will come into effect from December 2027.
The draft implementing regulations published in March 2025 clarify what applies to certain products. This allows companies to better understand the requirements being imposed. For example, password managers include both software and hardware devices designed to store passwords.
The experience of Switzerland
In March 2025, Switzerland adopted a regulation that requires operators of critical infrastructure (energy and drinking water suppliers, transportation companies, cantonal and municipal administrations) to report cyber attacks to the National Cyber Security Center5 (NCSC) within 24 hours of discovery.
Cyberattacks that threaten the operation of critical infrastructure, leak or alter information, or are accompanied by extortion, threats or coercion are subject to mandatory reporting. Operators who fail to comply with the requirement may be fined.
After submitting the initial report within 24 hours of discovering the incident, organizations will have 14 days to complete their report about the incident.
It is noteworthy that a similar system has already been established in the EU, as we mentioned in Monitoring No. 3 for 2024. In addition, the EU regulation on digital elements described above also envisages the introduction of a system of notification by manufacturers of such products of identified vulnerabilities - the requirement will apply from September 2026.
The experience of Turkey,
Vietnam
In March 2025, Turkey's Cybersecurity Law came into force, stipulating obligations and measures for individual companies and government agencies to implement cybersecurity measures, including incident reporting, the ability to purchase certified6 cybersecurity products, and more.
The Vietnamese government has finalized a public consultation on requiring individual companies to implement a cyber risk management system, conduct regular security audits, and develop incident response plans to7 mitigate cyber threats.
Russia’s experience
In Russia, since 2017, the Law “On the Security of Critical Information Infrastructure” has been in force, which, as well as similar norms adopted in the EU, Switzerland and other countries, provides for a mechanism for reporting computer incidents and also requires to ensure the security of significant critical information infrastructure objects.
- https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng ↑
- https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202402847 ↑
- Software that filters incoming information and keeps out malicious content and viruses. ↑
- Software that is used to run multiple operating systems on a single device and is responsible for providing computing resources to each operating system during use. ↑
- A communication device capable of transmitting and receiving data for information, monitoring and control purposes. ↑
- https://www.admin.ch/gov/en/start/documentation/media-releases/media-releases-federal-council.msg-id-104400.html ↑
From the monitoring issue No. 3 (15), March 2025. Download the full issue (PDF) · issue page at the Gaidar Institute