Transatlantic Cooperation for Cybersecurity and a Safer Future for IoT Products

27 Feb, 2025
CyberSafe Products Action Plan - CRACoWi

In an era of growing cyber threats, the European Union and the United States have taken a major step toward enhancing global cybersecurity. On January 30, 2024, both sides signed an Administrative Arrangement on a Joint CyberSafe Products Action Plan, reinforcing their commitment to securing consumer IoT products. This collaboration aims to advance technical cooperation and work toward mutual recognition of cybersecurity requirements for IoT hardware and software, ultimately strengthening consumer protection while easing compliance for businesses.

This agreement builds on existing cybersecurity frameworks. In the EU, the Cyber Resilience Act (CRA) establishes security requirements for digital products, while in the U.S., the Cyber Trust Mark Program serves as a labeling system to help consumers identify secure IoT products. By aligning regulatory approaches, the EU and U.S. are working toward a seamless transatlantic market for trusted digital products, making it easier for companies to comply with consistent security standards while enhancing global cybersecurity.

As part of this initiative, both sides are committed to developing a shared cybersecurity lexicon and taxonomy, improving coordination in standards development, and exploring potential alignment of certification processes. The Action Plan highlights the importance of fostering collaboration between governments and industry players, ensuring that regulations remain effective and practical. European Commissioner Thierry Breton emphasized that this agreement brings “concrete benefits for consumers and businesses” and reinforces the shared commitment to strengthening cybersecurity across borders.

The CRACoWi project (Cyber Resilience Act Compliance Wizard) plays an essential role in supporting businesses – particularly SMEs – by helping them navigate cybersecurity regulations, assess compliance under the Cyber Resilience Act, and integrate security-by-design principles into IoT product development. By providing clear guidance on certification processes, CRACoWi ensures that companies can meet regulatory requirements without being overwhelmed by complexity.

With this agreement in place, the EU and U.S. are setting the stage for stronger cybersecurity cooperation. Their focus on harmonizing security standards, promoting international best practices, and fostering industry engagement will help shape a more resilient digital ecosystem. As the world becomes increasingly interconnected, initiatives like these are vital to ensuring the safety and trustworthiness of digital products.

You may also like

The Role of the EU Cyber Resilience Act and NIS2 Directive 

The Role of the EU Cyber Resilience Act and NIS2 Directive

The importance of cybersecurity has never been greater, especially in light of the evolving digital landscape and escalating cyber risks. Two major EU regulatory frameworks - the Cyber Resilience Act (CRA) and the NIS2 (Network and Information...

Lessons from Asia-Pacific VPN Exploits

Lessons from Asia-Pacific VPN Exploits

Ransomware operators are getting faster, stealthier, and more aggressive - and the cost of delayed action is growing. The recent article from CySecurity News highlights a troubling surge in ransomware and data exfiltration attacks across the Asia-Pacific region. Let`s...

WEBINAR: Threat Modelling under the Cyber Resilience Act

WEBINAR: Threat Modelling under the Cyber Resilience Act

📅 20 November 2025 | 14:00–15:00 CET | Online | English | Free Join us for the first CRACoWi project webinar with Katherine Leese from SevenShift, to explore a practical, evidence-based threat modelling process that aligns directly with the CRA’s risk-assessment and...

Understanding the US Cyber Trust Mark

Understanding the US Cyber Trust Mark

The United States is set to launch the US Cyber Trust Mark in 2025, a groundbreaking voluntary initiative aimed at enhancing the cybersecurity of wireless consumer IoT products sold in the U.S. market. This program marks a significant step in creating safer digital...

CRACoWi`s 2nd Plenary Meeting

CRACoWi`s 2nd Plenary Meeting

On February 12–13, 2025, the CRACoWi consortium convened in Düsseldorf, Germany, for its second Plenary Meeting - a key milestone in the project’s first year of implementation. The event brought together all 14 partners to evaluate progress, exchange insights, and...

Australia’s Landmark Cyber Security Bill 2024

Australia’s Landmark Cyber Security Bill 2024

On November 25, 2024, Australia passed the Cyber Security Bill 2024, ushering in a significant step forward in its efforts to enhance cybersecurity. At its core, this legislation sets mandatory security standards for "relevant connectable products," or smart devices,...

CRACoWi White Paper

CRACoWi White Paper

The digitalization of the global economy is driving a massive shift in consumer and business behaviors, creating an interconnected ecosystem of billions of devices and millions of applications. This exponential growth amplifies the importance of robust cybersecurity...