Cyber Solidarity Act
Cyber Solidarity Act — EU-level detection and response
Regulation (EU) 2025/38. While NIS2 tells individual organisations to secure themselves, the Cyber Solidarity Act builds collective, EU-level muscle to detect large-scale threats early and respond to major incidents together. Adopted in the same January-2025 package as the Cybersecurity Act’s managed-security-services amendment.
Three components
1. European Cybersecurity Alert System (“Cyber Shield”)
A pan-EU network of cross-border Security Operations Centres (SOCs) — national and cross-border cyber hubs using advanced tooling (AI, threat intelligence) to detect and share signals of threats and incidents quickly across borders. The aim is a shared early-warning picture rather than 27 isolated views.
2. Cyber Emergency Mechanism
Preparedness and mutual assistance for significant/large-scale incidents:
- coordinated preparedness testing of entities in highly critical sectors (health, energy, etc.) for common vulnerabilities;
- an EU Cybersecurity Reserve — incident-response services from pre-vetted trusted private providers, deployable on request by a Member State, EU institution, or an affected third country under an association agreement;
- mutual assistance between Member States.
3. Cybersecurity Incident Review Mechanism
Structured after-action review of significant incidents — ENISA (at the request of the Commission, EU-CyCLONe or the CSIRTs Network) assesses lessons learned and recommends improvements, feeding back into policy.
Who runs it
ENISA and the EU-level cooperation networks (CSIRTs Network, EU-CyCLONe) sit at the centre; Member States host and connect the SOCs. The Reserve is contracted from trusted managed security service providers — a direct link to the Cybersecurity Act’s new certification scheme for such services.
Why it matters
It shifts part of cybersecurity from a purely national/organisational duty to a shared-defence posture: pooled detection, a standing incident-response reserve, and institutionalised learning. For an organisation, the practical touchpoints are the threat intelligence flowing from the SOC network and (for critical-sector entities) the possibility of coordinated preparedness testing.
Interplay
- NIS2 / CER: operational backing for the entities and authorities those directives create.
- Cybersecurity Act: the Reserve draws on trusted providers certifiable under the new managed-security-services schemes.
- CSA2 proposal: further strengthens ENISA’s operational role, incl. ransomware support with Europol.