Cyber Solidarity Act

← All instruments
in forcehorizontal
Type
regulation
Layer
horizontal
Status
in force
In force
2025-01-15
Last verified
2026-07-16

Cyber Solidarity Act — EU-level detection and response

Regulation (EU) 2025/38. While NIS2 tells individual organisations to secure themselves, the Cyber Solidarity Act builds collective, EU-level muscle to detect large-scale threats early and respond to major incidents together. Adopted in the same January-2025 package as the Cybersecurity Act’s managed-security-services amendment.

Three components

1. European Cybersecurity Alert System (“Cyber Shield”)

A pan-EU network of cross-border Security Operations Centres (SOCs) — national and cross-border cyber hubs using advanced tooling (AI, threat intelligence) to detect and share signals of threats and incidents quickly across borders. The aim is a shared early-warning picture rather than 27 isolated views.

2. Cyber Emergency Mechanism

Preparedness and mutual assistance for significant/large-scale incidents:

  • coordinated preparedness testing of entities in highly critical sectors (health, energy, etc.) for common vulnerabilities;
  • an EU Cybersecurity Reserve — incident-response services from pre-vetted trusted private providers, deployable on request by a Member State, EU institution, or an affected third country under an association agreement;
  • mutual assistance between Member States.

3. Cybersecurity Incident Review Mechanism

Structured after-action review of significant incidents — ENISA (at the request of the Commission, EU-CyCLONe or the CSIRTs Network) assesses lessons learned and recommends improvements, feeding back into policy.

Who runs it

ENISA and the EU-level cooperation networks (CSIRTs Network, EU-CyCLONe) sit at the centre; Member States host and connect the SOCs. The Reserve is contracted from trusted managed security service providers — a direct link to the Cybersecurity Act’s new certification scheme for such services.

Why it matters

It shifts part of cybersecurity from a purely national/organisational duty to a shared-defence posture: pooled detection, a standing incident-response reserve, and institutionalised learning. For an organisation, the practical touchpoints are the threat intelligence flowing from the SOC network and (for critical-sector entities) the possibility of coordinated preparedness testing.

Interplay

  • NIS2 / CER: operational backing for the entities and authorities those directives create.
  • Cybersecurity Act: the Reserve draws on trusted providers certifiable under the new managed-security-services schemes.
  • CSA2 proposal: further strengthens ENISA’s operational role, incl. ransomware support with Europol.

Sources