Full text
D6.2 Socio-Economical sustainability analysis ecosystem report Work package WP6: Dissemination, Communication and Business Planning Task Task 6.1: Market Analysis and Strategy Definition Task 6.2: Socio-Economical Sustainability Analysis and COBALT Ecosystem Business Models and Uptake Roadmap Editor Rafaella Elia (eBOS) Authors Rafaella Elia, Sozos Karageorgiou (eBOS) Luna Garcia Jesus (BOSCH) Valentin Acker, Singh Harshit Kumar (BGSG) Anjan Chatterjee (TUV) Ricard Vilalta, Raul Muñoz (CTTC) Sotirios Nakos (PRACTIN) Raisia Gorbunov (INQBIT) Ioannis Koufos (NCSRD) Adrian Asensio, Xavi Masip, Jordi Forné (UPC) Ayman Khalil (RAL) Pedro Ruzafa Alcázar (UMU) Dissemination level PU Status Final Due date 28/02/2025 Document date 28/02/2025 Version number 1.0 Reviewers Sotirios Nakos (PRACTIN), George Xilouris (NCSRD) Co-funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union. Neither the European Union nor the granting authority can be held responsible for them. Ref. Ares(2025)1871439 - 08/03/2025
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 2 REVISION AND HISTORY CHART Version Date Main author Summary of changes 0.1 10/09/2024 Rafaella Elia (eBOS) ToC created and added initial content to all chapters and sections. 0.2 10/12/2024 Luna Garcia Jesus (BOSCH), Adrian Asensio, Xavi Masip, Jordi Forné (UPC), Ayman Khalil (RAL) Added content in Chapters 4 and 6. 0.3 20/12/2024 Anjan Chatterjee (TUV), Pedro Ruzafa Alcázar (UMU), Valentin Acker, Singh Harshit Kumar (BGSG) Added content in Chapters 4 and 6. 0.4 10/01/2025 Sotirios Nakos (PRACTIN), Raisia Gorbunov (INQBIT), Ioannis Koufos (NCSRD) Added content in Chapters 4 and 6. 0.5 06/02/2025 Rafaella Elia (eBOS) Updated ToC, Add content for Chapter 7. 0.6 13/02/2025 Rafaella Elia (eBOS) Finalized content. 0.7 14/02/2025 Rafaella Elia (eBOS) Finalized editing. Version ready for peer review. 0.8 14/02/2025 Rafaella Elia (eBOS) Final corrections 0.9 24/02/2025 Rafaella Elia (eBOS) Modifications after peer review suggestions 1.0 28/02/2025 George Xylouris Final submitted version 2.0 00/00/0000
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 3 TABLE OF CONTENTS REVISION AND HISTORY CHART 2 TABLE OF CONTENTS 3 INDEX OF FIGURES 6 INDEX OF TABLES 7 LIST OF ABBREVIATIONS AND ACRONYMS 7 EXECUTIVE SUMMARY 10 INTRODUCTION 10 1.1 PURPOSE OF THE REPORT 10 1.2 SCOPE AND OBJECTIVES 10 1.3 METHODOLOGY 11 1.4 STRUCTURE OF THE REPORT 11 2 PROJECT BACKGROUND 13 2.1 OVERVIEW OF THE PROJECT 13 2.2 IMPORTANCE OF CYBERSECURITY IN THE CURRENT SOCIO-ECONOMIC CONTEXT 14 2.3 OVERVIEW OF THE CERTIFICATION FRAMEWORK LANDSCAPE 15 3 MARKET ANALYSIS 16 3.1 OVERVIEW OF THE CYBERSECURITY CERTIFICATION MARKET 16 3.2 KEY MARKET DRIVERS 16 3.3 MARKET SEGMENTATION AND TARGET INDUSTRIES 17 3.4 COMPETITIVE LANDSCAPE 18 3.4.1 OVERVIEW OF THE CYBERSECURITY CERTIFICATION MARKET 18 3.4.2 KEY COMPETITORS AND INITIATIVES 19 3.4.3 COMPETITIVE ADVANTAGES OF COBALT 23 3.4.4 GAPS IN THE COMPETITIVE LANDSCAPE 24 3.4.5 OPPORTUNITIES 24 3.5 BARRIERS TO ADOPTION AND CHALLENGES 25 3.6 MARKET OPPORTUNITIES FOR COBALT 26 4 STRATEGIC ANALYSES 27
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 4 4.1 SWOT ANALYSIS 27 4.1.1 SDT AND SDT MANAGER 27 4.1.2 CCM MANAGER 28 4.1.3 ECLIPSE QRISP 29 4.1.4 SECURITY METRICS AND SECURITY CONTROLS FOR AI 30 4.1.5 AI MODEL AND AI SUPPLY CHAIN VULNERABILITY ASSESSMENT 31 4.1.6 INTERLEDGER BLOCKCHAIN PLATFORM FOR CROSS-BORDER CERTIFICATION 32 4.1.7 RISK EVALUATION FRAMEWORK 33 4.1.8 COBALT UNIFIED CERTIFICATION FRAMEWORK 34 4.1.9 PREDICTIVE MAINTENANCE 35 4.1.10 CLOUDITOR 36 4.1.11 IDS CONNECTOR 37 4.2 PESTEL ANALYSIS 38 4.2.1 SDT AND SDT MANAGER 38 4.2.2 CCM MANAGER 39 4.2.3 ECLIPSE QRISP 40 4.2.4 SECURITY METRICS AND SECURITY CONTROLS FOR AI 41 4.2.5 AI MODEL & AI SUPPLY CHAIN VULNERABILITY ASSESSMENT 42 4.2.6 INTERLEDGER BLOCKCHAIN PLATFORM 43 4.2.7 RISK EVALUATION FRAMEWORK 44 4.2.8 COBALT UNIFIED CERTIFICATION FRAMEWORK 45 4.2.9 PREDICTIVE MAINTENANCE 46 4.2.10 CLOUDITOR 47 4.2.11 IDS CONNECTOR 48 4.3 COST-BENEFIT ANALYSIS 49 4.3.1 SDT AND SDT MANAGER 49 4.3.2 CCM MANAGER 50 4.3.3 ECLIPSE QRISP 51 4.3.4 SECURITY METRICS AND SECURITY CONTROLS FOR AI 52 4.3.5 AI MODEL AND AI SUPPLY CHAIN VULNERABILITY ASSESSMENT 53 4.3.6 INTERLEDGER BLOCKCHAIN PLATFORM 54 4.3.7 RISK EVALUATION FRAMEWORK 55 4.3.8 COBALT UNIFIED CERTIFICATION FRAMEWORK 56 4.3.9 PREDICTIVE MAINTENANCE 57 4.3.10 CLOUDITOR 58 4.3.11 IDS CONNECTOR 59 4.4 COST-EFFECTIVENESS ANALYSIS 60 4.4.1 SDT AND SDT MANAGER 60 4.4.2 CCM MANAGER AND CCL 61 4.4.3 ECLIPSE QRISP 62 4.4.4 SECURITY METRICS AND SECURITY CONTROLS FOR AI 63 4.4.5 AI MODEL AND AI SUPPLY CHAIN VULNERABILITY ASSESSMENT 64 4.4.6 INTERLEDGER BLOCKCHAIN PLATFORM 65 4.4.7 RISK EVALUATION FRAMEWORK 66 4.4.8 COBALT UNIFIED CERTIFICATION FRAMEWORK 67
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 5 4.4.9 PREDICTIVE MAINTENANCE 68 4.4.10 CLOUDITOR 69 4.4.11 IDS CONNECTOR 70 5 SOCIO-ECONOMIC IMPACT ANALYSIS 71 5.1 ECONOMIC IMPACT 71 5.2 SOCIAL IMPACT 71 5.3 ENVIRONMENTAL IMPACT 72 6 BUSINESS MODELS FOR COBALT ECOSYSTEM 73 6.1 OVERVIEW OF COBALT BUSINESS MODEL 73 6.2 BUSINESS MODEL CANVAS OF THE SDT AND THE SDT MANAGER 74 6.3 BUSINESS MODEL CANVAS OF THE CCM AND THE CCL 74 6.4 BUSINESS MODEL CANVAS OF THE ECLIPSE QRISP 75 6.5 BUSINESS MODEL CANVAS OF THE SECURITY METRICS AND SECURITY CONTROLS FOR AI 76 6.6 BUSINESS MODEL CANVAS OF THE AI MODEL AND AI SUPPLY CHAIN VULNERABILITY ASSESSMENT 76 6.7 BUSINESS MODEL CANVAS OF THE INTERLEDGER BLOCKCHAIN PLATFORM 77 6.8 BUSINESS MODEL CANVAS OF THE RISK EVALUATION FRAMEWORK 78 6.9 BUSINESS MODEL CANVAS OF THE COBALT UNIFIED CERTIFICATION FRAMEWORK 78 6.10 BUSINESS MODEL CANVAS OF THE PREDICTIVE MAINTENANCE 79 6.11 BUSINESS MODEL OF THE CLOUDITOR 80 6.12 BUSINESS MODEL CANVAS OF THE IDS CONNECTOR 80 7 INTELLECTUAL PROPERTY RIGHTS (IPR) 82 7.1 IPR MANAGEMENT 82 7.2 IPR MANAGEMENT OBJECTIVES 82 7.3 IPR MANAGEMENT METHODOLOGY 82 7.4 IPR CONSIDERATIONS FOR KEY INNOVATIONS 83 8 SUSTAINABILITY ROADMAP 84 8.1 ADOPTION AND UPTAKE ROADMAP 84 8.1.1 STRATEGIES FOR ENCOURAGING ADOPTION IN KEY SECTORS 84 8.1.2 TIMELINE AND MILESTONES FOR WIDESPREAD UPTAKE 84 8.2 ALIGNMENT WITH EU POLICY GOALS AND GLOBAL STANDARDS 86 8.2.1 EU DIGITAL POLICY INTEGRATION 86 8.2.2 ADAPTING COBALT TO GLOBAL CERTIFICATION STANDARDS 87 8.2.3 CONTRIBUTION TO GLOBAL CYBERSECURITY HARMONIZATION 88 8.3 MONITORING AND EVALUATION 88 9 SUMMARY OF FINDINGS AND RECOMMENDATIONS 89
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 6 9.1 SUMMARY OF KEY FINDINGS 89 9.2 STRATEGIES FOR ENHANCING SOCIO-ECONOMIC SUSTAINABILITY 89 9.3 FUTURE RESEARCH AND DEVELOPMENT AREAS 91 CONCLUSIONS 92 REFERENCES 93 INDEX OF FIGURES Figure 1: COBALT Business Model Canvas 73 Figure 2: SDT and SDT Manager Business Model Canvas 74 Figure 3: CCM and CCL Business Model Canvas 75 Figure 4: Eclipse Qrisp Business Model Canvas 75 Figure 5: Security Metrics and Security Controls for AI Business Model Canvas 76 Figure 6: AI Model and AI Supply Chain Vulnerability Assessment for AI Business Model Canvas 77 Figure 7: Interledger Blockchain Platform Business Model Canvas 77 Figure 8: Risk Evaluation Framework Business Model Canvas 78 Figure 9: COBALT Unified Certification Framework Business Model Canvas 79 Figure 9: Predictive Maintenance Business Model Canvas 79 Figure 11: Clouditor Business Model Canvas 80 Figure 12: IDS Connector Business Model Canvas 81
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 7 INDEX OF TABLES Table 1: SDT and SDT Manager - SWOT Analysis .............................................................................................. 27 Table 2: CCM Manager - SWOT Analysis ............................................................................................................ 28 Table 3: Eclipse Qrisp - SWOT Analysis ............................................................................................................... 29 Table 4: Security Metrics and Security Controls for AI - SWOT Analysis ........................................................... 30 Table 5: AI Model and AI Supply Chain Vulnerability Assessment - SWOT Analysis ......................................... 31 Table 6: Interledger Blockchain Platform - SWOT Analysis ................................................................................. 32 Table 7: Risk Evaluation Framework - SWOT Analysis ....................................................................................... 33 Table 8: COBALT Unified Certification Framework - SWOT Analysis ............................................................... 34 Table 9: Predictive Maintenance - SWOT Analysis............................................................................................... 35 Table 10: Clouditor - SWOT Analysis ................................................................................................................... 36 Table 11: IDS Connector - SWOT Analysis .......................................................................................................... 37 Table 12: SDT and SDT Manager - PESTEL Analysis .......................................................................................... 38 Table 13: CCM and CCL - PESTEL Analysis ....................................................................................................... 39 Table 14: Eclipse Qrisp - PESTEL Analysis .......................................................................................................... 40 Table 15: Security Metrics and Security Controls for AI - PESTEL Analysis....................................................... 41 Table 16: AI Model & AI Supply Chain Vulnerability Assessment - PESTEL Analysis ...................................... 42 Table 17: Interledger Blockchain Platform – PESTEL Analysis ........................................................................... 43 Table 18: Risk Evaluation Framework - PESTEL Analysis................................................................................... 44 Table 19: COBALT Unified Certification Framework - PESTEL Analysis .......................................................... 45 Table 20: Predictive Maintenance - PESTEL Analysis .......................................................................................... 46 Table 21: Clouditor - PESTEL Analysis ................................................................................................................ 47 Table 22: IDS Connector - PESTEL Analysis........................................................................................................ 48 Table 23: SDT and SDT Manager - CBA Analysis ................................................................................................ 49 Table 24: CCM and CCL - CBA Analysis ............................................................................................................. 50 Table 25: Eclipse Qrisp - CBA Analysis ................................................................................................................ 51 Table 26: Security Metrics and Security Controls for AI - CBA Analysis............................................................. 52 Table 27: AI Model and AI Supply Chain Vulnerability Assessment - CBA Analysis .......................................... 53 Table 28: Interledger Blockchain Platform - CBA Analysis .................................................................................. 54 Table 29: Risk Evaluation Framework - CBA Analysis......................................................................................... 55 Table 30: COBALT Unified Certification Framework - CBA Analysis ................................................................ 56 Table 31: Predictive Maintenance - CBA Analysis ................................................................................................ 57 Table 32: Clouditor - CBA Analysis ...................................................................................................................... 58 Table 33: IDS Connector - CBA Analysis.............................................................................................................. 59 Table 34: SDT and SDT Manager - CEA Analysis ................................................................................................ 60 Table 35: CCM Manager - CEA Analysis .............................................................................................................. 61 Table 36: Eclipse Qrisp - CEA Analysis ................................................................................................................ 62 Table 37: Security Metrics and Security Controls for AI - CEA Analysis ............................................................. 63 Table 38: AI Model and AI Supply Chain Vulnerability Assessment - CEA Analysis .......................................... 64 Table 39: Interledger Blockchain Platform - CEA Analysis .................................................................................. 65 Table 40: Risk Evaluation Framework - CEA Analysis ......................................................................................... 66 Table 41: COBALT Unified Certification Framework - CEA Analysis ................................................................ 67 Table 42: Predictive Maintenance - CEA Analysis ................................................................................................ 68 Table 43: Clouditor - CEA Analysis....................................................................................................................... 69 Table 44: IDS Connector - CEA Analysis .............................................................................................................. 70 LIST OF ABBREVIATIONS AND ACRONYMS Acronyms/ Abbreviations Description AI Artificial Intelligence AHWGs Ad Hoc Working Groups CAB Conformity Assessment Body
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 8 CABs Conformity Assessment Bodies CBA Cost Benefit Analysis CC Common Criteria CCL Common Certification Language CCM Common Certification Model CEA Cost Effective Analysis CMMC Cybersecurity Maturity Model Certification CRA Cyber Resilience Act CSF Cybersecurity Framework DLT Distributed Ledger Technology DORA Digital Operational Resilience Act DRA Dynamic Risk Assessment DT Digital Twinning DT-aaS Digital Twinning as a Service ECSMAF ENISA Cyber Security Market Analysis Framework EUCCF EU Cybersecurity Certification Framework EUCS European Cybersecurity Certification Scheme for Cloud Services ENISA European Union Agency for Cybersecurity GA Grant Agreement GDPR General Data Protection Regulation HPC High Performance Computing ICT Information and Communication Technology IDS International Data Spaces IoT Internet of Things IP Intellectual Property IPR Intellectual Property Rights ISMS Information Security Management Systems KER Key Exploitable Result KERs Key Exploitable Results PESTEL Political, Economic, Social, Technological, Environmental, Legal QC Quantum Computing QMS Quantum Management Systems ROI Return of Investment SDT Security Digital Twin SDN Software-Defined Networking SMEs Small Medium Enterprises
