The New EU Digital Reality: A Guide to the 2026 ICT Standardisation Rolling Plan, Trusted Chips, and the Trust in Media Mandate
The European Commission's 2026 ICT Standardisation Rolling Plan introduces mandatory technical frameworks for hardware security and media authenticity, effectively accelerating the compliance timeline for global tech manufacturers.
- Hardware Manufacturers
- Companies designing and fabricating microchips and connected devices.
- Media Producers and Platforms
- Organizations creating and distributing digital content.
- European Policymakers
- EU regulators and standardisation bodies.
At a glance
- The 2026 ICT Standardisation Rolling Plan translates EU digital laws into mandatory engineering standards.
- Three new chapters focus on Trusted and Secure Chips, Trust in Media, and Internet protocols.
- Hardware manufacturers must adopt standards like SESIP now to meet the 2027 Cyber Resilience Act deadline.
- Media platforms must integrate JPEG Trust frameworks to verify content provenance under the AI Act.
- The plan effectively pulls the compliance window forward, forcing global supply chains to adapt immediately.
What most technology executives get wrong about European digital regulation is treating the enforcement dates as their engineering deadlines. They look at the Cyber Resilience Act (CRA) or the AI Act, see enforcement windows stretching into late 2027 or 2028, and assume they have years to adapt their product architectures. The evidence says otherwise. The European Commission's release of the 2026 ICT Standardisation Rolling Plan effectively pulls the compliance window forward to today, dictating the exact engineering standards required to sell into the EU market.[1][2]
For companies manufacturing connected hardware or distributing digital media, the 2026 Rolling Plan marks a critical and immediate shift from abstract policy to concrete implementation. Because hardware and software certification processes take months or even years, the technical standards codified in this plan must be integrated into product development cycles immediately. Waiting for the headline enforcement dates of the underlying laws guarantees that engineering teams will be too far behind to certify their products in time, effectively locking them out of the European Single Market.[1]
The 2026 edition of the Rolling Plan is the most comprehensive to date, expanding to cover approximately 260 standardisation actions across 40 technological domains. It serves as the definitive bridge between EU digital policy objectives and the technical work carried out by European and international standards development organizations like CEN, CENELEC, and ISO. By consolidating these requirements into a single, actionable roadmap, the Commission provides a clear blueprint for how abstract legal concepts like 'cybersecurity-by-design' translate into measurable engineering specifications.[1][2][3]
Crucially, the 2026 update introduces three entirely new chapters that fundamentally alter the compliance landscape: Trusted and Secure Chips (Chapter 3.1.12), Internet (Chapter 3.1.13), and Trust in Media (Chapter 3.2.9). These additions are not mere suggestions; they form the technical bedrock for complying with sweeping regulations. They reflect an increasing policy focus on security, resilience, and trust as the foundational elements of Europe's digital transformation, moving beyond basic data protection into the physical and cryptographic layers of technology.[1][2]
The 'Trusted and Secure Chips' mandate addresses a glaring vulnerability in the global supply chain: hardware-level security. As microchips become the foundation for critical infrastructure, automated vehicles, cloud computing, and defense systems, the EU is demanding verifiable trustworthiness from the silicon up. The increasing complexity involved in the development, integration, and post-deployment use of microelectronics presents new security risks that cannot be patched with software alone, necessitating a unified, standardized approach to hardware resilience across the entire European ecosystem.[4]
Under the umbrella of the European standardization organizations CEN and CENELEC, the 'Trusted Chips' project—led by the German Commission for Electrical, Electronic & Information Technologies (DKE)—aims to define cybersecurity, authenticity, and reliability requirements for advanced chips. The goal is to establish a shared definition of what makes a microchip trustworthy. This involves creating a roadmap that identifies standardisation gaps and proposes concrete measures for a unified certification process, ensuring that chips reliably perform their intended functions without hidden vulnerabilities.[4]
This hardware standardisation directly supports the Cyber Resilience Act (CRA), which mandates that digital products remain secure throughout their lifecycle. With the CRA applying from December 11, 2027, chip designers must integrate standards like SESIP (Security Evaluation for IoT Products) now to ensure their hardware can be certified in time. The CRA promotes a cybersecurity-by-design and cybersecurity-by-default approach, and the Trusted Chips initiative provides the exact technical specifications required to prove that these legal obligations have been met at the device level.[1][4]
The standardisation effort seeks to establish a rigorous compliance process that enables third-party assessment of CRA compliance for microcontrollers and microprocessors. By defining these requirements at the hardware level, the EU is forcing global semiconductor manufacturers to adapt their fabrication processes if they wish to sell into the European Single Market. This includes developing technical specifications for anti-counterfeit controls in design, verification, and packaging, as well as ensuring complete, verifiable traceability throughout the entire semiconductor supply chain from foundry to final integration.[4]
The second major pillar of the 2026 plan is the 'Trust in Media' mandate. Driven by the rapid proliferation of generative AI and the escalating threat of deepfakes, this chapter focuses on establishing verifiable content provenance and authenticity across the digital ecosystem. While automated detection methods can provide some insights, they cannot offer trustworthy and comprehensive information about the origin of media assets, prompting the EU to mandate secure, interoperable annotations that travel with the content itself from the moment of creation.[1][2]
The second major pillar of the 2026 plan is the 'Trust in Media' mandate.
