EU Statement – UN Global Mechanism on ICTs in international security: First Substantive Session Key EU messages for Agenda item on Rules, norms and principles

22.07.2026
New York

21 July 2026, New York - Key EU messages for Agenda item: Rules, norms and principles of responsible behaviour of States and the ways for their implementation at the Global Mechanism on developments in the field of ICTs in the context of international security and advancing responsible State behaviour in the use of ICTs First Substantive Session (20 – 24 July 2026)

 

  1. Chair, colleagues, I have the honour to speak on behalf of the European Union and its Member States.

    The Candidate Countries North Macedonia, Montenegro*, Serbia*, Albania*, Ukraine, the Republic of Moldova, Bosnia and Herzegovina* and Georgia, and the EFTA country Norway, member of the European Economic Area, as well as San Marino align themselves with this statement.
  2. The European Union and its Member States reaffirm their strong commitment to the full and effective implementation of the United Nations framework of responsible State behaviour in cyberspace.

  3. As part of the framework, the 11 voluntary non-binding norms of responsible State behaviour constitute a central pillar for maintaining international security and stability. The practical implementation of the norms contributes to enhanced transparency, predictability and accountability of State conduct in cyberspace.

  4. Adherence to the norms reduces the risk of misperception and escalation, strengthens trust among States, and supports the secure and resilient functioning of critical infrastructures and digital services upon which modern societies depend.

  5. The 11 voluntary, non-binding norms of responsible State behaviour in cyberspace were first agreed upon by the 2015 United Nations group-of-governmental experts in 2015 and subsequently endorsed by consensus at the General Assembly in 2015 through resolution 70/237.

  6. The 11 cyber norms were reaffirmed at the Open-ended Working Groups (OEWG) on security of and in the use of information and communications technologies 2019–2021, and 2021–2025.

  7. In view of the actionable work by UN Member States on the implementation of the UN norms under the UN Global Mechanism, the EU and its Member States presented ahead of the Plenary session to UN Member States an initial overview of the EU’s efforts to implement the norms of responsible state behaviour.

  8. For this contribution, we used the consensus norms guidance included in the 2021 report of the UN Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace in the Context of International Security, detailing the main legislation, policies, structures and mechanisms the EU has put in place.

  9. For instance, as regards Norm 13(b) – In case of ICT incidents, States should consider all relevant information, including the larger context of the event the challenges of attribution in the ICT environment and the nature and extent of the consequences – the EU has put in place legislation, policies, structures and mechanisms to gain a comprehensive understanding of the cyber threat landscape and enable relevant authorities to consider all relevant information.

  10. At Union level, the most relevant EU level actors that contribute to shared situational awareness are the EU member states and their national agencies, the European Commission (EC), the European External Action Service (EEAS), including its Single Intelligence and Analysis Capacity (SIAC), the EU Agency for Cybersecurity (ENISA), the Cybersecurity Service for the Union’s institutions (CERT-EU), and Europol’s European Cybercrime Centre (EC3).

  11. Under the framework of NIS2, the Member States and EU actors cooperate at the strategic, operational and technical level and have created cooperation structures at each level, such as the NIS cooperation group, the CSIRTs Network and EU-CyCLONe.

  12. Based on their shared situational awareness, these EU actors work together to consider all relevant information and provide a comprehensive assessment of cyber incidents and crisis, in view of an appropriate response. To further enhance the EU’s situational awareness, the EU has put in place cooperative mechanisms with the multi-stakeholder community, including through ENISA’s Cyber Partnership Programme (CPP).

  13. Based on this shared situational awareness, the EU and its 27 Member States could decide upon using diplomatic measures under its EU Cyber Diplomacy Toolbox, including attribution.

  14. The agreed principles for such response include for instance the need for the response to be based on a shared situational awareness among the Member States, and for the response to be proportionate to the scope, scale, duration, intensity, complexity, sophistication and impact of the cyber activity.

  15. Like this, we have elaborated on each norm, using the UNGGE norms guidance, detailing the main efforts by the EU in implementing the UN norms of responsible state behaviour.

  16. We aim to further work to detail these efforts, including by providing more insights in the efforts by individual EU Member States in the implementation at national level, notably in the fields of capacity building and assistance in mitigation and recovery after malicious ICT activity.

  17. This EU contribution complements the 2024 Declaration by the EU and Member States on the application of international law in cyberspace, which outlines the common understanding by the EU and its Member States on international law applicable to cyberspace, as we should not forget that voluntary norms do not exist in isolation; but they sit alongside international law.

  18. While norms are voluntary and non-binding, international law itself is binding. To take one example, international law prohibits the use of ICTs, including ransomware, to interfere coercively in the internal or external affairs of other states. The norms make it clear that states should not use ICT tools like ransomware to disrupt critical infrastructure.

  19. To further build our common understanding on the ways and means to implement the norms of responsible state behaviour, the EU and Member States encourage also other states in sharing their experiences in implementing the norms, which will help to enhance our implementation efforts, ultimately strengthening security in cyberspace for all.

  20. In addition to written contributions by States, the DTGs are best placed to elaborate on the implementation of the 11 norms connected to a specific cybersecurity challenge such as the protection of critical infrastructure or ransomware, to exchange best practices that could feed into recommendations.

  21. In this context we also see the draft Voluntary Norms Checklist as a valuable tool to take our work forward. In our view, the Voluntary Checklist should be treated as a living document and serve as the primary reference as states continue to implement the Framework. We could use the Checklist as a reference document facilitating our discussions in the DTGs, to which we look forward.

 

  1. North Macedonia, Montenegro, Serbia, Albania and Bosnia and Herzegovina continue to be part of the Stabilisation and Association Process.