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 9 SWOT Strengths, Weaknesses, Opportunities, Threats ToE Target of Evaluation WP Work Package WPs Work Packages
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 16 3 Market Analysis The Market Analysis for the COBALT project provides an in-depth evaluation of the potential for adoption, growth and integration of its cybersecurity certification framework across industries. In this section, the analysis of the cybersecurity certification landscape will be presented along with the identified key trends and the opportunities and challenges that COBALT will face in encouraging adoption. 3.1 Overview of the Cybersecurity Certification Market The cybersecurity certification market is growing rapidly, driven by the increasing importance of protecting digital systems for cyber threats. As businesses and governments around the world face rising risks from cyberattacks, there is a growing demand for trustworthy ways to ensure the security of systems, networks and data. With the rise of new technologies like AI, Quantum Computing, and Industry 4.0, the need for robust cybersecurity measures has become even more critical. COBALT is designed to meet this demand by offering a unified certification framework. Unlike traditional certification systems that may only focus on specific industries or technologies, COBALT provides a comprehensive solution that works across different sectors. As more companies look for ways to automate compliance and safeguard their operations, the cybersecurity certification market is expanding. There is a clear need for efficient, high-assurance certification systems, and COBALT is well-positioned to play a key role in fulfilling this need. By offering a standardized approach, it can help businesses reduce risks, build trust with customers, and ensure compliance with global standards. 3.2 Key Market Drivers Several critical drivers are shaping the demand for robust cybersecurity certification. The framework of COBALT is equipped to directly address these drivers to ensure that each organization remains secure, compliant, and competitive in an ever-evolving arena. Cyberattacks are becoming more complex and frequent, including ransomware attacks, data breaches, and the growing value of digital assets highlighting the need for stronger security measures. This underscores the urgency with which robust security measures need to be instituted. Further, as industries integrate advanced technologies like AI, IoT, and robotics, ensuring cybersecurity and compliance with standards become crucial for operational success. COBALT’s certification framework directly addresses these challenges. By providing assurance that systems are secure and compliant with industry standards, COBALT enables businesses to adopt digital technologies confidently. As businesses expand globally, ensuring cybersecurity of cross-border digital operations is critical. The project’s certification framework is designed to address the unique challenges of global supply chains. It provides standardized security protocols that can be applied across borders, ensuring that businesses maintain consistent cybersecurity practices regardless of locations. Additionally, governments and regulatory bodies worldwide are introducing stricter cybersecurity requirements to safeguard national security, critical infrastructure, and consumer data. For businesses, keeping up with these regulations can be overwhelming and costly, especially if they lack clear guidelines. COBALT gives business a clear path to compliance, helping them meet regulatory demands while reducing risks and penalties. The demand for cybersecurity certification is growing stronger every day as businesses face rising cyber threats, stricter regulations, and the need to protect new technologies. COBALT offers a flexible certification framework that addresses these needs and helps build a safer, secure digital future for everyone.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 17 3.3 Market Segmentation and Target Industries The cybersecurity certification market is diverse, with different sectors requiring tailored solutions. By focusing on flexibility, scalability and industry-specific requirements, COBALT is designed to address the needs of different industries, and more specifically those endorsing advanced technologies. Below is an analysis of key market segments and their relevance to the COBALT initiative: • Artificial Intelligence (AI): The integration of AI across sectors such as healthcare, finance, manufacturing, and autonomous systems has led to an increased reliance on sophisticated algorithms that process sensitive data. AI systems are particularly vulnerable to cybersecurity threats, including data breaches, adversarial attacks, and algorithm manipulation. These vulnerabilities can compromise decision-making processes and expose personal and proprietary information. Recognizing these challenges, COBALT’s certification framework is designed to ensure that these types of models adhere to rigorous security standards. This helps build trust among stakeholders and fosters the secure adoption of AI technologies. Certification not only reinforces data integrity and privacy but also supports compliance with regulatory requirements, thereby accelerating the adoption of AI in critical and everyday applications [10]. • Quantum Computing: Quantum Computing is emerging as a transformative technology with the potential to revolutionize complex problem-solving across various fields, from cryptography to material science. However, the very nature of quantum computing introduces unique cybersecurity challenges. Securing quantum algorithms, safeguarding quantum communications, and ensuring the integrity of quantum-resistant protocols are critical issues as these systems transition from experimental research to real-world applications. COBALT’s certification initiative for Quantum Computing is tailored to address these specialized security needs. By certifying quantum systems and Quantum Oracles, COBALT aims to ensure that these technologies meet high-security standards, which is essential for sectors like national security, advanced finance, and critical infrastructure. This targeted certification fosters confidence in the reliability and security of quantum technologies, facilitating their secure integration into industry practices. • Manufacturing and Industry 4.0: The manufacturing sector is rapidly growing through Industry 4.0, which leverages IoT, automation, and data analytics to enhance efficiency and productivity. However, the interconnected nature of these advanced systems creates significant cybersecurity challenges, such as vulnerabilities in supply chains, industrial control systems, and IoT devices. Certified systems will not only protect against cyber threats but also ensure compliance with industry standards and regulations. This support is essential for manufacturers aiming to stay resilient while adopting digital transformation. COBALT enhance safety, minimize downtime caused by cyber incidents, and help manufacturers deliver secure, reliable products to meet customer demands. • SMEs and Start-ups: Small and medium-sized enterprises (SMEs) and start-ups play a vital role in the global economy, but they are often affected by cybersecurity challenges. COBALT can enhance these businesses by offering a simplified pathway to certification. With the offered certification, SMEs can compete in secure markets alongside larger businesses. This not only enhances their competitiveness but also strengthens the broader economic ecosystem. COBALT also provides SMEs with the tools and knowledge to improve their cybersecurity practices, helping them protect their operations and build trust with customers and partners. • Healthcare and Critical Infrastructure: Healthcare systems and critical infrastructure are prime targets for cyberattacks due to the sensitive nature of the data they handle and their essential role in society. COBALT’s certification framework can provide these
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 18 sectors with the assurance they need to protect patient data, medical devices, and essential services from cyber threats. • Finance and Banking: Due to the sensitivity of financial transactions and data, the finance sector is one of the most heavily regulated industries. COBALT offers a certification framework which could be aligned with existing financial regulations to address emerging threats such as cryptocurrency fraud and AI-driven financial crime. Certified systems enhance trust and security, enabling financial institutions to adopt such frameworks for securing cybersecurity is achieved but at the same maintenance compliance is also ensured. • Emerging Markets and Global Reach: In addition to establish industries and sectors, emerging markets could be also benefited from COBALT’s framework. While digital transformation is expanding rapidly, COBALT can help businesses in these regions to adopt secure technologies and participate in the global digital economy, by providing a recognized certification standard. • Digital Platforms: Social Media and E-commerce: Digital platforms, including social media and e-commerce, play pivotal roles in today’s interconnected economy. These sectors handle vast amounts of sensitive personal and financial data, making them prime target for cyber threats such as data breaches, account takeovers, and phishing attacks. The fallout from such incidents can be severe, ranging from significant economic losses to a breakdown of consumer trust and public safety concerns. COBALT’s certification framework is uniquely positioned to address these challenges by providing a comprehensive evaluation of cybersecurity measures across digital platforms. By offering detailed evaluations, COBALT helps organizations understand where improvements are needed, guiding them toward aligning with industry best practices and regulatory requirements. This support empowers digital platform providers to strengthen their defences and enhance overall security, ultimately contributing to a more resilient digital environment. COBALT’s adaptability to various industry applications highlights its importance and potential for growth in a constantly evolving market. By handling cybersecurity challenges faced by each domain, the project pushes technological progress while fostering a secure, inclusive, and robust digital environment. COBALT is set to establish itself as a key player in ensuring cybersecurity across a wide range of domains. 3.4 Competitive Landscape The competitive landscape section analyses existing and emerging players, frameworks, and solutions in the cybersecurity certification ecosystem. This helps position the COBALT within the market, identify its competitive advantages, and uncover opportunities for differentiation and collaboration. This section will assess COBALT’s competitive position in the market, identifying key players, analysing their strengths and weaknesses, and outlining COBALT’s differentiators. 3.4.1 Overview of the Cybersecurity Certification Market The cybersecurity certification market is becoming increasingly competitive as the need for robust digital security grows across industries. Numerous initiatives, both regional and global, are emerging to address the challenges of cybersecurity compliance, trust, and digital assurance. Key market players offering certifications across different sectors, include existing certification frameworks, private certification providers, and regulatory initiatives from government and organizations. However, COBALT’s unique value proposition lies in its ability to standardize certification processes across industries, integrating diverse technologies like AI, Quantum Computing into a cohesive framework.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 19 3.4.2 Key Competitors and Initiatives In this section, the main competitors or alternative solutions to the COBALT certification framework are identified. These include: • Existing Certification Standards and Frameworks: The COBALT certification framework enters a complex ecosystem that already features well-established international standards. By examining these existing standards, COBALT can both align with best practices and identify opportunities to till emerging gaps. Key frameworks include: - ISO/IEC 27001 – Information Security Management Systems (ISMS) Overview: ISO/IEC 27001 is a globally recognized standard for managing information security. It provides a systematic approach to managing sensitive information, ensuring it remains secure. This includes people, processes and IT systems applying a risk management process [11]. Relevance to COBALT: COBALT can leverage ISO/IEC 27001 by aligning its certification framework with established ISMS practices, thus ensuring compatibility and ease of adoption for organizations already certified under ISO/IEC 27001. This would also facilitate a smoother integration with existing cybersecurity management systems. Limitations and Gaps: The standard primarily focuses on risk management for information assets and does not explicitly address emerging technologies such as Quantum Computing, Digital Twins, or decentralized security approaches. - ISO/IEC 15408 - Common Criteria (CC) for IT Security Evaluation Overview: The Common Criteria framework provides a method for evaluating the security features and assurances of IT products and systems [12]. Relevance to COBALT: COBALT can adopt the structured evaluation methods from Common Criteria to define robust security requirements for its certification process. Limitations and Gaps: Its product-centric focus limits is applicability to complex, dynamic systems such as Digital Twins and integrated Industrial AI platforms. - ISO/IEC 62443 – Industrial Automation and Control Systems Security Overview: This set of standards is tailored for securing Industrial Automation and Control Systems (IACS), providing guidelines on risk assessment, system architecture, and component security [13]. Relevance to COBALT: Given COBALT’s focus on Industry 4.0, aligning with ISO/IEC 62443 can help ensure that the framework addresses the unique challenges of operational technology environments. Limitations and Gaps: While comprehensive for IACS, the standard does not extend to the cybersecurity challenges posed by innovations such as Quantum Computing or Digital Twins. - NIS2 Directive and ENISA’s Cybersecurity Certification Framework Overview: The NIS2 Directive sets out high-level cybersecurity and incident reporting requirements for critical infrastructure within the EU, while ENISA’s framework aims to harmonize certification across EU member states [1], [14].
