#E2025J0022EFTA Court Finds Norway Failed to Implement the EU Cybersecurity Act
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
Norway must bring the EU Cybersecurity Act into its national legal system. The EFTA Court found that Norway failed to adopt the required measures under the EEA Agreement, including rules linked to ENISA and cybersecurity certification for information and communications technology. The decision mainly matters for Norwegian authorities and businesses in electronic communications, audiovisual services, digital services, and ICT markets. It signals that Norway is behind on aligning with EEA cybersecurity obligations and may need to move quickly to create the legal basis for EU-style cybersecurity certification.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Confirms that Norway failed to implement Regulation (EU) 2019/881 into national law
- Requires Norway to align its legal framework with EEA cybersecurity obligations
- Orders Norway to pay the costs of the proceedings
Obligations
What this law requires
The EFTA Court concluded that Norway failed to make Regulation (EU) 2019/881 on ENISA and ICT cybersecurity certification, as adapted for the EEA Agreement, part of its internal legal order as required by Article 7 of the EEA Agreement.
The judgment records that Regulation (EU) 2019/881 concerns ENISA and the framework for information and communications technology cybersecurity certification; Norway was required to incorporate that EEA-relevant act into national law.
The Court ordered Norway to bear the costs of the infringement proceedings brought by the EFTA Surveillance Authority.