Governing Trust: Cybersecurity Certification and Regulatory Power in the European Union and China

Governing Trust: Cybersecurity Certification and Regulatory Power in the European Union and China

Authors

  • Xiaoyu Gu University College London

DOI:

https://doi.org/10.66069/ojspub.26820805

Keywords:

Cybersecurity certification, Regulatory power, Standards governance, Technological trust, Digital sovereignty, European Union, China

Abstract

Cybersecurity certification has become an increasingly important mechanism for governing digital technologies and infrastructures. Although commonly understood as a technical process for evaluating security performance, certification increasingly determines which technologies, suppliers, and infrastructures are recognised as trustworthy. This article argues that cybersecurity certification should be understood as a form of governance infrastructure through which technological trust is institutionally produced. Building on research on regulatory power, standards governance, and digital sovereignty, the article develops a framework of technological trust governance centred on three dimensions: trust definition, trust verification, and trust diffusion. Through a comparative analysis of the European Union and China, the article identifies two distinct pathways through which regulatory power operates in digital governance. The European Union represents a model of market-mediated trust governance, where cybersecurity certification frameworks transform regulatory objectives into technical requirements and create incentives for external compliance through market access. China represents a model of state-coordinated trust governance, where cybersecurity standards are mobilised through institutional coordination, industrial alignment, and technological ecosystem embedding. The article contributes to debates on digital governance by demonstrating that competition over cybersecurity is not only a contest over technologies or standards, but also over the institutional authority to define and govern technological trust.

References

Bradford, A. (2020). The Brussels effect: How the European Union rules the world. Oxford University Press.

Brunsson, N., Rasche, A., & Seidl, D. (2012). The dynamics of standardization: Three perspectives on standards in organization studies. Organization Studies, 33(5-6), 613-632. https://doi.org/10.1177/0170840612443620

Büthe, T., & Mattli, W. (2011). The new global rulers: The privatization of regulation in the world economy. Princeton University Press.

Common Criteria Recognition Arrangement. (n.d.). Common Criteria Recognition Arrangement.

Drezner, D. W. (2007). All politics is global: Explaining international regulatory regimes. Princeton University Press.

Ernst, D. (2011). Indigenous innovation and globalization: The challenge for China's standardization strategy. East-West Center.

European Union. (2019). Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act). Official Journal of the European Union, L 151, 15-69.

European Union Agency for Cybersecurity. (2024). EUCC: European Common Criteria-based cybersecurity certification scheme.

European Union Agency for Cybersecurity. (n.d.). European cybersecurity certification framework.

European Union Agency for Cybersecurity. (n.d.). European cybersecurity certification scheme for cloud services (EUCS) [Candidate scheme documentation].

Farrell, H., & Newman, A. L. (2019). Weaponized interdependence: How global economic networks shape state coercion. International Security, 44(1), 42-79. https://doi.org/10.1162/isec_a_00351

International Organization for Standardization. (2019). ISO/IEC 15408: Information technology-Security techniques-Evaluation criteria for IT security.

Kim, S., Lee, H., Kwak, J., & Seo, J. (2014). China's information security standardization: Analysis from the perspective of technical barriers to trade principles. Telecommunications Policy, 38(10), 909-921.

Larkin, B. (2013). The politics and poetics of infrastructure. Annual Review of Anthropology, 42, 327-343. https://doi.org/10.1146/annurev-anthro-092412-155522

Mattli, W., & Woods, N. (Eds.). (2009). The politics of global regulation. Princeton University Press.

National Information Security Standardization Technical Committee. (n.d.). National cybersecurity standards documents [Institutional materials].

Plantin, J.-C., Lagoze, C., Edwards, P. N., & Sandvig, C. (2018). Infrastructure studies meet platform studies in the age of Google and Facebook. New Media & Society, 20(1), 293-310. https://doi.org/10.1177/1461444816661553

Radu, R. (2019). Negotiating Internet governance. Oxford University Press.

Sivan-Sevilla, I. (2021). Europeanisation on demand: The EU cybersecurity certification regime between market integration and core state powers. Journal of Public Policy, 41(3), 570-593. https://doi.org/10.1017/S0143814X20000099

Downloads

Published

2026-08-31

Issue

Section

Articles
Loading...