Different EU legal acts, notably the AI Act and the Data Act, underline the urgent need for robust media trust standards. The Rolling Plan points directly to frameworks like JPEG Trust (ISO/IEC 21617), which provides a standardized method for securely annotating media assets throughout their lifecycle. This framework was born out of the initial JPEG Fake Media exploration and has since evolved into a comprehensive international standard designed to establish verifiable trust in media production, distribution, and consumption across various digital platforms.[1][5]
JPEG Trust establishes a framework for authenticity, provenance, attribution, and intellectual property rights. By embedding cryptographic provenance into the media files themselves, the EU aims to create an interoperable ecosystem where consumers and platforms can instantly verify the origin and integrity of an image or video. Because the framework is built in compliance with well-established JPEG standards, it ensures a smooth integration into existing digital media ecosystems, allowing for secure and reliable annotation without breaking legacy viewing software.[1][5]
This means that media producers, news organizations, and social platforms must begin adopting these cryptographic standards to comply with the transparency requirements of the AI Act and the European Media Freedom Act. The technical infrastructure for media trust is being laid down now, and platforms that fail to integrate it will struggle to meet future regulatory audits. The mandate shifts the burden of proof from post-publication detection to pre-publication cryptographic signing, fundamentally altering how digital media is handled.[1][5]
The Rolling Plan also elevates the 'Internet' to its own domain (Chapter 3.1.13), focusing on foundational protocols to ensure an open, resilient, and interoperable web architecture. This move is designed to counter the threat of digital fragmentation and ensure that the core infrastructure of the internet aligns with European values of privacy and security. By standardizing these foundational protocols, the EU aims to protect the underlying mechanics of the web from being co-opted by proprietary or non-transparent standards.[2][3]
Furthermore, foundational drivers like the Data Economy and Cybersecurity have been extensively revised in the 2026 edition. The Data Act, which entered into force in 2025, requires robust standards for data interoperability and the creation of common European data spaces. As data flows become increasingly critical to the European economy, standards for data sharing frameworks and internal data governance are being heavily prioritized to ensure that data can move securely and seamlessly across borders and industrial sectors without compromising privacy.[1][2]
To support this massive data initiative, technical committees like JTC 25 are actively developing harmonized standards on Trusted Data Transactions, specifically the EN 18235 series. These standards cover critical terminology, trustworthiness requirements, and quality frameworks for internal data governance, providing the foundational layer upon which sector-specific trust mechanisms can be built. This ensures that when companies participate in European data spaces, they are relying on a standardized maturity assessment that guarantees the quality, provenance, and security of the data being exchanged.[1]
The European Multi-Stakeholder Platform on ICT Standardisation (MSP), which advises the Commission, ensures that these standards are practical but rigorous. By bringing together industry representatives, public authorities, and civil society, the MSP helps identify standardisation gaps and priorities that directly support the implementation of EU legislation. This collaborative approach ensures that the resulting standards are not just theoretical exercises, but actionable engineering guidelines that can be realistically implemented by small and medium-sized enterprises as well as multinational corporations.[1][3]
The primary uncertainty in this regulatory landscape is the speed of standard development versus the relentless pace of technological innovation. While the Rolling Plan sets clear objectives, the actual drafting of technical specifications by bodies like CEN and CENELEC can face unforeseen delays, potentially squeezing the compliance window even further for manufacturers waiting for final guidelines. Companies must therefore actively participate in or closely monitor these standardisation working groups, rather than passively waiting for the final documents to be published, to ensure their R&D remains aligned.[6]
Ultimately, the 2026 Rolling Plan represents the EU's transition from rule-maker to standard-setter. By defining the technical reality of trusted hardware, verifiable media, and secure data spaces, Europe is exporting its digital values globally. This phenomenon, often referred to as the 'Brussels Effect,' means that international supply chains will inevitably adapt to the EU's baseline. For global technology companies, the engineering requirements for the next decade of digital innovation are being written in Europe today, and compliance begins immediately.[6]
Terms to know
- ICT Standardisation Rolling Plan
- An annual European Commission document that links EU digital policies to concrete technical standardisation actions.
- Cyber Resilience Act (CRA)
- An EU regulation mandating cybersecurity-by-design for all products with digital elements, enforceable from December 2027.
- SESIP
- Security Evaluation for IoT Products, a standard used to assess and certify the security of microcontrollers and microprocessors.
- JPEG Trust (ISO/IEC 21617)
- An international standard framework for securely annotating media assets to establish authenticity and provenance.
- CEN/CENELEC
- The European Committee for Standardization and the European Committee for Electrotechnical Standardization, responsible for drafting technical standards.
Sources
[1]European CommissionEuropean PolicymakersRolling Plan 2026 for ICT Standardisation
Read on European Commission →
[2]INSTAR StandardsMedia Producers and PlatformsThe European Commission Publishes the Rolling Plan for ICT Standardisation 2026
Read on INSTAR Standards →
[3]European DIGITAL SME AllianceHardware ManufacturersRolling Plan 2026 for ICT Standardisation: strengthening the link between policy and implementation
Read on European DIGITAL SME Alliance →
[4]VDEHardware ManufacturersTrusted Chips: Standardization and certification of tamper-proof microprocessors
Read on VDE →
[5]ZenodoMedia Producers and PlatformsTowards an international standard to establish trust in media production, distribution and consumption
Read on Zenodo →
[6]Factlen Editorial TeamEuropean PolicymakersSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.

