EU Cybersecurity Act Revision (CSA2)

Commission proposal of 20 January 2026 recasting the 2019 Cybersecurity Act: ICT supply-chain security, simplified certification schemes, a stronger ENISA, and targeted NIS2 amendments. In Parliament and Council negotiation through 2026.

JurisdictionEuropean Union
CategoryCybersecurity
StatusProposed
Latest development

Analysis

The Cybersecurity Act 2.0 (CSA2) is a proposal, not yet in force, so all requirements and dates are subject to change during Parliament/Council negotiations. Core details come from the European Commission proposal and associated EU institutional documents such as the recast Regulation proposal and impact assessment, and from authoritative summaries by the European Parliament and EU-level bodies.

Below I focus on what the Commission proposed on 20 January 2026, how it interacts with NIS2, and practical implications, with direct links in every section.


Key Requirements (as proposed in CSA2)

1. Trusted ICT supply‑chain security framework for critical sectors

  • Under CSA2, the Commission would conduct EU‑level risk assessments of ICT supply chains, identify key ICT assets, and analyse both technical and non‑technical risks (including foreign interference, ownership/control structures, and dependence on third‑country suppliers).
  • Risk‑assessment and ICT supply‑chain provisions are described in Articles on ICT supply‑chain security in the proposal as summarised by the European Parliament Research Service: Revision of the Cybersecurity Act – EPRS Briefing788144_EN.pdf)
  • Impact assessment for CSA2: Commission Staff Working Document SWD(2026) 11 – Impact Assessment

2. Simplified and strengthened European Cybersecurity Certification Framework (ECCF)

3. Stronger and broader mandate for ENISA

4. Targeted NIS2 amendments and simplification measures

  • Alongside CSA2, the Commission tabled a proposal to amend NIS2 to:
  • Clarify scope and sector coverage
  • Align technical measures with CSA2 certification and supply‑chain framework
  • Introduce certification‑based compliance routes
  • Simplify reporting and supervision processes and reinforce ENISA’s role.
  • NIS2 text: Directive (EU) 2022/2555 – NIS2
  • Overview of the NIS2 simplification proposal: European Commission Proposes Targeted Amendments to NIS2

Compliance Challenges

Because CSA2 is still a proposal, challenges are derived from impact assessments, legal analyses, and industry commentary.

1. Complexity of ICT supply‑chain mapping and risk assessment

  • Organizations will need to identify “key ICT assets” in their supply chains, understand dependencies on third‑country suppliers, and assess both technical and non‑technical risks – a substantial analytical and data‑collection burden.
  • Description of key ICT assets and high‑risk suppliers: EU Cybersecurity Act 2.0 proposal: new trade controls
  • Commission impact assessment discussion of sectoral risk assessments: SWD(2026) 11 – Impact Assessment

2. Certification adoption and scheme alignment

  • While certification remains formally voluntary in the CSA2 proposal, industry expects de facto obligations as certification becomes a preferred route to demonstrate compliance with NIS2 and other sector‑specific requirements.
  • Jones Day’s explanation of certification‑based presumption of conformity with NIS2: EU Commission Proposes Revised Cybersecurity Act
  • ISC2 perspective on how CSA2 certification will be used by organizations: EU CSA2 and NIS2 Updates – ISC2

3. Governance and coordination with ENISA and national authorities


Implementation Best Practices (for organizations preparing for CSA2)

Because CSA2 is not yet law, best practices focus on preparing for its likely direction and leveraging existing NIS2 and certification frameworks.

1. Establish end‑to‑end ICT supply‑chain visibility

  • Implement supply‑chain risk methodologies aligned with NIS2 and ENISA guidance, covering technical risks (vulnerabilities, patching, secure development) and non‑technical risks (jurisdiction, ownership, geopolitical exposure).
  • NIS2 security requirements: Directive (EU) 2022/2555 – NIS2
  • ENISA guidance on supply‑chain cybersecurity (background): ENISA – Cybersecurity in the Supply Chain

