Positions and publications

We share our knowledge and take part in public consultations, national and European, from the perspective of small and medium-sized organisations and the healthcare sector.

We prepare expert content independently of our commercial offer. When a topic concerns ShieldNet, we say so.

Positions

  • Publication date: April 2026

    Cross-border identification and authentication (EHDS)

    English

    Draft Commission Implementing Regulation on an Interoperable, Cross-Border Identification and Authentication Mechanism for Natural Persons, Health Professionals and Healthcare Providers for the Purposes of the Cross-Border Exchange of Personal Electronic Health Data

    A consultation position paper on the draft Commission implementing regulation on the cross-border identification and authentication mechanism for the exchange of electronic health data under EHDS, contributing the perspective of practical IAM implementation in healthcare. It highlights areas needing clarification, such as representation and legal guardianship, attribute protection, proportionality for smaller entities and operational resilience.

  • Publication date: April 2026

    MyHealth@EU

    English

    Draft Commission Implementing Regulation on MyHealth@EU

    A consultation position paper on the draft Commission implementing regulation on MyHealth@EU, assessing the draft positively and offering recommendations in the areas of greatest operational and security significance, such as requirements for national contact points, response to critical incidents, cryptography and proportionality for less mature national systems. Useful for organisations involved in work on cross-border health data exchange.

  • Publication date: March 2026

    ENISA standardisation and SMEs

    English

    Statement on the ENISA Ad Hoc Working Group on Cybersecurity Standardization

    Position on the composition of the ENISA ad hoc working group on cybersecurity standardisation and the representation of small and medium-sized enterprises.

  • Publication date: March 2026

    Reform of the Cybersecurity Act (CSA2)

    English

    IS Consulting Position on the Proposed Reform of the Cybersecurity Act (CSA2)

    A position paper contributing to the discussion on the reform of the Cybersecurity Act (CSA2), setting out four principles (proportionality and a risk-based approach, certification as a mechanism that facilitates compliance, consistency of the EU regulatory framework, technological neutrality) from the perspective of SME feasibility. Useful for consultation participants and organisations following the development of European certification frameworks.

  • Publication date: 2025

    Cybersecurity Strategy of the Republic of Poland

    Polish

    Strategia Cyberbezpieczeństwa Rzeczypospolitej Polskiej. Wnioski i Rekomendacje

    A consultation contribution to the draft Cybersecurity Strategy of the Republic of Poland, analysing the draft's provisions regarding the separation of state roles (regulator, integrator, trust operator) and the risk of crowding out the commercial services market, with proposals for instruments strengthening demand and feasibility in the SME segment. It brings the market and SME perspective to the debate on national cybersecurity policy.

Analyses

  • Publication date: June 2025

    EU Cyber Resilience Act: Impact on Healthcare Supply Chain

    English

    An analysis of the impact of the CRA regulation on the healthcare supply chain, covering vulnerabilities in medical devices and software, the obligations of four stakeholder groups (device manufacturers, pharmaceutical distributors, smart pharmacies, IT suppliers), the tiered conformity assessment system and links to MDR, NIS2, GDPR and EHDS. Useful for healthcare entities and their suppliers preparing for CRA requirements ahead of 2027.

  • Publication date: May 2025

    Navigating EU Cybersecurity Laws: A Comprehensive Guide for SMEs

    English

    A cross-cutting guide to the EU cybersecurity regulatory landscape (GDPR, NIS2, DORA, CRA, AI Act, sector-specific rules) from the SME perspective, including a timeline of key deadlines, a twelve-month implementation roadmap, compliance checklists and a regulatory map. Useful for SME owners and managers and for compliance officers who want to establish which rules apply to them and how to prepare.

  • Publication date: April 2025

    NIS2 & CRA: New EU Regulations, New Opportunity?

    Polish

    An analysis of the impact of the NIS2 directive and the CRA regulation on Polish small and medium enterprises and non-governmental organisations, covering benefits, costs, risks, indirect obligations arising from the supply chain and practical preparation steps. Useful for boards and staff of SMEs and NGOs assessing the scope of their obligations and planning implementation.

Reports

  • Publication date: June 2026

    ASCLEPIUS: activity report

    Report from a Digital Europe co-funded project: training, phishing tests, maturity assessments and supplier evaluation in six healthcare organisations.