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 20 Relevance to COBALT: Both frameworks support regulatory alignment and mutual recognition, which are critical for cross-border certification efforts. Limitations and Gaps: They offer broad guidelines without the technical specificity needed for advanced technologies, leaving room for COBALT to define more granular criteria. - CSA’s Cloud Security Certification (STAR) Overview: The Cloud Security Alliance’s STAR program certifies cloud service providers on their security practices and transparency. Relevance to COBALT: By drawing from cloud security practices, COBALT can integrate mechanisms for ensuring secure decentralized data exchange and processing. Limitations and Gaps: CSA STAR is focused on cloud environments and does not directly address issues related to Quantum Computing or Digital Twins. By aligning with these standards, COBALT can leverage established practices to build trust, while innovating in areas where these frameworks fall short – particularly in addressing emerging technologies. This dual approach can facilitate broader market adoption and establish COBALT as a forward-thinking certification authority. • Private and Industry Specific Providers: Alongside international standards, several private organisations and industry-specific providers offer specialized certification and training programs. These entities focus on both individual competencies and sector-specific requirements, providing a rich source of insight for COBALT’s development. - SANS Institute and GIAC Certifications Overview: The SANS Institute is a leader in cybersecurity training, and its affiliated GIAC certifications focus on practical skills across multiple domains, such as penetration testing, incident response, and cyber defence [15], [16]. Relevance to COBALT: The hands-on, scenario-based approach championed by SANS and GIAC can inform the practical assessment components within COBALT’s certification framework. Limitations and Gaps: Their programs are oriented towards individual professionals rather than comprehensive system-level or organizational certifications, and they may not yet fully address the challenges of emerging technologies. - (ISC)2 – International Information System Security Certification Consortium Overview: Recognized globally, (ISC)2 offers certifications like the Certified Information Systems Security Professional (CISSP), which validate expertise across various cybersecurity domains [17]. Relevance to COBALT: The broad and recognized body knowledge from (ISC)2 can be incorporated into COBALT’s curriculum, ensuring that the framework covers essential cybersecurity principles. Limitations and Gaps: Their focus remains largely on individual knowledge and competencies rather than on certifying comprehensive organizational security practices. - ISACA Overview: ISACA is known for its certifications on IT governance and auditing, including CISA and CISM, which are highly valued in both audit and risk management spheres [18]. Relevance to COBALT: ISACA’s structured approach to governance and risk management can help COBALT integrate strong oversight and compliance measures into its framework.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 21 Limitations and Gaps: The technical depth required for emerging technologies such as Digital Twins and Quantum Computing is less emphasized in ISACA’s certifications. - Industry-Specific Frameworks Overview: Specific sectors have developed targeted standards to meet their unique cybersecurity challenges. Examples include: o Payment Card Industry Data Security Standard (PCI DSS): Focused on securing payment card transactions [19]. o Health Insurance Portability and Accountability Act (HIPAA): Establishes requirements for safeguarding patient data [20]. o Federal Information Security Management Act (FISMA): Mandates security practices for federal agencies in the US [21]. Relevance to COBALT: By integrating industry-specific requirements, COBALT can tailor its certifications to the needs of various sectors, ensuring higher relevance and better compliance. Limitations and Gaps: These frameworks are typically confined to specific industries and may not address cross-sector challenges posed by new technologies. COBALT’s approach can fill this gap by offering unified certification across industries. • Regional Initiatives: Regional regulatory and compliance initiatives play a significant role in shaping the cybersecurity certification landscape. By understanding these initiatives, COBALT can better tailor its framework to address both global standards and local requirements. - GDPR and NIS Directive Compliance Efforts (EU) Overview: The General Data Protection Regulation (GDPR) and the NIS Directive are cornerstone initiatives in the EU, emphasizing robust data protection and securing critical infrastructure. GDPR establishes strict data privacy requirements, while the NIS Directive mandates enhanced cybersecurity measures and incident reporting for essential services [22], [23]. Relevance to COBALT: These initiatives highlight the need for certification solutions that not only ensure data protection and regulatory compliance but also validate the security of advanced technologies. Limitations and Gaps: While GDPR and NIS set high-level requirements, they often lack the technical specificity needed for novel technologies such as DT or Quantum Computing. - U.S. CMMC Framework Overview: The Cybersecurity Maturity Model Certification (CMMC) is a U.S. initiative designed to ensure cybersecurity compliance within the defence supply chain. It features a structured maturity model with levels corresponding to specific cybersecurity practices . Relevance to COBALT: While tailored for the defence sector, the CMMC framework’s emphasis on measurable cybersecurity outcomes offers valuable insights for developing a scalable certification process that extends beyond U.S. defence contracts. Limitations and Gaps: The Cybersecurity Maturity Model Certification (CMMC) ensures cybersecurity compliance in the defence supply chain. It is mandatory but has limited applicability beyond U.S. defence contracts.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 22 • Existing Certification Bodies: Well-established certification bodies have long set the benchmark for cybersecurity standards; however, they often operate in environments with limited integration across different sectors and technologies. Key players include: - ENISA (European Union Agency for Cybersecurity): Provides guidance and frameworks to support cybersecurity certification across the EU. While ENISA’s efforts promote harmonized standards, they sometimes lack the agility needed for rapidly evolving technological landscapes. - NIST (National Institute of Standards and Technology): A major authority in US, NIST produces detailed cybersecurity guidelines and frameworks, such as the NIST Cybersecurity Framework. However, NIST’s frameworks are primarily focused on risk management and may not directly address emerging technologies. - ISO (International Organization for Standardization): Offers internationally recognized standards (e.g. ISO/IEC 27001, ISO/IEC 15408) that provide a solid foundation for cybersecurity management. Despite their global acceptance, these standards are often too generalized to capture the variations of advanced technological implementations like Digital Twins or Quantum Computing. Relevance to COBALT: - Interoperability: COBALT is designed to work alongside these established frameworks, integrating their best practices while addressing their limitations through specialized modules for emerging technologies. - Added Value: By bridging the gap between high-level standards and the technical demands of modern cyber ecosystems, COBALT can serve as complementary certification framework that enhances overall cybersecurity resilience. • Emerging Competitors: The cybersecurity landscape is witnessing an influx of new entrants, particularly driven by digital transformation and the rise of artificial intelligence. These emerging competitors offer specialized solutions, often focusing on niche areas, which can be both an opportunity and a challenge for COBALT. Overview: - New entrants in Digital Transformation and AI: Startups and technology firms are increasingly offering cybersecurity solutions that leverage advanced analytics, machine learning, and automation to detect and mitigate threats. These companies are often more agile and innovative, addressing specific vulnerabilities in rapidly changing digital environments. Relevance to COBALT: While these emerging competitors address particular aspects of cybersecurity, their offerings tend to be specialized and narrowly focused. COBALT’s broad scope and cross-industry applicability enable it to provide a more integrated and comprehensive certification solution. This positions COBALT as a versatile framework capable of certifying diverse environments, from traditional IT systems to cutting-edge industrial applications. Limitations and Gaps in Competitors’ Offering: The focus of many emerging players may lead to fragmented cybersecurity practices. In contrast, COBALT aims to deliver a unified approach that not only covers conventional security requirements but also anticipates the challenges posed by emerging technologies such as Quantum Computing and Digital Twins.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 23 3.4.3 Competitive Advantages of COBALT COBALT distinguishes itself within the competitive landscape by offering a unified framework that integrates emerging technologies with established standards. Its design not only aligns with evolving regulatory requirements, such as the EU’s Cyber Resilience Act and DORA, but also addresses the unique needs of diverse sectors – from AI and Quantum Computing to Industry 4.0. Leveraging a trusted and scalable framework COBALT can support and quip organizations with the tools needed to safeguard and optimize their digital environments in a continuous evolving threat landscape. • Unified and Multi-Sectorial Framework COBALT is engineered as a single, cohesive certification model that transcends traditional industry units. Rather than being limited to one domain, it integrates diverse sectors-ranging from AI and Quantum Computing to Industry 4.0 and IoT-under one umbrella. This unified approach enables organizations to adopt a common set of security standards across their entire operations, reducing complexity and promoting interoperability [24]. • Integration with Emerging Technologies COBALT is not built on legacy IT assumptions. It incorporates forward-looking assessments that address the security differences of emerging technologies such as AI, Quantum Computing, and the proliferation of of interconnected IoT devices. This integration ensures that the framework remains relevant even as new technologies reshape the digital landscape. • Alignment with EU Policy Goals As an EU-based project, COBALT is developed in close alignment with key EU regulatory frameworks and digital policies. It is designed to meet evolving standards such as the Cyber Resilience Act and the Digital Operational Resilience Act (DORA). This ensures that COBALT-certified organizations not only achieve high cybersecurity standards but also maintain compliance with future regulatory changes. • SME-friendly Approach One of the most significant gaps in the current cybersecurity landscape is the accessibility of robust certification processes for small and medium-sized enterprises (SMEs). COBALT addresses this challenge by offering scalable and simplified certification processes. Its modular design allows SMEs to adopt essential security measures without the high cost and complexity of typically associated with comprehensive cybersecurity frameworks. • Trusted, Transparent and Scalable Framework COBALT is built on principles of trust, transparency, and scalability. It employs rigorous, standardized assessment procedures that are openly documented, ensuring that certification processes are clear and replicable. Moreover, its design is inherently scalable, enabling organizations of any size to adopt and benefit from its certification processes. This transparency and adaptability foster long-term confidence among stakeholders and prepare organizations to manage future technological disruptions effectively. These competitive advantages position COBALT as a comprehensive, future-ready certification framework. Its unified design, along with robust integration of emerging technologies and regulatory alignment, enables it to meet the dynamic challenges of today’s and tomorrow's digital landscape – while remaining accessible to organizations of all sizes.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 24 3.4.4 Gaps in the Competitive Landscape While existing frameworks and solutions have made progress in cybersecurity assurance, several gaps remain that COBALT can address: 1. Lack of Harmonization: Many widely recognized frameworks – such as ISO/IEC 27001 and the NIST Cybersecurity Framework – are implemented in ways that vary significantly across regions and sectors. These variations stem from differing local regulations and standards, creating a fragmented certification landscape that complicates operations for multinational businesses. COBALT aims to fill this gap by offering a harmonized, crossborder solution that streamlines certification processes and reduces inefficiencies. 2. Emerging Technology Coverage Current certification frameworks are primarily designed around traditional IT infrastructures and often do not fully address the unique security challenges posed by emerging technologies like AI, Quantum Computing. These technologies introduce novel risks and require certification approaches that can adapt to their evolving nature. COBALT’s framework is specifically engineered to incorporate the latest technological developments, providing future-proof evaluations that align with these advanced domains. 3. Accessibility for SMEs: Many of the existing solutions tend to be resource-intensive and costly, making them less accessible to small and medium-sized enterprises (SMEs). This creates a barrier for a significant segment of the market that is equally vulnerable to cyber threats. In response, COBALT’s approach features streamlined processes designed to lower these entry barriers, ensuring that SMEs can also benefit from comprehensive cybersecurity assessments. By addressing these critical gaps, COBALT not only enhances the overall cybersecurity posture but also paves the way for a more unified and inclusive digital security environment. 3.4.5 Opportunities To strengthen its position in the cybersecurity certification landscape, COBALT can explore strategic opportunities by engaging with global frameworks, regulatory bodies, and key industry players. These opportunities not only enhance the project’s impact but also contribute to the long-term sustainability and adoption of its certification framework: • Harmonization with Global Standards: Aligning COBALT with internationally recognized frameworks such as ISO 27001, NIST Cybersecurity Framework and Common Criteria (CC) will ensure that its certification approach I applicable and widely accepted. By integrating best practices these established standards, COBALT can provide a seamless certification experience for businesses operating across different regions. This alignment would increase trust in COBALT-certified systems and facilitate mutual recognition agreements, reducing redundancy in certification efforts for multinational organizations. • Engagement with EU Bodies: Close collaboration with EU regulatory agencies – such as ENISA, the European Commission, and national cybersecurity authorities – is essential to ensuring that COBALT remains aligned with evolving cybersecurity policies, such as the Cybersecurity Act and NIS2 Directive. Engaging with these bodies can help COBALT contribute to shaping EU-wide certification schemes and influence cybersecurity policymaking. Furthermore, involvement in regulatory discussions will increase COBALT’s credibility and accelerate its adoption as part of Europe’s broader cybersecurity ecosystem.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 25 • Partnerships with SMEs and Industry Leaders: Establishing partnerships with SMEs, large enterprises, and technology developers allows COBALT to cocreate tailored certification solutions that address industry-specific needs. SMEs often struggle with complex and costly certification processes; by engaging directly with them, COBALT can develop streamlined, accessible, and cost-effective approaches to certification. Meanwhile, collaborating with industry leaders and multinational corporations can help drive market adoption, encourage best practices sharing, and create scalable certification models that align with real-world security challenges. Additionally, engagement with sector-specific alliances (e.g., industrial automation, financial services, and telecommunications) will enable COBALT to refine its framework to meet the precise needs of different verticals. By leveraging these opportunities, COBALT can enhance its relevance, foster greater adoption, and ensure its certification framework remains robust, adaptable, and widely recognized across industries and regulatory landscapes. 3.5 Barriers to Adoption and Challenges Adopting COBALT’s cybersecurity certification framework comes with its own set of challenges. Despite the growing demand for robust security measures, several barriers stand in the way of successful implementation and scalability. These challenges range from high costs, lack of awareness and complex regulations that need to be addressed. • Fragmented Regulatory Landscape: Different countries and industries may have varying cybersecurity regulations. COBALT must ensure its certification framework is adaptable to these regulations while promoting harmonization. • Awareness and Education: Many organizations may not fully understand the importance of cybersecurity certification or the benefits it brings. Educating these businesses on the value of certification and the benefits of COBALT’s framework will be critical to its adoption. • Cost of Certification: The certification cost can still be significant financial burden for smaller businesses. COBALT must ensure its certification process remains affordable while maintaining the highest standards of security.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 32 4.1.6 Interledger Blockchain Platform for Cross-border Certification Integration of different certificates and documents and their interrelation to facilitate the certification process. The DLT (Distributed Ledger Technology) Gateway in the ETSI TeraFlowSDN project serves as a pivotal component that integrates blockchain technology into the SDN (Software-Defined Networking) framework. It facilitates secure, transparent, and efficient communication between different network domains and enables smart contract deployments for managing network services. Table 6: Interledger Blockchain Platform - SWOT Analysis • Integration Capabilities: Seamlessly integrates Distributed Ledger Technology (DLT) with SDN frameworks, offering enhanced scalability and flexibility. • Transparency and Trust: Blockchain ensures secure, transparent, and efficient communication, which is pivotal for crossborder certifications. • Interledger Design: Provides interconnection among ledgers to handle multi-component certifications. • Alignment with EU Standards: Adheres to the evolving EU Cybersecurity Certification landscape, such as the Cyber Resilience Act. S T R E N G T H S W E A K N E S S E S • Extensive different document approaches. • Complexity in Implementation: Challenges in integrating the Interledger Blockchain across diverse industries and verticals. • Interoperability Issues: Ensuring compatibility between blockchain and legacy systems can be resource intensive. • Standardization and Policy Support: Opportunity to contribute to EU standardization and certification frameworks. • Expanding Market for Certifications: Growing demand for cybersecurity certifications due to regulatory requirements like the EU CRA and AI Act. • Global Applicability: Addresses the universal need for cross-border certification, positioning it for adoption beyond the EU. • Partnership Opportunities: Collaboration with organizations such as ENISA, SDOs, and open-source initiatives for joint contributions. O P P O R T U N I T I E S T H R E A T S • Adoption Barriers: Resistance from manufacturers and stakeholders unfamiliar with blockchain technologies. • Regulatory Uncertainty: Future changes in EU or global regulations might necessitate significant adjustments. • Competitor Solutions: Emerging solutions with similar functionalities could reduce the competitive edge. • Cybersecurity Risks: As a platform handling sensitive data, it might attract significant security threats and attacks.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 33 4.1.7 Risk Evaluation Framework Dynamic Risk Assessment as the support of EU-based certification frameworks, automation of Risk Assessment in the context of continuous Vulnerability Management Process in EUCC and EUCS. Develop tailored risk management techniques based on regulations. Table 7: Risk Evaluation Framework - SWOT Analysis • Holistic Approach: Combines static and dynamic assessments for thorough risk identification and continuous monitoring. • Dual-process integration: Static assessments establish a baseline, while dynamic assessments ensure adaptability to real-time risks, offering resilience and agility. • Forward-looking risk management: Addresses both current and emerging risks using internationally recognized standards (ISO/IEC 27005, NIST CSF, ENISA, etc.). • Integration of Static and Dynamic Processes: Static assessments provide a baseline, while dynamic assessments ensure adaptability to real-time risks, offering resilience and agility. • Robust Methodology: Comprehensive asset, threat, and vulnerability identification and quantification of risks facilitates prioritization and resource allocation. • Automation and Efficiency: Real-time monitoring and event-based triggers (via the DRA toolkit) enhance efficiency and responsiveness. • Strong Certification Management: The decision engine ensures lifecycle management of certifications, maintaining system integrity over time. • Compliance with Industry Standards: Aligns with globally accepted frameworks, making it easier to achieve regulatory and industry compliance. S T R E N G T H S W E A K N E S S E S • Complex Implementation: Initial setup may be resource intensive, requiring significant time and effort. • Data Dependency: Real-time risk assessments depend heavily on accurate and up-to-date data, which may not always be available or reliable. • Scalability Challenges: Managing the framework for large-scale or highly dynamic systems may require additional resources and tools. • Leverage AI and Machine Learning: AIbased predictive models can enhance the dynamic assessment process by identifying patterns and potential vulnerabilities faster. • Partnerships and Collaborations: Collaborating with organizations like ENISA and ISO can ensure the framework stays aligned with emerging threats and standards. • Improved Risk Quantification: Advanced metrics and models (e.g., probabilistic risk assessment) can make quantification more precise, enhancing decision-making. O P P O R T U N I T I E S T H R E A T S • Evolving Cyberthreats: Rapidly changing threat landscapes may outpace the framework’s adaptation capabilities. • Compliance Burdens: Keeping up with multiple standards and frequent updates can strain resources. • Over-reliance on Automation: Automated tools may miss subtle, context-specific risks that require human expertise.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 34 4.1.8 COBALT Unified Certification Framework COBALT proposes the creation of a framework to support the automation of cybersecurity certification processes, which can benefit EU stakeholders involved on those engagements. In the case of industrial manufacturers of products or services, COBALT provides tools implementing the automation of compliance assessments with guarantees of trustworthiness. Those tools include compliance metrics, evidence collectors, and graphical user interfaces that facilitate automation while transparently communicating achieved levels of compliance to manufacturers. In the specific case of Bosch, our requirement for the contributed COBALT framework is to support EU-cybersecurity certification schemes, in particular the newly developed EUCS[25]. Table 8: COBALT Unified Certification Framework - SWOT Analysis • Potentially big customer-base because EUcybersecurity certification schemes (with potential AI Extension Profiles) are used as presumption of conformity with EU Regulations and Directives like AI Act and CRA. • Proposed framework will be validated on an industrial environment which is relevant for other EU scenarios. S T R E N G T H S W E A K N E S S E S • Complexity of final framework makes it not (financially) feasible to implement on an industrial environment. • Lack of interoperability due to non-existent standards in critical aspects like automation and compliance metrics. • To the best of our knowledge, no similar automation frameworks for EU cybersecurity certification exist in the market. • Strong engagement with Regulators and ENISA might provide strong alignment of framework’s capabilities with actual EU requirements. O P P O R T U N I T I E S T H R E A T S • Lack of acceptance by Regulators and other relevant stakeholders involved in cybersecurity certification processes. • Lack of customer base due to required skills for deploying and using the framework’s toolset.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 35 4.1.9 Predictive Maintenance As a tool on top of the SDT, a proactive strategy to maximize security assessment will be designed aimed at predicting potential evidence deviations that may negatively affect the accuracy of the proposed assessment. Table 9: Predictive Maintenance - SWOT Analysis • Open tool for predicting deviations. • Automated insights from evidence collected. • Contribution to overall SDT trustworthiness. S T R E N G T H S W E A K N E S S E S • Wrong warnings driving wrong corrective actions. • Enough evidence needs to be collected and analysed to learn from it, thus leading to potentially large periods of time dedicated to data collection and use of resources of AI model training and validation. • Complexity on identifying relevant evidence and their deviations. • Complexity on identifying interrelationships among evidence. • To the best of our knowledge, no similar tool exists to support predictive maintenance based on collected evidence for cybersecurity certification. • Generalization of the tool, that could be applied in a wide variety of verticals, based on cybersecurity-related evidence. O P P O R T U N I T I E S T H R E A T S • High inaccuracy. • No acceptance within the community. • Low knowledge.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 36 4.1.10 Clouditor Clouditor provides multiple core components of the COBALT framework. These components enable the collection, assessment, and management of evidence. For example, the Cloud Evidence Collector can collect evidence about cloud resource configuration, the Assessment component can assess evidence for a given set of metrics, and the Orchestrator manages the storage and other functionalities. As such, Clouditor has a unique position in the field of monitoring solutions. Table 10: Clouditor - SWOT Analysis • Multi-cloud approach: Using the underlying ontology, Clouditor enables the harmonized collection of evidence across different cloud systems. For example, evidence regarding Microsoft Azure Virtual Machines and AWS EC2 Instances are abstracted and assessed using the same metrics as they both represent the same concept (virtual machines) in the ontology. • Open-Source: Clouditor is an open-source project and as such, can easily be tried by potential users. Also, it can benefit from the open-source community where developers may contribute to Clouditor’s features. S T R E N G T H S W E A K N E S S E S • Metric range is limited, i.e., the scope of conformance checking is limited. • Implementation is focused on Microsoft Azure, while extensions for other platforms require significant manual work. • Extendibility: Clouditor is extendible for new evidence collection sources, like new cloud technologies, AI, and custom services. Also, it is extendible for upcoming regulatory requirements, e.g., from the Cyber Resilience Act. O P P O R T U N I T I E S T H R E A T S • Competitors: Cloud-native security posture management services can be competition for Clouditor. For instance, Azure Policy is able to scan Azure resources and apply policies to them. • AI developments: AI-based tooling may present an alternative to deterministically assessing evidence in the future.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 37 4.1.11 IDS Connector Data Spaces are emerging as critical ecosystems where organizations can share and collaborate on data from diverse sources to achieve common goals. These environments prioritize interoperability and security, facilitating cooperation among different stakeholders including Data Owners, Data Providers, Data Consumers, Data Intermediaries, Technology Providers, and Operators. Table 11: IDS Connector - SWOT Analysis • Enhanced data security and interoperability: Provides a secure and structures environment for data sharing, reducing isolated data and fostering collaboration. • Strong industry support: Backed up by alliances like the DSBA, ensuring alignment with emerging standards and frameworks. • Compliance enablement: Facilitates adherence to industry standards, ensuring legal and regulatory compliance for users. • Improved data accessibility and quality: Promotes structured data sharing, enhancing the usability and reliability of shared information. S T R E N G T H S W E A K N E S S E S • Integration complexity: Initial setup requires significant resources and technical expertise, potentially slowing adoption. • Stakeholder dependency: The framework’s success depends on continuous and active collaboration among diverse stakeholders, which can be challenging to maintain. • Conflicting IP issues: Proprietary data formats and connector compatibility may create barriers to interoperability and deployment. • Expanding use cases: Data spaces have applications across industries such as healthcare, finance, manufacturing, and government, offering huge market potential. • Open-source integration: Combining the IDS connector with various tools can enhance accessibility and innovation through community contributions. • Collaborative ecosystem: Partnerships with industry leaders can drive adoption and improve technology alignment with market needs. O P P O R T U N I T I E S T H R E A T S • Data privacy concerns: Sharing data raises compliance and security risks, especially under various regulations. • Technical vulnerabilities: Potential failures in infrastructure or integration workflows could undermine trust in the system. • Competition: Emerging data-sharing platforms, including blockchain-based solutions and established cloud service providers, could challenge market positioning.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 38 4.2 PESTEL Analysis The PESTEL analysis provides a broader outline that enables the evaluation of external factors affecting the organizational decision-making and market dynamics. The approach examines the Political, Economic, Social, Technological, Environmental and Legal factors. In this way, organizations obtain valuable understanding of possible opportunities and threats that emerge from shifts in broader external environment. Political factors include government policies and regulations that affect business operations, while economic factors consider key economic indicators like unemployment, inflation rates, and economic growth. Additionally, social factors focus on demographic trends and cultural behaviours that influence consumer preferences, while technological factors evaluate the impact of innovations and technological advancements. Environmental factors deal with sustainability and ecological considerations, while legal factors cover compliance with laws such as intellectual property and labour regulations. This thorough analysis will allow COBALT partners to develop targeted strategies, ensuring the project maximizes its market potential while addressing vulnerabilities and risks effectively. 4.2.1 SDT and SDT Manager The SDT operates within an evolving environment, where continuous and updated evidence arise according to both novel hardware and software, as well as to new threats and regulation requirements, thus demanding for a global understanding of factors impacting the SDT concept and its evolution. Table 12: SDT and SDT Manager - PESTEL Analysis P OLITICAL E CONOMIC • Alignment with international standards could facilitate market acceptance. • Increasing cybersecurity regulations in the EU support the adoption of secure digital twin management solutions. • Cost savings for industries through proactive security strategies enabled by the SDT. • High ROI potential due to the growing demand for cybersecurity and digital twin solutions. S OCIAL T ECHNOLOGICAL • Rising awareness of cybersecurity risks drives demand for proactive security solutions. • Adoption may be slowed by limited knowledge and familiarity with digital twin technologies. • Advances in real-time data synchronization and attack modelling enhance the SDT’s value. • Modular and open architecture supports integration and scalability with evolving technologies. E NVIROMENTAL L EGAL • SDT can protect digital infrastructures, including those in environmentally sensitive industries. • DT reduces the need for physical testing, minimizing resource use and environmental impact. • IP issues with proprietary digital twin technologies need careful management. • Compliance with EU regulations and certifications like the EUCC and EUCS drives adoption.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 39 4.2.2 CCM Manager The Common Certification Model (CCM) Manager is designed to standardize cybersecurity certification processes across industries. They integrate existing frameworks and regulations to support automation, compliance management, and security requirements (in COBALT’s CCL), particularly in emerging fields like AI and Quantum Computing. Table 13: CCM Manager - PESTEL Analysis P OLITICAL E CONOMIC • Challenges arising from varying national policies on data sovereignty, particularly with cross-border data sharing and certification processes. • Opportunities to shape global cybersecurity certification standards through collaboration with ENISA and other policy-making bodies • By unifying certification processes, CCM and CCL reduce costs for industries, especially in avoiding redundant certifications. • Increased demand for robust cybersecurity certification in Industry 4.0, AI, and Quantum Computing drives economic viability. • Enhances Europe’s competitiveness by providing a streamlined and reliable certification framework applicable across industries. S OCIAL T ECHNOLOGICAL • Transparent processes and robust cybersecurity assurances foster trust among businesses, regulators, and consumers. • Growing societal focus on cybersecurity and data protection supports the adoption of certification frameworks. • Advances in real-time data synchronization and Leveraging technologies like Digital Twins, AI, and OSCAL ensures CCM Manager remain cutting-edge. • The fast pace of innovation in ICT and cybersecurity necessitates continuous updates to CCM, CCL and corresponding COBALT’s certifications schemes. E NVIROMENTAL L EGAL • No significant direct environmental impact noted. • Compliance with GDPR, the EU Cybersecurity Act, and other international regulations is essential for legal viability. • Potential legal challenges could arise if certifications are found insufficient/inconsistent in ensuring cybersecurity compliance.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 40 4.2.3 Eclipse Qrisp Eclipse Qrisp is an open-source, high-level programming language designed to simplify quantum algorithm development and compilation. Table 14: Eclipse Qrisp - PESTEL Analysis P OLITICAL E CONOMIC • Support from governments investing in quantum technologies could create opportunities. • Open-source nature aligns with policies promoting innovation and knowledge sharing. • High potential for consulting and project revenue. • Increasing demand in industries like finance, logistics, and material sciences ensures market relevance. S OCIAL T ECHNOLOGICAL • Lack of a developer community may hinder widespread adoption. • The educational application to universities and research institutes can drive knowledge sharing and skill development. • Strong competition from well-established frameworks (Qiskit, Cirq) may affect market penetration. • Rapid advancements in quantum computing could challenge the software’s adaptability. E NVIROMENTAL L EGAL • No significant direct environmental impact noted. • Licensing under EPL 2.0 ensures open-source compliance. • Protection of IP within the open-source community requires observance.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 41 4.2.4 Security Metrics and Security Controls for AI Despite compliance metrics are a part of the full framework envisioned by COBALT, the following PESTEL analysis provides a broad understanding of the external factors that could influence the introduction and success of the metrics and controls supporting automation of cybersecurity certification processes for AI systems. Table 15: Security Metrics and Security Controls for AI - PESTEL Analysis P OLITICAL E CONOMIC • New government regulations (EU AI Act, EU Cybersecurity Act) could slow AI adoption and certification due to lack of practical experience. • Changing data privacy policies may impact COBALT’s metrics and controls, requiring flexibility. • Different development timelines between COBALT and relevant regulations (e.g. AI Act) could result in delayed early adoption. • Economic conditions and funding availability for AI and cybersecurity can influence the adoption of COBALT’s compliance metrics. • Economic downturns may reduce AI/cybersecurity investment, while growth could promote adoption. S OCIAL T ECHNOLOGICAL • Public attitudes toward AI, cybersecurity, and data privacy will influence COBALT’s adoption and market demand. • Interest in “AI Trustworthiness” is outside COBALT’s scope but still relevant to public perception. • Rapid advancements in AI and cybersecurity technologies can drive opportunities but challenge the pace of standard development. • COBALT’s metrics must adapt to evolving technologies and integrate easily with tools from various providers. E NVIROMENTAL L EGAL • Environmental concerns may not directly impact the metrics, but sustainability and energy efficiency could affect market reputation, especially regarding AI system energy use. • Compliance with AI, cybersecurity, and data protection laws is key to COBALT’s success. • Legal changes could affect the development and adoption of compliance metrics.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 48 4.2.11 IDS Connector The IDS Connector is a core component of the International Data Spaces architecture, enabling secure and trusted data exchange between components by adhering to standardized protocols, data sovereignty principles, and dynamic usage control. Table 22: IDS Connector - PESTEL Analysis P OLITICAL E CONOMIC • Data regulations: Compliance with strict data protection regulations in the EU is a critical factor influencing adoption and integration. • Government support: Increasing government initiatives and funding for secure data-sharing frameworks and digital transformation bolster adoption opportunities. • Standardization policies: Efforts by international organizations to standardize data-sharing practices provide a favourable environment for the IDS Connector. • Rising demand for data management solutions: The growing need for secure, efficient, and interoperable data-sharing frameworks in sectors like healthcare, finance, and manufacturing drives market growth. • Cost of implementation: High initial integration and maintenance costs could pose a barrier for small and medium-sized enterprises. • Economic stability: Fluctuations in economic conditions may influence organizational willingness to invest in new technologies. S OCIAL T ECHNOLOGICAL • Trust and transparency: Organizations are increasingly prioritizing trust in data-sharing processes, necessitating robust security and compliance mechanisms. • Collaboration culture: Growing emphasis on collaborative ecosystems among businesses and institutions supports the adoption of tools like the IDS Connector. • Data privacy concerns: Public awareness and sensitivity around data privacy and ownership could impact trust and willingness to share data within ecosystems. • Advancements in interoperability: Emerging technologies improve integration capabilities. • Open-source contributions: Leveraging open-source developments can accelerate innovation and enhance community-driven enhancements to the IDS Connector. • Integration with emerging technologies: Potential to integrate with AI, IoT, and blockchain solutions, further expanding functionality and market relevance. • Cybersecurity threats: Continuous advancements in cyberattacks require proactive security measures to maintain trust and reliability. E NVIROMENTAL L EGAL • Energy efficiency: Data-sharing platforms should aim to minimize energy consumption, particularly with rising concerns about the environmental impact of the ICT infrastructure. • Eco-friendly data management practices: Encouraging environmentally responsible data practices can attract sustainability-conscious stakeholders. • Compliance with data protection regulations: Adherence to global, regional and industry-specific data protection standards is essential for credibility and adoption. • Intellectual Property (IP) issues: Managing proprietary data formats and connectors while ensuring interoperability without legal conflicts is crucial. • Liability concerns: Clear guidelines on liability for data breaches or misuse within the ecosystem must be established to protect stakeholders.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 49 4.3 Cost-Benefit Analysis The Cost-Benefit Analysis (CBA) is a key tool for evaluating the overall economic viability and impact of the COBALT project. The analysis will provide a clear understanding of the project’s value proposition. This process not only highlights financial gains but also captures broader, qualitative benefits such as improved cybersecurity resilience, increased trust and market growth. 4.3.1 SDT and SDT Manager The SDT is a digital replica of a physical system’s security state, and the SDT Manager oversees the creation, integration, and maintenance of these digital twins, ensuring accurate security data and effective system protection. Table 23: SDT and SDT Manager - CBA Analysis Alternatives • Manual management of DT, which is time-intensive, prone to errors, and lacks real-time updates. • Decentralized DT management tools with limited automation and no integration with certification frameworks. Costs Benefits • Direct costs: o Development and testing of the SDT and the SDT Manager and integration into COBALT. o Operational costs for deploying the system in real-world environments. • Indirect costs: o Training stakeholders and end-users on the SDT Manager functionalities. o Technical support and updates to maintain compatibility with evolving standards. • Intangible costs: o Potential delays in synchronization or integration with existing systems. o Challenges in ensuring stakeholder acceptance of new technology. • Opportunity costs: o Resources allocated to SDT development could have been used for other cybersecurity innovations. o Time spent on training and implementation might delay other operational priorities. • Direct benefits: o Enhanced efficiency in cybersecurity certification processes through automation. o Reduced costs of manual assessments by enabling decentralized and real-time updates of DT. o Enhanced support to analysis and validation of predicted scenarios without impacting the real system operation. • Indirect benefits: o Improved operational security for enterprises by proactively managing vulnerabilities. o Strengthened market positioning for organizations adopting advanced cybersecurity measures. o New products, services or processes can be developed and evaluated upon the SDT. • Intangible benefits: o Increased trust in digital twin-based solutions for cybersecurity certification. o Contribution to industry standards and best practices, fostering innovation and collaboration. o Digital threads linking data from different sources and stages throughout SDTs’ lifecycle can enhance decision-making and extend knowledge base. Preliminary Assessment of Value Sensitivity Analysis • The SDT’s manager ability to streamline and secure DT management offers significant time savings, operational efficiency, and enhanced cybersecurity, outweighing the initial investment and operational costs. • The SDT is based on a modular and extendable architecture, leveraging standardized interfaces • Key risks: Data privacy concerns, technical challenges in synchronization, and slow market adoption. • Mitigation: Implement robust encryption, ensure modular architecture for flexibility, and promote
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 50 and providing an abstraction of the underlying technologies. awareness through targeted marketing and demonstrations. 4.3.2 CCM Manager The CCM Manager provides a unified approach to streamline cybersecurity certification. They ensure compliance with international standards while addressing emerging technologies (i.e., AI and Quantum Computing). Table 24: CCM Manager - CBA Analysis Alternatives • Implement a fully centralized certification framework relying on existing standards without adopting CCM innovations. • Hybrid approach with partial CCM adoption, focusing on modular components for specific verticals (e.g., AI, Quantum Computing). Costs Benefits • Development costs: o Development, deployment, and integration of CCM. o Training stakeholders and operational costs for maintaining certification pipelines. • Operational costs: o Delay in leveraging new technologies due to focus on certification implementation and support for tool developers and external system integrators. • Opportunity costs: o Resources required for stakeholder engagement and adaptation. o Impact on workflows during transition phases. o Potential resistance from stakeholders, leading to slower adoption. o Effort to align CCM with international standards. • Direct Benefits: o Increased efficiency in certification processes. o Cost savings by avoiding redundant certifications. o Financial gains from licensing CCM tools. • Indirect Benefits: o Greater customer confidence in certified products. o Enhanced market competitiveness for stakeholders. • Intangible Benefits: o Improved interoperability across industries. o Increased trust in the cybersecurity ecosystem. o In addition, CCM can establish a shared understanding among stakeholders, reducing conflicts or misinterpretations. Preliminary Assessment of Value Sensitivity Analysis Financial savings from certification efficiencies, improved interoperability, and setting a European standard. • Key risks: Slow adoption could delay the realization of indirect benefits, such as market expansion and competitive advantages. Moreover, Costs of aligning with evolving regulatory requirements could potentially affect the products impact and lifecycle. • Mitigation: Use phased implementation, iterative development, and regular stakeholder feedback to adjust assumptions dynamically.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 51 4.3.3 Eclipse Qrisp Eclipse Qrisp is a high-level quantum programming language designed for scalable and efficient software development. Table 25: Eclipse Qrisp - CBA Analysis Alternatives • Use existing frameworks like Qiskit or Cirq with custom modifications • Develop an entirely custom quantum programming framework tailored to specific needs. Costs Benefits • Direct costs: Development, maintenance, and integration. • Indirect costs: Training for developers, community-building efforts, and documentation updates. • Intangible costs: Potential delays due to adoption resistance or lack of immediate stakeholder support. • Opportunity costs: Resources allocated to Eclipse Qrisp that could have been used for other tools or frameworks. • Direct benefits: Reduction in development time and costs due to automation of low-level programming tasks. • Indirect benefits: Increased accessibility of quantum programming to a wider audience, improving industry adoption. • Intangible benefits: Enhance reputation of FOKUS as a leader in quantum software and open-source innovation. Preliminary Assessment of Value Sensitivity Analysis The most significant benefits are the reduction in development costs, increased accessibility of quantum computing and potential revenue generation. • Key risks: Low developer adoption due to lack of interest from developers and organization; Rapid technological changes in quantum computing coupled with insufficient community engagement limiting framework evolution. • Mitigation: Provide extensive support, training programs, clear integration paths, and invest in outreach, and open-source projects; Commit to regular updates, active monitoring of technological trends, and collaborate with quantum research institutions and standardization bodies for alignment and ecosystem development.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 52 4.3.4 Security Metrics and Security Controls for AI The envisioned COBALT set of compliance metrics and corresponding cybersecurity controls for AI Systems potentially represents for our organization setting an internal cybersecurity baseline for related products and services, which might result in concrete business benefits as elaborated next. Table 26: Security Metrics and Security Controls for AI - CBA Analysis Alternatives • Minimal integration of standardized security metrics for AI; existing practices may lack automation or validation. Costs Benefits • Development costs: High costs expected for designing and validating the metrics, establishing controls, and engaging with regulators. • Operational costs: Maintenance of controls, integration with internal frameworks, and periodic updates to address evolving regulations. • Opportunity costs: Time and resources diverted from other innovative projects to focus on compliance-driven metrics. • Direct benefits: o Demonstrated compliance with AI Act regulations. o Competitive edge through early adoption of standards, increasing market access. • Indirect benefits: o Influence on international standardization and regulations. o Improved internal processes and risk management through validated metrics. • Intangible benefits: o Enhanced brand reputation as a leader in AI cybersecurity. o Long-term trust from stakeholders and customers. Preliminary Assessment of Value Sensitivity Analysis The integration of metrics and controls into ongoing standards ensures strong market positioning and compliance advantages, outweighing development costs. • Key risks: Delays in regulatory maturity, interoperability challenges with existing standards. • Mitigation: Collaboration with standardization bodies to shape evolving regulations.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 53 4.3.5 AI Model and AI Supply Chain Vulnerability Assessment This KER automates the identification and assessment of vulnerabilities in AI models and supply chains, addressing risks like model extraction and insecure artifacts. Using the AIShield platform, it ensures compliance, risk evaluation, and monitoring, enhancing the security and trustworthiness of AI systems while aligning with EU regulations. Table 27: AI Model and AI Supply Chain Vulnerability Assessment - CBA Analysis Alternatives • Current manual assessment practices without automation. • Full automation of vulnerability assessment processes for AI models and supply chains. • Hybrid approach combining manual evaluations with automated tools. Costs Benefits • Direct costs: Tool development and deployment, licensing, infrastructure. • Indirect costs: Operational adjustments, trainings, integration with existing systems. • Intangible costs: Potential delays in regulatory acceptance, resistance to adoption. • Opportunity costs: Missed competitive advantage due to delayed implementation. • Direct benefits: Reduced time and cost for vulnerability assessments, increased efficiency. • Indirect benefits: Enhanced compliance, streamlined certification processes. • Intangible benefits: Improved customer trust and brand reputation. • Competitive advantages: Market differentiation through advanced AI risk management. Preliminary Assessment of Value Sensitivity Analysis • Most significant benefits: Time and cost savings, enhanced regulatory compliance. • Alignment with goals: Strong alignment. • Key risks: Misalignment with evolving EU regulations, limited adoption of automation, dependency on API availability, and challenges integrating with diverse compliance frameworks. • Mitigation: Maintain collaboration with regulatory bodies, promote awareness of automation benefits, and design flexible, modular tools adaptable to various frameworks.