Cybersecurity Act 2 (CSA2)

← All proposals

PROPOSAL

PROPOSAL
Reference
COM(2026) 11
Proposed
2026-01-20
Key date
proposed 2026-01-20
Last verified
2026-07-16

Cybersecurity Act 2 (CSA2) — proposed revision

Status: PROPOSAL. Published 20 January 2026 as the centrepiece of the EU Cybersecurity Package. In the ordinary legislative procedure (Parliament + Council); the Commission aimed for political agreement later in 2026. Text and timelines will change — verify before relying on any detail.

Proposal for a Regulation revising the Cybersecurity Act, which would repeal and replace Regulation 2019/881. Once adopted it would be immediately applicable, and it comes bundled with targeted NIS2 amendments (see nis2-amendments-2026.md).

The four pillars

1. A stronger ENISA

A substantially expanded mandate and more resources: ENISA as the single EU-level point of cybersecurity expertise; coordinating EU cybersecurity exercises; issuing early alerts; supporting ransomware response with Europol and the CSIRTs; developing a Union approach to vulnerability management; and operating the Single Entry Point for incident reporting proposed in the Digital Omnibus.

2. A reformed certification framework (ECCF)

The under-used framework would be streamlined: clearer governance, and candidate schemes developed within ~12 months of a Commission request by default. The headline innovation is “cyber posture certification” — certifying an organisation’s overall cybersecurity risk-management (not just a product), which NIS2 entities could use as proof of compliance / presumption of conformity with NIS2 and other EU rules, reducing duplicative audits. High-risk-jurisdiction suppliers would be ineligible for certification.

3. A horizontal ICT supply-chain security framework

A first in EU law: address non-technical supply-chain risks. The Commission could designate third countries posing cybersecurity concerns and identify/restrict/ exclude high-risk suppliers and key ICT assets used by NIS2 entities — weighing technical and non-technical factors (e.g. third-country influence over a supplier) — across ~18 critical sectors. It would enable mandatory de-risking of mobile telecom networks from high-risk third-country suppliers, building on the 5G Toolbox.

4. Simplified, coherent compliance

Certification as a single, cross-cutting proof of compliance aligned across NIS2, CRA, DORA and sector rules — fewer duplicative activities, a more predictable environment.

Who it would affect most

Manufacturers/providers of ICT products and services (broader, more harmonised certification); companies using critical technologies (aligning risk management); operators in essential sectors (assessing exposure to high-risk suppliers); and newly flagged categories — digital wallet providers, submarine cable operators, dual-use infrastructure operators — should start assessing readiness.

Relationship to other files

  • Revises → ../10-eu-regulations/cybersecurity-act.md
  • Bundled with → nis2-amendments-2026.md
  • Complementary to → digital-omnibus-sep.md, and the upcoming Cloud and AI Development Act (CADA).

Practical prep (no-regret moves while it’s a proposal)

Gap assessments; supply-chain risk governance (map dependencies on suppliers that could be designated high-risk); certification readiness; track ENISA/ECCF developments.

Sources