Skip to main navigation Skip to search Skip to main content

Harmonised standards as empirically informed regulation: lessons from cybersecurity

Activity: Talk or presentation typesInvited talkScientific

Description

This lecture investigates standardisation as an empirically informed mode of regulation in the context of European cybersecurity law. Building on recent developments surrounding the EU Cyber Resilience Act, it examines how technical standards are mobilised as regulatory instruments to achieve legally binding objectives across the digital single market. Using cybersecurity as a case study, the lecture highlights the challenges of entrusting European Standardisation Organisations with quasi-regulatory functions, particularly in relation to legitimacy, inclusiveness, and accountability. It argues that while standardisation can complement legislation by providing flexible, evidence-based solutions, it also raises critical questions of democratic oversight, institutional balance, and stakeholder participation.

Ultimately, the lecture situates cybersecurity standardisation within broader debates on the use of private rule-making to pursue public policy goals, offering insights into how law and regulation may adapt to technological complexity while safeguarding principles and values.
Period15 Oct 2025
Held atUniversity of Luxembourg, Luxembourg
Degree of RecognitionInternational