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 54 4.3.6 Interledger Blockchain Platform Integration of different certificates and documents and their interrelation to facilitate the certification process. The DLT (Distributed Ledger Technology) Gateway in the ETSI TeraFlowSDN project serves as a pivotal component that integrates blockchain technology into the SDN (Software-Defined Networking) framework. It facilitates secure, transparent, and efficient communication between different network domains and enables smart contract deployments for managing network services. Table 28: Interledger Blockchain Platform - CBA Analysis Alternatives • Baseline scenario: Maintain existing manual and region-specific certification processes. • Adoption scenario: Deploy the Interledger Blockchain Platform to automate cross-border certification while ensuring interoperability. • Hybrid Scenario: Gradual adoption of the blockchain platform in select industries or regions, maintaining existing processes in others. Costs Benefits • Direct Costs: o Platform design and integration with existing certification systems. o Development of smart contracts and interledger connectivity. • Indirect Costs: o Training users (e.g. certification bodies and stakeholders). o Administrative costs for transitioning to the new system. • Intangible Costs: o Resistance to change from stakeholders unfamiliar with blockchain technology. o Initial loss of trust due to technical glitches during the early stages. • Opportunity Costs: o Time spent on adoption that could delay other strategic initiatives. • Direct Benefits: o Faster certification processes via automated workflows. o Reduced costs for certification bodies due to decreased manual intervention. • Indirect Benefits: o Enhanced collaboration across regions due to interoperable certification. o Increased market access for companies with globally recognized certifications. • Intangible Benefits: o Improved transparency and trust in certification processes. o Strengthened brand positioning as an innovative solution provider. • Competitive Advantages: o Early adoption positions stakeholders as leaders in cross-border certification innovation. Preliminary Assessment of Value Sensitivity Analysis • Significant Benefits: Increased efficiency (faster processing) and improved trust (via transparent record-keeping). • Alignment with Goals: Supports COBALT’s mission to enhance cybersecurity and enable scalable, trusted certification processes. • Key Variables: Adoption rate, stakeholder engagement, and system reliability. • Scenario Example: A slower adoption rate reduces initial efficiency gains, but long-term benefits remain strong.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 55 4.3.7 Risk Evaluation Framework The Risk Evaluation Framework is a tool designed to automate the risk assessment process withing the context of continuous vulnerability management. It aims to integrate dynamic risk evaluation techniques tailored to specific regulations, addressing the growing need for real-time, adaptive risk analysis and mitigation strategies. This tool also supports compliance with certification schemes such as the EUCC and EUCS, providing a holistic approach to risk management that overcomes the limitations of static, manual risk assessment methods. Table 29: Risk Evaluation Framework - CBA Analysis Alternatives • Current static risk assessment processes: Primarily manual and time-consuming, lacking real-time adaptability. • Dynamic risk evaluation framework: Automated, regulation-tailored, and capable of continuous risk assessment. Costs Benefits • Development costs: Efforts to design and implement the Dynamic Risk Assessment (DRA) tool, including co-development across partners. • Operational costs: Ongoing maintenance, updates and training for users. • Opportunity costs: Transition from static to automated processes, requiring resource reallocation. • Intangible costs: Potential IP conflicts during codevelopment and licensing agreements. • Direct benefits: o Reduced time and resources for certification compliance. o Improved scalability to handle large volumes of certificates. • Indirect benefits: o Enhanced trust among certification authorities and stakeholders. o Alignment with CRA requirements and EU regulations. • Intangible benefits: o Increased market adaptability due to real-time assessment. o Improved stakeholder satisfaction through automation and transparency. Preliminary Assessment of Value Sensitivity Analysis • The ability to meet regulatory demands and support certification growth positions the Risk Evaluation Framework as a valuable innovation. • Key risks: IP conflicts and integration challenges. • Mitigation: Clear IP management and licensing agreements.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 56 4.3.8 COBALT Unified Certification Framework The COBALT Unified Certification Framework is a comprehensive approach to cybersecurity certification, designed to ensure trusted, adaptable, and sustainable certification across industries. Table 30: COBALT Unified Certification Framework - CBA Analysis Alternatives • Adopt existing certification frameworks, such as OSCAL, without customization or developing industry-specific certification solutions independently. Costs Benefits • Direct costs: Development, integration, and operational expenses for the COBALT Unified Certification Framework. • Indirect costs: Training and onboarding of stakeholders, along with infrastructure upgrades. • Intangible costs: Resistance to adoption and potential delays in acceptance by stakeholders. • Opportunity costs: Resources diverted from other cybersecurity or R&D initiatives. • Direct benefits: Streamlined, automated certification processes that reduce time-to-certification and operational inefficiencies. • Indirect benefits: Enhanced stakeholder collaboration through integration with international standards and frameworks. • Intangible benefits: Increased trust and market competitiveness for certified entities, along with the ability to shape global certification norms. Preliminary Assessment of Value Sensitivity Analysis The COBALT Unified Certification Framework promises significant value by addressing gaps in the cybersecurity certification landscape, particularly in emerging domains like AI and Quantum Computing. Its adoption could position stakeholders as leaders in compliance innovation. • Key risks: Inadequate framework maintenance, resistance from established organizations, and misalignment with future advancements. • Mitigation: Continuous updates, partnerships with global standardization bodies, and proactive engagement with stakeholders.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 57 4.3.9 Predictive Maintenance The Predictive Maintenance tool, powered by an AI-assisted pattern generator, forecasts potential evidence deviations that could impact the accuracy of risk assessments. It promotes proactive maintenance and enhances overall security and reliability. Table 31: Predictive Maintenance - CBA Analysis Alternatives • Proactive approaches based on penetration testing, network monitoring, personnel training for cybersecurity awareness, and strategies for security patch management. • Reactive approach with remarkable impact on the infrastructure. Costs Benefits • Direct costs: Design, implementation, and integration of the tool. Design, implementation, and integration of algorithms. • Indirect costs: Training for developers. Technical support and updates to maintain compatibility with evolving standards. Use of computing resources. • Intangible costs: Inaccuracies leading to wrong decisions and mistrust from stakeholders. Poor adaptation to new threats, thus not detecting them and impacting the real system. • Opportunity costs: Complexity to create accurate predictions and maintain updated algorithms adapting to changes in the environment and continuous learning could delay other strategic objectives. • Direct benefits: Automated early detection and prediction of threats, which allows them to react in advance before the real system is affected by the threat. • Indirect benefits: Strengthened overall security. Allow stakeholders to estimate maintenance costs beforehand. • Intangible benefits: Build trust and maintain compliance. Preliminary Assessment of Value Sensitivity Analysis • Early detection and immediate definition of mitigation/prevention actions to minimize the effects of the potential attack. • Key risks: Inaccurate process driving wrong decisions. • Mitigation: Guarantee proper data to feed the decision-making process, including exhaustive control on the whole data lifecycle, also considering internal checks to detect data bias, deviations, etc.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 64 4.4.5 AI Model and AI Supply Chain Vulnerability Assessment Table 38: AI Model and AI Supply Chain Vulnerability Assessment - CEA Analysis Objective Automate AI vulnerability assessments to improve efficiency, compliance and risk management. Outcomes Potential Costs (Qualitative) • Reduced assessment time. • Increased assessment accuracy. • Compliance rate improvement. • Development of the solution requires significant resource allocation for design, testing, and implementation. • Integrating the tool with existing systems and APIs involves technical challenges and additional effort. • Training users to effectively adopt and utilize the tool saves time and effort. • Continuous maintenance and updates will be necessary to keep the tool aligned with evolving regulations and emerging threats. Effectiveness Cost-Effectiveness (Qualitative) • Automation achieves increased efficiency gains compared to manual processes. • Accuracy improvements reduce post-certification vulnerabilities. • The investment cost is justified by significant efficiency and compliance gains. • Faster assessments lower the overall lifecycle costs of AI system development. Alternatives • Manual vulnerability assessments with human experts require significant time and effort but lacking scalability. • Semi-automated tools offering partial assessments, reducing manual effort but with limited scope and integration. • Fully automated tools providing comprehensive, scalable, and efficient vulnerability assessment aligned with regulations. The AI Model Vulnerability and AI Supply Chain Vulnerability Assessment tools provide cost-effective, scalable and automated solutions that enhance security, compliance and efficiency, offering significant long-term benefits.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 65 4.4.6 Interledger Blockchain Platform Table 39: Interledger Blockchain Platform - CEA Analysis Objective The primary objective of the Interledger Blockchain Platform is to reduce cross-border certification time and complexity while ensuring interoperability, transparency, and trust among stakeholders. Outcomes Potential Costs (Qualitative) • Reduction in certification time: Achieve a decrease in the time required for cross-border certification processes. • Improved transparency: Provide an immutable and auditable record of certifications. • Scalability: Enable certification interoperability across multiple industries and regions. • Stakeholder satisfaction: Increase stakeholder trust and willingness to adopt the platform. • Development costs: Effort required for creating interledger functionality and integrating with existing certification frameworks. • Operational costs: Resources needed for maintaining the platform and training users. • Opportunity costs: Time spent transitioning from manual to automated systems, which could delay other strategic goals. Effectiveness Cost-Effectiveness (Qualitative) • Projected efficiency gains: The platform automates manual processes, significantly reducing time and operational overhead. • Transparency impact: the blockchain’s immutability ensures certifications are tamperproof and verifiable. • Stakeholder engagement: Projections suggest high stakeholder satisfaction due to simplified processes and reduced costs. • The platform offers a high return of efficiency by reducing certification time and costs, even though initial development and adoption require significant effort. • The qualitative trade-off is clear: the long-term benefits (e.g. scalability, trust, and collaboration) far outweigh the transitional costs. Alternatives • Existing systems: Manual, region-specific processes are slower and prone to errors and inefficiencies. • Interledger Blockchain Platform: Provides automation, transparency, and scalability with a one-time significant effort. • Hybrid approaches: Incremental adoption mitigates risk but delays realizing full benefits. The Interledger Blockchain Platform offers a highly effective solution for achieving COBALT’s objective with long-term scalability and efficiency, aligning well with COBALT’s objectives of enabling trusted and decentralized certification process.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 66 4.4.7 Risk Evaluation Framework Table 40: Risk Evaluation Framework - CEA Analysis Objective Develop and deploy a dynamic, automated Risk Evaluation Framework tailored to EU-based certification schemes (EUCC, EUCS). Outcomes Potential Costs (Qualitative) • Automation of risk assessments. • Real-time operation compliant with new EU regulations. • Adaptive mitigation strategies for vulnerabilities. • Increased efficiency in handling multiple certification schemes. • Development and operational costs: Significant but scalable. • Licensing and IP management: Critical to ensuring co-development success. Effectiveness Cost-Effectiveness (Qualitative) • Projected efficiency gains: Transitioning from static to dynamic assessments enables real-time adaptability and regulatory compliance. • Stakeholder adoption: Likely to be high due to the alignment with emerging regulatory needs. • Compared to static assessments, the dynamic framework demonstrates higher efficiency and adaptability at a moderate cost increase. Alternatives • Static assessments: Time-consuming, and unable to scale for modern certification demands. • Dynamic framework: Offers automation, adaptability, and alignment with CRA/EUCS regulations, making it the more cost-effective solution. The Risk Evaluation Framework is highly cost-effective, with significant qualitative and operational benefits outweighing moderate developmental and operational costs.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 67 4.4.8 COBALT Unified Certification Framework Table 41: COBALT Unified Certification Framework - CEA Analysis Objective To establish a unified, cross-domain cybersecurity certification framework that standardizes processes, reduces redundancy, and addresses emerging needs in AI and Quantum Computing compliance. Outcomes Potential Costs (Qualitative) • Streamlined certification processes that lower time-to-certification. • Increased collaboration and interoperability among stakeholders. • Enhanced alignment with European and international standards (e.g. AI Act, Cyber Resilience act, ISO, NIS2). • Initial investment in development, infrastructure, and training. • Stakeholder onboarding challenges and resource allocation. • Ongoing maintenance and adaptation to evolving technologies. Effectiveness Cost-Effectiveness (Qualitative) The COBALT framework is highly effective in addressing gaps in current certification landscapes, particularly for AI and Quantum technologies. Its ability to integrate with global standards fosters trust, compliance and scalability. The framework offers a high return of investment by automating processes, reducing duplication, and fostering a competitive edge for adopters. While the upfront costs are significant, the long-term savings and benefits outweigh initial expenditures. Alternatives • Rely on fragmented, industry-specific certification solutions. • Adopt existing frameworks like OSCAL without customization for emerging technologies. The COBALT Unified Certification Framework represents a cost-effective solution for modern cybersecurity challenges. It offers scalable, future-proof certification processes that align with regulatory and technological advancements, ensuring long-term value and impact.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 68 4.4.9 Predictive Maintenance Table 42: Predictive Maintenance - CEA Analysis Objective AI-assisted pattern generation predicting evidence deviations to anticipate possible degradation in risk assessment, thus promoting systems' maintenance in advance to enhance security. Outcomes Potential Costs (Qualitative) • Predictive analysis enabling a proactive response. • The actions to carry out to minimize performance degradation in risk assessment and their impact. • High initial development and integration effort. • Continuous maintenance and updates are required to align with new threats and technologies. • Coordination challenges among multiple stakeholders during implementation. Effectiveness Cost-Effectiveness (Qualitative) • Predictive maintenance in combination to preassessment in virtual scenarios minimizes performance degradation in risk assessment while optimally identifying and evaluating the actions to implement and their impact. • Higher capacity to face potential attacks. • Immediate response to early detection through a set of well-defined mitigation/preventive actions. Alternatives • Reactive approach with a notable impact on the infrastructure. • Demand for non-realistic continuous monitoring. This AI-assisted solution advances the actions to perform aimed at preventing performance degradation in risk assessment.