2. Use existing EU certification schemes and prepare for CSA2 alignment

3. Strengthen incident management and reporting in line with ENISA’s evolving role

  • Prepare for EU‑level incident reporting and coordination, including:
  • Centralized logging and incident management platforms
  • Clear internal workflows to respond to ENISA alerts and guidance
  • Capability to feed data into EU repositories while managing privacy and regulatory constraints.
  • ENISA incident coordination information: ENISA – CSIRT Network
  • Discussion of ENISA’s unified incident notification platform in CSA2: EU Commission Proposes Revised Cybersecurity Act – Jones Day
  • Incorporate data‑protection safeguards compatible

Recent developments

  • — The European Parliament’s legislative train notes that on 2026-01-20 the Commission published the **Cybersecurity Act revision (CSA2)** as part of a new cybersecurity package, aiming to clarify ENISA’s mandate, improve the European Cybersecurity Certification Framework (ECCF), and introduce measures for secure and resilient ICT supply chains, including restrictions and phase‑out obligations for high‑risk vendors’ components in electronic communications networks[2][1]. (source)
  • — Jones Day reports that CSA2 is advancing through the EU legislative process with a proposed horizontal framework for ICT supply‑chain security; it would empower the Commission to designate “high‑risk” third‑country‑linked suppliers, triggering exclusion from EU funding, standardization, procurement, and mandatory phase‑out of their equipment across critical sectors, while some Member States raise concerns over EU competence and the breadth of these powers[10]. (source)
  • — An EPRS (European Parliament Research Service) briefing on the **Cybersecurity Act Revision (CSA2)** explains that the proposal repeals and replaces the 2019 Cybersecurity Act, reforms ENISA and the ECCF, and establishes a horizontal framework to address non‑technical security risks in critical ICT supply chains, alongside targeted amendments to the NIS2 Directive[1][3]. (source)
  • — ISC2’s June 2026 analysis of CSA2 and NIS2 proposals highlights four core reforms: a new EU framework for ICT supply‑chain security with powers to classify high‑risk third‑country‑controlled suppliers, a simplified and time‑bounded certification framework including “cyber posture” certifications linked to NIS2, voluntary EU‑level individual cybersecurity skills attestations, and a reinforced ENISA with over 75% budget increase and expanded operational roles; ISC2 broadly welcomes the ambition but flags implications for organizations’ compliance and skills needs[5]. (source)
  • — Council documentation on COM(2026)11 related to CSA2 discusses recognition of the European cybersecurity certification framework across all Member States and legal details of the proposed regulation, indicating early Council‑level examination of automatic mutual recognition and harmonization mechanisms for EU‑wide cybersecurity certifications[11]. (source)
  • — A joint opinion by the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) on the CSA2 proposal assesses the Commission’s draft regulation on ENISA, the certification framework, and ICT supply‑chain security, focusing on fundamental rights, data protection, and governance issues raised by expanded EU powers to classify high‑risk suppliers and manage cross‑border cybersecurity risks[9]. (source)
  • — Cullen International’s legal update describes how CSA2 would introduce binding 12‑month timelines for developing certification schemes, expand the ECCF to include “cyber posture” certifications to ease NIS2 compliance for cross‑border operators, and strengthen ENISA’s role in guidance and promotion of certification, thereby reducing fragmentation and providing clearer obligations for ICT product and service providers[6]. (source)
  • — McDermott Will & Emery’s February 2026 article on the new EU cybersecurity package explains that the CSA2 proposal and NIS2 amendments have entered the legislative process, with trilogue negotiations expected and a target of political agreement by early 2027; it stresses that once adopted CSA2 will apply directly in the EU and will significantly strengthen ENISA, streamline certification, and impose new supply‑chain security obligations on companies[4]. (source)
  • — CMS’s overview of the new cybersecurity package notes that CSA2 aims to strengthen EU cyber resilience by reducing regulatory fragmentation, supporting faster and clearer compliance, and raising security across critical sectors through an updated certification framework and robust ICT supply‑chain security rules, impacting telecoms, cloud, and other ICT‑dependent industries[7][8]. (source)
  • — Inside Privacy’s analysis of the Commission’s CSA2 proposal details that the regulation would replace the 2019 Cybersecurity Act, introduce the EU’s first horizontal ICT supply‑chain security framework with significant consequences for organizations sourcing components from high‑risk jurisdictions, update and expand the ECCF, and substantially broaden ENISA’s mandate, with companies urged to assess future procurement, certification, and compliance impacts[13]. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates