Cybersecurity Act 2 (CSA2)
Cybersecurity Act 2 (CSA2) — proposed revision
Status: PROPOSAL. Published 20 January 2026 as the centrepiece of the EU Cybersecurity Package. In the ordinary legislative procedure (Parliament + Council); the Commission aimed for political agreement later in 2026. Text and timelines will change — verify before relying on any detail.
Proposal for a Regulation revising the Cybersecurity Act, which would repeal and
replace Regulation 2019/881. Once adopted it would be immediately applicable, and it
comes bundled with targeted NIS2 amendments (see nis2-amendments-2026.md).
The four pillars
1. A stronger ENISA
A substantially expanded mandate and more resources: ENISA as the single EU-level point of cybersecurity expertise; coordinating EU cybersecurity exercises; issuing early alerts; supporting ransomware response with Europol and the CSIRTs; developing a Union approach to vulnerability management; and operating the Single Entry Point for incident reporting proposed in the Digital Omnibus.
2. A reformed certification framework (ECCF)
The under-used framework would be streamlined: clearer governance, and candidate schemes developed within ~12 months of a Commission request by default. The headline innovation is “cyber posture certification” — certifying an organisation’s overall cybersecurity risk-management (not just a product), which NIS2 entities could use as proof of compliance / presumption of conformity with NIS2 and other EU rules, reducing duplicative audits. High-risk-jurisdiction suppliers would be ineligible for certification.
3. A horizontal ICT supply-chain security framework
A first in EU law: address non-technical supply-chain risks. The Commission could designate third countries posing cybersecurity concerns and identify/restrict/ exclude high-risk suppliers and key ICT assets used by NIS2 entities — weighing technical and non-technical factors (e.g. third-country influence over a supplier) — across ~18 critical sectors. It would enable mandatory de-risking of mobile telecom networks from high-risk third-country suppliers, building on the 5G Toolbox.
4. Simplified, coherent compliance
Certification as a single, cross-cutting proof of compliance aligned across NIS2, CRA, DORA and sector rules — fewer duplicative activities, a more predictable environment.
Who it would affect most
Manufacturers/providers of ICT products and services (broader, more harmonised certification); companies using critical technologies (aligning risk management); operators in essential sectors (assessing exposure to high-risk suppliers); and newly flagged categories — digital wallet providers, submarine cable operators, dual-use infrastructure operators — should start assessing readiness.
Relationship to other files
- Revises →
../10-eu-regulations/cybersecurity-act.md - Bundled with →
nis2-amendments-2026.md - Complementary to →
digital-omnibus-sep.md, and the upcoming Cloud and AI Development Act (CADA).
Practical prep (no-regret moves while it’s a proposal)
Gap assessments; supply-chain risk governance (map dependencies on suppliers that could be designated high-risk); certification readiness; track ENISA/ECCF developments.
Sources
- Proposal & annexes (COM(2026) 11): https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act
- Commission Cybersecurity Act page: https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act