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 69 4.4.10 Clouditor Table 43: Clouditor - CEA Analysis Objective To provide an automated, technology-agnostic compliance and evidence collection tool for certification processes. Outcomes Potential Costs (Qualitative) • Increased efficiency in certification workflows. • Reduced operational and compliance costs. • Enhanced ability to certify multi-technology systems. • Development and integration costs for adapting Clouditor to various technologies. • Training costs for personnel to effectively utilize the tool. • Maintenance costs for ensuring compatibility with evolving standards. Effectiveness Cost-Effectiveness (Qualitative) Clouditor simplifies compliance processes, reduces manual errors, ensures scalability for diverse certification needs. The investment in Clouditor is justified by its ability to significantly lower compliance time and labour, improve accuracy, and enhance organizational productivity. Alternatives • Rely on manual certification and compliance efforts. • Utilize proprietary tools that may lack flexibility and scalability. Clouditor represents a cost-effective solution for automating compliance and certification processes, offering substantial benefits fir organizations managing complex certification workflows.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 70 4.4.11 IDS Connector Table 44: IDS Connector - CEA Analysis Objective To enable secure, decentralized, and interoperable data exchange across organizations and borders. Outcomes Potential Costs (Qualitative) • Seamless integration with existing systems for data exchange. • Increased trust and compliance with regulatory frameworks. • Enhanced operational efficiency through interoperability. • Development and implementation costs for ensuring compatibility with diverse systems. • Training costs to upskill staff on the functionality. • Continuous updates to align with evolving data sovereignty regulations. Effectiveness Cost-Effectiveness (Qualitative) The IDS Connector facilitates secure and efficient data-sharing, reduces compliance risks, and supports global interoperability. The solution offers a high return on investment by minimizing data-sharing risks, ensuring compliance, and fostering trust across industries. Alternatives • Depending on centralized data-sharing systems with limited flexibility. • Build proprietary data-sharing tools that may not meet regulatory requirements. The IDS Connector is a highly cost-effective tool for secure and compliant data exchange, addressing the needs of organizations navigating complex data sovereignty regulations.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 71 5 Socio-Economic Impact Analysis The COBALT project aims to provide strong socio-economic returns fostering innovation, economic development and social confidence in ICT systems. Likewise, its certification framework and ecosystem are developed to meet the growing needs of AI, Quantum Computing and Industry 4.0. This section discusses the performance of COBALT in terms of economic, social and environmental principles, emphasizing its alignments with European policy goals and its potential to foster long-term sustainability. 5.1 Economic Impact The implementation of COBALT project is expected to provide a positive impact on promoting employment opportunities across various sectors. New employment positions will become available with the services of certification, consulting and in research as well as development. Further, other sectors that will be integrate the use of the systems that will be developed such as manufacturing, logistics and quantum computing will have a trained staff to perform as well as supervise the implementation of cybersecurity standards. Such advancements are expected to enhance the expansion of the market by increasing the availability of the certification procedures, especially for the small and medium enterprises. The application of strategy of standardization and automation by the COBALT focuses on eliminating the financial and operational hazards that come with the certification processes making it possible for smaller business to enter high assurance markets. In terms of market growth, COBALT aims to drive expansion in the cybersecurity space. As technologies such as Industry 4.0 and Quantum Computing continue to grow, the project’s outcomes will help to integrate these industries into a unified and secure framework. With cybersecurity becoming an increasing concern across all sectors, the demand for certified, trustworthy systems is expected to escalate, creating new market opportunities such as growth in certification services, cybersecurity consulting, and managed security solutions. This includes emerging fields like Industry 4.0, quantum computing, IoT, and cloud infrastructure, as well as established sectors such as healthcare, finance and logistics. The economic benefits are extended beyond the new employment opportunities. By streamlining certification workflows, the project simplifies the process for businesses to achieve and maintain certifications, thereby reducing administrative burdens and enhancing operational efficiency. Although this may not directly lower costs, the clarity and efficiency provided by a systematic approach contribute to overall economic benefits. Additionally, COBALT’s framework offers thorough assessments that equip organizations with the insights needed to identify and address cybersecurity risks, supporting informed decision-making and strengthening economic resilience. By simplifying the certification process and making it more affordable, COBALT allows start-ups and SMEs to innovate and thrive within a secure, high-assurance environment. These advantages not only increase the economic stability, but they also promote a secure and resilient ICT ecosystem. 5.2 Social Impact COBALT has a transformative role in enhancing societal trust in digital products and services. In today’s world, where data breaches and privacy concerns dominate headlines, people need to feel confident in the technology they use. COBALT’s certification framework ensures meeting of critical security requirements in ICT systems hence increasing assurance to users and organizations. This trust is a necessity in an increasingly connected world. COBALT aims to create an inclusive cybersecurity ecosystem. It recognizes the unique challenges faced by smaller businesses, which often lack the resources to navigate the complexities of cybersecurity certification. By simplifying processes and reducing costs, COBALT creates opportunities for these enterprises to access highassurance markets that were previously inaccessible. Furthermore, addressing the needs of the smaller organizations and, COBALT is way of making certification more available to the majority. Such inclusivity
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 72 promotes a more equitable digital economy providing opportunities for smaller enterprises to access markets that are highly security and compliance oriented. Through these efforts, COBALT is contributing to both technological advancement and a more sustainable future. This not only enables smaller organizations to grow and innovate but also fosters a more dynamic and competitive digital landscape. Moreover, COBALT contributes to public education and workforce development by promoting cybersecurity awareness and training initiatives. The outcomes of the project will help people understand and embrace cybersecurity. COBALT can act as a driver of both technological and social progress, empowering individuals and organizations to navigate an increasingly complex digital landscape. By raising awareness and fostering knowledge, COBALT is creating a society that’s not just digitally connected but also digitally secure. 5.3 Environmental Impact COBALT-enabled technologies have a significant potential to drive sustainability across various industries, primarily by enhancing the efficiency of cybersecurity certification processes. Instead of directly promoting energy-efficient systems, COBALT adopts an eco-approach by reducing the resources required during security audits. By eliminating redundant procedures that were traditionally executed through more resource-intensive methods, COBALT significantly reduces the time-to-certification, resulting in a process that is inherently more energy-efficient. Furthermore, COBALT’s integrated lifecycle management components help extend the usability of ICT products. These components streamline processes such updates or maintenance, which in turn can reduce electronic waste by encouraging the continued use and timely upgrading of existing systems rather than replacing them prematurely. Although COBALT does not directly enforce sustainable design or disposal practices, its alignment with environmental regulations and policies ensures that the certification process adheres to high standards of environmental responsibility. This approach contributes indirectly to waste reduction and supports circular economy principles, fostering a more sustainable ICT ecosystem.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 73 6 Business Models for COBALT Ecosystem 6.1 Overview of COBALT Business Model The development of the business model involves a systematic and iterative methodology. It begins with understanding the problem with opportunity that COBALT addresses, such as the need for robust cybersecurity certification across diverse ICT verticals. The business model for the COBALT project serves as a structured framework to illustrate how each KER generates, delivers, and captures value. At this stage, the business model is built around the initial Business Model Canvas adopted from the Grant Agreement (GA) and deliverable D6.1. This canvas acts as a starting point for defining key components, including value propositions, customer segments, revenue streams, cost structures, key activities, resources and partnerships. Figure 1: COBALT Business Model Canvas The value proposition focuses on delivering a trusted, adaptable, and future-proof certification framework, integrating advanced technologies like Industrial AI, Quantum Computing, and Digital Twinning. To ensure the business model is aligned with market needs, it identifies key customer segments and defines effective channels to engage these customers including direct partnerships, pilot projects and targeted workshops. Customer relationships are built around strategic partnerships, tailored support, and active community involvement. The model also considers various revenue streams, including licensing, integration, subscriptions and mentoring services, to ensure the long-term financial sustainability of COBALT’s outcomes. Additionally, it identifies key resources – such as technical expertise, infrastructure, network and funding – and outlines essential activities like research, development, engagement of stakeholders and promote project outcomes. Strategic partnerships with research institutions, industry partners, technology providers and certification bodies will be formed to strengthen capabilities and support scalability. Finally, the cost structure covers both capital and operational expenses, including the ongoing support, technology implementation, equipment and services. Using this approach, COBALT develops tailored business models for each KER, as detailed in the following sections. This ensures the project outcomes are economically viable, market-ready and capable of driving sustainable growth and innovation in cybersecurity certification landscape.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 80 6.11 Business Model of the Clouditor The business model for Clouditor focuses on automating evidence collection and assessment for multi-cloud environments, ensuring compliance with EU cybersecurity regulations. Key partners include cloud service providers, certification bodies, and open-source communities. Key activities involve integrating with cloud-native security tools, maintaining Clouditor for evidence collection, and engaging with certification frameworks. The value proposition simplifies certification processes, enhances compliance, and offers technology-independent solutions. Revenue is generated through licensing fees for enhanced versions, as well as customization and consulting services. Customer relationships are maintained through direct support, open-source contributions, and community engagement. Figure 11: Clouditor Business Model Canvas 6.12 Business Model Canvas of the IDS Connector The business model for the IDS Connector focuses on enabling secure, trusted and decentralized data exchange across diverse industrial ecosystems. Key partners include data providers, certification bodies, and the opensource community. Key activities involve the development, maintenance, and integration of the IDS Connector with existing systems, ensuring alignments with International Data Spaces (IDS) standards. The value proposition offers enhanced data security, compliance with regulations like GDPR, and facilitates interoperability across industries. Revenue is generated through consulting services for system integration and compliance, as well as licensing fees for premium features. Customer relationships are encouraged through direct support, open-source engagement, and industry partnerships.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 81 Figure 12: IDS Connector Business Model Canvas
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 82 7 Intellectual Property Rights (IPR) 7.1 IPR Management COBALT acknowledges that effective Intellectual Property Rights (IPR) management is essential for ensuring the sustainability, protection and market adoption of its research outcomes. As a publicly funded project, COBALT is committed to safeguarding partners’ innovations while balancing open access principles and commercial exploitation potential. To systematically handle IPR, COBALT will establish an IPR Management Registry that: • Identifies and documents background knowledge (pre-existing partner expertise). • Records and safeguards project-generated knowledge (foreground assets). • Ensures compliance with licensing, ownership, and exploitation policies. • Facilitates strategic dissemination, ensuring IPR protection before public release. This structured approach ensures that COBALT’s certification methodologies, AI-driven cybersecurity frameworks, and Quantum Oracles are properly protected, regulated, and positioned for impact in the European Market. 7.2 IPR Management Objectives The IPR Management Registry within COBALT is designed to achieve the following objectives: • Protection of Partner Contributions and Innovations - Safeguard the intellectual property of project partners, considering both background assets (pre-existing IP) and foreground assets (knowledge generated within COBALT). - Define clear ownership structures and protection mechanisms for all project results. • Ensuring IPR Protection and Conflict Resolution - Address shared ownership issues and define clear exploitation pathways. - Provide guidelines on patent fillings, copyright protection, and licensing. - Resolve potential IPR conflicts before exploitation or publication. • Facilitating Secure Knowledge Sharing and Standardization - Establish a structured process for partners to securely share results while maintaining ownership rights. - Encourage contributions to standardization bodies (e.g. ENISA, ETSI, ISO) to ensure COBALT’s outputs align with global cybersecurity certification frameworks. • Preventing Unauthorized Use and IP Misappropriation - Actively discourage and prohibit unauthorized use or misuse of project outcomes. - Implement access control mechanisms for sensitive research outputs. 7.3 IPR Management Methodology The IPR Management Registry will include three key components:
