While there is broad agreement on the objectives of the CSA2 proposal, there are still many important questions regarding its scope, the threats it seeks to address, the associated compliance requirements, and its practical implementation. Especially Title IV of the CSA2 raises several key issues that this event aims to explore.
How can ICT supply chain risks be effectively identified, assessed, and managed through evidence-based risk governance? Based on such an approach, how should high-risk vendors be identified? What constitutes a secure solution, and what does not? Which equipment or services may need to be replaced, by when, and on what grounds? What alternative measures could mitigate identified risks, and how would these interact with existing European and national regulatory frameworks? How can trusted suppliers be identified, and what supply chain challenges may arise when substituting equipment and services? Finally, what impact could these measures have on the EU's ability to achieve its Digital Decade goals?
Markéta Gregorová MEP and EIF Member
Marc Vancoppenolle, Vice President, Nokia
Katarzyna Prusak-Górniak, Head of Digital Affairs Section, cybersecurity and cyber diplomacy, Polish Representation to the European Union
Rita Jonusaite, Government Affairs & Public Policy Manager, Google
Pinar Serdengecti, Senior Policy Director, Connect Europe