European Cycling Industries (ECI) has launched its new Manifesto for a Safe and Compliant EU Market, calling on European institutions and national governments to take stronger action against non-compliant eBikes.
The Manifesto broadens the debate beyond eBike tampering to address the wider issue of non-compliant products reaching European consumers, particularly through online marketplaces. ECI said products are frequently sold directly by operators based outside the EU, with no identifiable entity within EU jurisdiction that can be held accountable for compliance.
The Manifesto calls on the European Commission, the European Parliament and Member States to ban the sale of EPAC tampering kits across the EU and establish a European evidence base on the road-safety and economic impacts of non-compliant eBikes.
It also calls for EU market surveillance rules to be strengthened and consistently enforced, including those covering online sales. ECI is also urging greater investment in local enforcement, training and technical capacity to enable authorities to identify and take action against non-compliant eBikes.
ECI said the issue also raises a “fundamental question of fair competition”, arguing that responsible manufacturers invest significantly in product safety, testing, certification, documentation and compliance with European regulations. These companies, it said, should not have to compete with operators that avoid those costs or fail to meet the same requirements.
ECI added that illegal and non-compliant eBikes that fail to meet European safety and technical requirements, or that have been modified to operate outside those requirements, can pose risks to riders and other road users. They can also undermine confidence in eBikes more broadly, it said.
Alongside the Manifesto, ECI members have renewed their commitment to tackling eBike tampering, with a more detailed position on anti-tampering measures.
The accompanying Position Paper sets out what ECI considers to be the “state of the art” in anti-tampering protection. Its annexes identify measures manufacturers should implement, including cryptographically verified software updates with anti-rollback protection, secure authentication between motor, controller and battery systems, sensor plausibility checks using multiple signals, tamper-resistant logging of critical parameter changes, and protected diagnostic and debug interfaces.
The Paper also identifies measures that ECI says do not meet this standard. These include user-accessible compliance changes through apps or service menus, simple on-bike unlocking using button combinations or default PINs, unsigned firmware, reliance on a single sensor signal, and security measures based solely on obscurity.
“The 2021 commitment established that this industry does not accept tampering,” said Paul Walsh, CEO of ECI. “We are taking it a step further with our related Position Paper. It gives manufacturers a concrete benchmark to design against, and it gives authorities and standardisation bodies a reference point for assessing whether a system is genuinely protected or just appears to be.”