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 83 • Background IPR (Pre-Existing Partner Knowledge and Assets) - Description of pre-existing IP owned by partners before the project. - Relevance of each background asses to COBALT work packages (WPs). - Ownership and potential challenges related to exploitation. • Foreground IPR (Knowledge Generated Within COBALT) - Detailed description of new IP developed during the project. - Ownership structures, protection steps (e.g., patents, copyrights). - Expected commercial and technological impact of results. - Interconnection with other COBALT WPs and ongoing certification frameworks. • Third-Party Software and Licensing - Identification of third-party IP integrated within COBALT. - Licensing models (e.g. open-source, proprietary, hybrid). - Compliance with data protection and security standards. 7.4 IPR Considerations for Key Innovations COBALT’s IPR management approach is particularly relevant to the certification models and emerging technologies it develops: • Common Certification Model (CCM) Manager and Language (CCL): Establishing a unified framework for ICT cybersecurity certification requires structured IP handling and potential standardization efforts. • AI-Driven Security (AI Shield): Intellectual property protection for AI models and cybersecurity algorithms will be balance between access principles and proprietary safeguards. • Quantum Oracles APIs: Given the novelty of quantum computing in certification, IPR considerations must define ownership of algorithmic developments and interface specifications. • Interledger for Cross-Border Certification: Ensuring secure interoperability between certification frameworks raises specific IPR and licensing concerns, particularly in multi-jurisdictional environments. By integrating IPR best practices from the outset, COBALT will maximize the exploitation of its results while ensuring a fair and structured approach to intellectual property management.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 84 8 Sustainability Roadmap The Sustainability Roadmap outlines how COBALT will ensure long-term success and impact by driving adoption, aligning with relevant policies and EU standards, and implementing effective monitoring and evaluation mechanisms. This section provides a structured plan to sustain COBALT’s socio-economic contributions while enabling continuous improvement and market growth. By addressing key opportunities and challenges, COBALT will establish itself as a trusted cybersecurity certification framework that delivers value across industries and regions. 8.1 Adoption and Uptake Roadmap COBALT has reached a critical phase where the initial groundwork and pilot activities must transition into broader adoption strategies. This roadmap identifies targeted actions, clear milestones, and practical strategies to accelerate uptake in key sectors and geographies. 8.1.1 Strategies for Encouraging Adoption in Key Sectors Driving adoption requires understanding sector-specific needs while promoting the flexibility and value of COBALT’s certification framework. Key strategies include: • Showcase Industry-Specific Benefits Share tailored use cases and success stories across sectors such as AI, Quantum Computing, Industry AI, and SMEs, demonstrating COBALT’s ability to enhance security, competitiveness, and compliance. • Strengthen Partnerships Collaborate with industry leaders, policymakers, and standardization bodies to build credibility and encourage broad adoption. • Support for SMEs Simplify certification processes, providing tailored resources, toolkits, and cost-effective solutions to reduce entry barriers. • Education and Awareness Conduct campaigns, webinars, and training sessions to inform stakeholders about cybersecurity certification and the value of COBALT. • Incentives for Early Adoption Introduce pilot programs, reduced fees, and expert support to encourage early adopters and showcase the framework’s benefits. 8.1.2 Timeline and Milestones for Widespread Uptake COBALT’s adoption strategy can follow a phased approach, ensuring a structured transition from pilot implementations to full-scale deployment across industries and regions. The roadmap outlines key milestones, balancing short-term impact with long-term sustainability to maximize industry engagement and regulatory alignment. Phase 1: Foundation and Early Adoption (Months 1-12) The initial phase focuses on strengthening the framework’s foundation, finalizing key certification models, and demonstrating early successes. Pilot programs can be launched with selected industry partners, including AI, Quantum Computing, and Industry 4.0 stakeholders, to refine certification processes and gather real-world
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 85 insights. Engagement with regulatory bodies and standardization organization can be prioritized to ensure compliance with EU and international cybersecurity standards. Key Milestones: • Development of the Common Certification Model (CCM) and Common Certification Language (CCL). • Selection and onboarding of pilot partners across AI, Quantum Computing, and Industry 4.0. • Initial stakeholder workshops with EU policymakers, standardization bodies and industry leaders. • Implementation of first certification pilots, testing methodology, processes, and compliance. • Development of training materials and guidance toolkits for early adopters (i.e. SMEs). Phase 2: Expansion and Regulatory Alignment (Months 13-24) Building on the insights from the pilot phase, COBALT can scale its certification framework, expanding partnerships and increasing industry participation. Efforts can focus, in this phase, on ensuring regulatory alignment with EU cybersecurity policies such as Cybersecurity Act, AI Act, and NIS2 Directive. Targeted training sessions, awareness campaigns, and technical support programs can drive adoption among a broader set of key stakeholders. Key Milestones: • Formal integration and endorsement discussions with EU regulatory and certification bodies. • Expansion of certification programs to additional industries, including finance, healthcare and critical infrastructure. • Strategic collaborations with European cybersecurity initiatives, innovation clusters, and industrial alliances. Phase 3: Market Consolidation and Sustainability (Months 25-36) In the final phase, COBALT will establish its certification framework as an industry standard, ensuring long-term sustainability through structured governance and international outreach. Lessons learned from pilot deployments will inform continuous improvement strategies, while engagement with global stakeholders will position COBALT as a reference model beyond Europe. Key Milestones: • Integration of COBALT certifications into procurement processes and compliance requirements of major industries. • Establishment of a long-term governance structure model for maintaining and evolving the certification framework post-project. • Expansion of the framework’s reach, targeting global alignment with ISO/IEC and NIST cybersecurity standards. • Final impact assessment report, evaluating industry adoption, regulatory acceptance, and economic benefits. • Sustainability and funding strategy for continued operation and certification framework evolution beyond COBALT’s official duration.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 86 8.2 Alignment with EU Policy Goals and Global Standards The objectives of COBALT are aligned with Europe’s vision for secure and sustainable development. By supporting the Digital Decade initiative, COBALT is helping to create a digitally inclusive Europe where all entities regardless of size or nature of their operations have access to secure and trusted ICT systems. Similar to that is its energy performance and waste minimization, which correspond with the European Green Deal, proving that cybersecurity can also contribute to climate action. 8.2.1 EU Digital Policy Integration COBALT is designed with and support major EU regulatory and strategic initiatives ensuring its certification framework contributes to meaningfully to Europe’s broader cybersecurity, digital transformation, and data protection goals. By integrating legislative requirements, COBALT not only ensures compliance but also enhances the trustworthiness and resilience of digital infrastructures across various industries. • Cybersecurity Act COBALT plays a key role in advancing the objectives of the EU Cybersecurity Act, which establishes a panEuropean cybersecurity certification framework to enhance trust in ICT products, services, and processes. By developing the Common Certification Model (CCM) and Common Certification Language (CCL), COBALT directly contributes to the creation of harmonized certification schemes, facilitating cross-border trust and reducing fragmentation in cybersecurity assurance. Additionally, COBALT ensures that certification remains scalable, adaptable, and applicable to emerging technologies, particularly in Industrial AI and Quantum Computing, where existing certification approaches remain limited. • AI Act COBALT supports EU AI Act by addressing the cybersecurity risks associated with Industrial AI applications. The AI Act introduces a risk-based approach to AI regulation, requiring high-risk AI systems to meet strict security, transparency, and risk management requirements. COBALT’s certification framework complements this by ensuring: - Compliance with ISO/IEC 42001, ensuring AI management systems integrate security-by-design principles. - A structured methodology for assessing the cybersecurity posture of AI-driven solutions. - Alignment with GDPR and NIS2, ensuring AI systems are not only secure but also privacy compliant. • Digital Decade Strategy COBALT aligns with the EU Digital Decade Strategy, which sets the 2030 Digital Compass targets, aiming to establish Europe’s leadership in secure and resilient digital infrastructure. COBALT contributes to the digital sovereignty objective by: - Strengthening the cybersecurity of critical sectors (e.g. finance, healthcare, and industrial manufacturing). - Enabling secure cross-border data sharing and trusted digital transactions. - Facilitating the adoption of certification mechanisms that enhance the competitiveness of European businesses in global market. • GDPR (General Data Protection Regulation)
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 87 Ensuring data security and privacy compliance is a fundamental aspect of COBALT’s certification framework. By embedding GDPR-aligned requirements, COBALT supports organizations in demonstrating compliance with data protection regulations through: - Implementing certification schemes that enforce privacy-by-design principles. - Enhancing data governance practices, particularly for AI and quantum-based solutions handling sensitive personal data. - Supporting cross-border data flows while ensuring compliance with GDPR’s security provisions. • NIS2 Directive COBALT’s cybersecurity framework is aligned with the NIS2 Directive’s objectives, which strengthens cybersecurity risk management and reporting obligations across essential and important entities. By integrating COBALT’s certification model into industry best practices, organizations can: - Enhance their resilience against cyber threats through structured risk assessments and mitigations strategies. - Streamline compliance with incident reporting requirement, ensuring timely and effective responses to cyber incidents. - Align with sector-specific security controls, reinforcing the directive’s goal of securing the EU’s digital infrastructure. 8.2.2 Adapting COBALT to Global Certification Standards To ensure interoperability and international relevance, COBALT can be further designed to align and integrate and with recognized global cybersecurity standards, enabling seamless integration into both the EU and non-EU regulatory environments. • ISO/IEC Standards COBALT incorporates best practices from ISO/IEC standards, ensuring a structured, industry-accepted approach to cybersecurity certification: - ISO/IEC 27001 (Information Security Management Systems - ISMS): COBALT integrates ISMS principles to help organizations establish and maintain a risk-based approach to cybersecurity management. - ISO/IEC 42001 (AI Management Systems): As one of the first global standards for AI governance, this standard ensures secure, ethical, and compliant AI deployments, aligning with COBALT’s objectives in Industrial AI certification. - ISO 9001 (Quality Management Systems - QMS): By incorporating quality management principles, COBALT ensures its certification processes remain consistent, reliable, and adaptable to evolving industry needs. - ISO/IEC 15408 (Common Criteria for IT Security Evaluation): This internationally recognized framework provides structured methodologies for assessing the security functionalities of ICT products, aligning with COBALT’s approach to certification. • NIST Cybersecurity framework COBALT references NIST Cybersecurity Framework (CSF) to ensure compatibility with globally recognized cybersecurity best practices. The NIST CSF provides a flexible, risk-based approach to managing cybersecurity risks, and COBALT aligns with its key pillars:
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 88 - Identify: COBALT’s risk evaluation framework aligns with NIST’s risk assessment methodologies enabling organizations to identify cybersecurity risks in ICT environments. - Protect: COBALT incorporates NIST’s security controls, ensuring certified products and services meet rigorous security-by-design principles. - Detect: COBALT aligns with NIST’s threat detection mechanisms, enhancing security monitoring capabilities for certified solutions. - Respond: COBALT certification ensures organizations adopt incident response best practices, consistent with NIST’s guidelines. - Recover: COBALT promotes resilience-building measures, supporting organizations in achieving faster recovery from cyber incidents. 8.2.3 Contribution to Global Cybersecurity Harmonization COBALT aims to foster international cooperation and regulatory harmonization, ensuring that its certification framework is recognized and widely applicable. By engaging with international regulatory bodies, industry partners, and certification authorities, COBALT will: • Promote mutual recognition of cybersecurity certifications, reducing compliance burdens for organizations. • Facilitate the interoperability of certification frameworks, enabling cross-border trust and ensuring a cohesive global cybersecurity landscape. • Establish collaborations with global cybersecurity initiatives such as the European Agency for Cybersecurity (ENISA), and regional certification authorities. By integrating EU policies, international standards, and best practices, COBALT positions itself as a comprehensive, future-proof certification framework, enhancing cybersecurity resilience, regulatory compliance, and market trust across diverse industries and geographies. 8.3 Monitoring and Evaluation The monitoring and evaluation of COBALT’s progress will rely on the existing robust framework of KPIs already established within the project. To ensure meaningful assessment and actionable insights without introducing additional metrics, the focus will be on: • Qualitative Assessments Regularly gather stakeholder feedback through interviews, workshops, and surveys to assess user satisfaction, perceived value, and adoption challenges. • Progress Reviews Conduct periodic reviews of project milestones, deliverables, and ongoing activities to ensure alignment with overall objectives and timelines. • Impact Analysis Evaluate the real-world impact of COBALT by analysing success stories, case studies, and pilot outcomes across key sectors. • Continuous Improvement Use insights from evaluations to refine processes, enhance stakeholders’ engagement, and address sectorspecific need effectively.
Deliverable D6.2 – Socio-Economical sustainability analysis ecosystem report © COBALT Consortium 89 9 Summary of findings and Recommendations Building on the analysis in previous sections, this section will provide concrete recommendations for ensuring the socio-economic sustainability of the COBALT framework. These recommendations will focus on regulatory alignment, market integration, financial models, workforce development, and technological adaptability. The report will suggest strategies for maximizing the impact of COBALT’s KERs, by addressing socio-economic challenges and leveraging opportunities in the broader ICT landscape. 9.1 Summary of Key Findings The sustainability analysis of COBALT highlights the growing need for a standardized cybersecurity certification framework in an increasingly interconnected digital landscape. As industries adopt advanced technologies such as AI, Quantum Computing, and Industry 4.0, the demand for a harmonized and trusted certification model becomes more pressing. COBALT addresses this need by enhancing security, transparency, and compliance across multiple ICT sectors. A key challenge identified is the need for tailored support for SMEs, which often face barriers in adopting certification frameworks due to resource constraints. To facilitate SME adoption, simplified processes, financial incentives, and targeted guidance are necessary. Additionally, strategic partnerships with industry leaders, policymakers, and standardization bodies will drive adoption and regulatory recognition. COBALT’s alignment with EU policy goals (e.g., Cybersecurity Act, AI Act, NIS2 Directive) strengthens its credibility and positions it as a globally relevant framework. By adhering to ISO/IEC and NIST standards, COBALT facilitates cross-border recognition, reducing compliance burdens for businesses operating internationally. Beyond regulatory aspects, COBALT leverages Digital Twin technology and decentralized processing for realtime risk assessment and proactive threat mitigation. This innovation enhances cybersecurity resilience by enabling organizations to simulate cyber threats before they materialize. To ensure widespread adoption, a structured roadmap with clear short-, mid-, and long-term milestones is essential. The transition from pilot programs to full-scale implementation must be supported by industry engagement, awareness campaigns, and practical demonstrations of COBALT’s value. Continuous monitoring and evaluation will be critical in adapting to emerging threats and technological advancements. From a socioeconomic perspective, cybersecurity certification is not just a technical requirement but a strategic enabler for businesses, improving market access, regulatory compliance, and operational security. Demonstrating clear economic benefits will reinforce COBALT’s relevance and encourage sustained industry participation. A community-driven approach, through knowledge-sharing initiatives and collaborative ecosystems, will further enhance trust and adaptability. COBALT’s long-term sustainability depends on a combination of regulatory alignment, strategic partnerships, technological adaptability, and stakeholder engagement. By addressing these factors, COBALT can establish itself as a trusted and indispensable cybersecurity certification framework that delivers lasting value across industries and regions. 9.2 Strategies for Enhancing Socio-Economic Sustainability To enhance the socio-economic sustainability of COBALT, several strategies can be implemented to maximize its impact. Below are some suggestions: • Support SMEs through specialized initiatives: - Provide tailored certification pathways to minimize complexity and cost.