On 6 August 2026, the Secretary-General of the Council approved the German cryptographic product SINA L2 Box S, version 3.4, for protecting EU classified information at the RESTREINT UE/EU RESTRICTED level. The approval, issued as an information note to delegations, permits EU institutions to use the device for data classified up to and including RESTREINT UE/EU RESTRICTED, provided that the evaluator's recommendations for product use are incorporated into the corresponding Security Operating Procedures. The decision does not cover higher classification levels.
The approval is based on Article 10(6) of the Council Security Rules, established by Council Decision 2013/488/EU of 23 September 2013. This legal framework governs the protection of EU classified information and allows the Council to approve specific cryptographic products for use within the EU institutions. The SINA L2 Box S, developed by German manufacturers, is designed to secure communications and data handling in sensitive environments.
The decision follows a standard evaluation process for cryptographic equipment, which assesses the product's security features against EU requirements. The approval is conditional: Security Operating Procedures must reflect the evaluator's usage recommendations to ensure the product is deployed securely. This condition aims to mitigate potential risks associated with the product's operational use.
The approval impacts several stakeholders. EU institutions and bodies that handle RESTREINT UE/EU RESTRICTED information can now adopt the SINA L2 Box S, potentially improving interoperability and security in their communications. The German manufacturer gains a formal endorsement for its product within the EU market, which may enhance its commercial prospects. National authorities of EU member states, which often cooperate with EU institutions on classified matters, may also benefit from a common approved tool, though they are not obliged to use it. However, the condition requiring updates to Security Operating Procedures imposes an administrative burden on adopting entities, as they must review and adjust their procedures to align with the evaluator's recommendations.
The approval is a procedural step within the EU's security framework, reflecting ongoing efforts to maintain robust cryptographic standards. No further institutional follow-up is specified in the note, but the decision may influence future evaluations of similar products. The Council's action underscores the importance of secure information handling in EU operations, balancing the need for advanced technology with the imperative of safeguarding classified data.