Don’t have time to read the full article? Plug in your earphones and listen to it instead!
0:00
-4:20
Welcome back to the INSTAR Interview Series, where we explore the work of experts shaping Europe's digital and cybersecurity future.
This week, we spoke with Octavian Popescu, a CYBERSTAND.eu-funded expert and an active contributor to European cybersecurity standardisation. Octavian is involved in CEN/CLC/JTC 13 Working Groups 8 and 9 and ETSI TC CYBER. His current work focuses on developing standards to support the Cyber Resilience Act (CRA).
In this interview, Octavian shares his perspective on the current landscape, the unique moment Europe is experiencing in aligning regulation with technological change, and the global balancing act between security and open markets.
"In my case, I'm focused on delivering Horizontal Standards mostly in CEN/CLC/JTC 13/WG 9, and then trying to put the basis for the work of what it is right now seen as the vertical standards."
Octavian's role within the second Specific Service Procedure of CYBERSTAND.eu is central to a coordinated response to the Cyber Resilience Act. He is engaged in building out horizontal standards — foundational frameworks that will underpin the development of more specific, product-oriented vertical standards.
Although the work responding directly to the new Standardisation Request (SR) is just beginning, the groundwork was laid much earlier. Within CEN-CENELEC Joint Technical Committee 13, Working Group 9 comprises three project teams, each tasked with preparing elements of these horizontal standards.
This preparatory phase is critical. As Octavian points out, the process may be at an early stage formally, but substantive activity has been underway for some time.
"From my perspective, this is a particularly significant moment because we’re at the cutting edge of regulatory work, where efforts to develop new standards are closely aligned with emerging technologies and the societal challenges we’re facing today."
According to Octavian, we are witnessing an inflection point. The regulatory and standardisation communities must come together to build a framework that meets both the technical demands of emerging technologies and the expectations of European society.
The Cyber Resilience Act has the potential to strengthen the European digital market, but only if it's implemented with careful attention to security and user protection. Regulators are acutely aware of their role in maintaining this balance.
"The safety and security are the first priorities of the market regulators."
This moment demands that all available resources be mobilised. What’s at stake is not just regulatory compliance, but the future trust of European citizens in their digital infrastructure.
"We're having a lot of challenges in finding the right balance between regulatory requirements and open market dynamics."
Europe does not operate in isolation. Octavian acknowledges the growing complexity of international alignment. On one hand, Europe must enforce strong cybersecurity requirements; on the other, it must preserve its commitments to open markets and international cooperation.
Other countries, including the UK, US, Canada, Australia, and New Zealand, have taken a more voluntary approach to cybersecurity. This divergence highlights the challenge for the EU: how to ensure robust protection without discouraging companies from entering the European market.
"I think we need to find a balanced approach: one that doesn’t put EU users at risk by ignoring cybersecurity requirements in products, but also doesn’t discourage distributors from bringing their products to the European market."
This tension becomes even more visible when considering the compliance procedures. If conformity assessments for digital products require approval from notified bodies, demand on those organisations may spike significantly.
"That, in turn, could become another bottleneck in the process of bringing secure products to the European market."
"These are complex issues, but also exciting times. I'm glad to be part of the conversation."
As a contributor to both the technical drafting of standards and the broader strategic discourse, Octavian Popescu plays a key role in shaping how cybersecurity resilience is built into European products and policies.
The INSTAR project is proud to highlight this kind of expertise — a blend of technical precision and regulatory foresight.
Stay tuned for our next interview, and thank you for reading.
💬 Want more insights like these delivered straight to your inbox?
Subscribe to the INSTAR Interview Series here on Substack and don’t miss a single update.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.