EU Cybersecurity Act Revision (CSA2)
Commission proposal of 20 January 2026 recasting the 2019 Cybersecurity Act: ICT supply-chain security, simplified certification schemes, a stronger ENISA, and targeted NIS2 amendments. In Parliament and Council negotiation through 2026.
| Jurisdiction | European Union |
|---|---|
| Category | Cybersecurity |
| Status | Proposed |
| Latest development |
Analysis
The Cybersecurity Act 2.0 (CSA2) is a proposal, not yet in force, so all requirements and dates are subject to change during Parliament/Council negotiations. Core details come from the European Commission proposal and associated EU institutional documents such as the recast Regulation proposal and impact assessment, and from authoritative summaries by the European Parliament and EU-level bodies.
Below I focus on what the Commission proposed on 20 January 2026, how it interacts with NIS2, and practical implications, with direct links in every section.
Key Requirements (as proposed in CSA2)
1. Trusted ICT supply‑chain security framework for critical sectors
- The proposal establishes a horizontal EU framework for ICT supply‑chain security covering critical sectors already listed in the NIS2 Directive (EU) 2022/2555, including energy, transport, banking, health, digital infrastructure and others.
- See the Commission’s Cybersecurity Act policy page: EU Cybersecurity Act – Shaping Europe’s digital future
- NIS2 sector list: Directive (EU) 2022/2555 – NIS2
- Under CSA2, the Commission would conduct EU‑level risk assessments of ICT supply chains, identify key ICT assets, and analyse both technical and non‑technical risks (including foreign interference, ownership/control structures, and dependence on third‑country suppliers).
- Risk‑assessment and ICT supply‑chain provisions are described in Articles on ICT supply‑chain security in the proposal as summarised by the European Parliament Research Service: Revision of the Cybersecurity Act – EPRS Briefing788144_EN.pdf)
- Impact assessment for CSA2: Commission Staff Working Document SWD(2026) 11 – Impact Assessment
- The Commission gains powers to designate high‑risk suppliers and “concerning” third countries, and to restrict or phase out their ICT products/services in critical sectors if they present non‑technical risks (such as undue state influence or security law obligations in foreign jurisdictions).
- See description of high‑risk supplier designations and trade restrictions: EU Cybersecurity Act 2.0 proposal – new trade controls
- Legal analysis of Commission designation powers under CSA2: European Commission proposes major cybersecurity package – Mayer Brown
2. Simplified and strengthened European Cybersecurity Certification Framework (ECCF)
- CSA2 recasts the 2019 Cybersecurity Act to simplify and enhance the EU cybersecurity certification framework, making certification more usable as a compliance tool for NIS2 and other EU laws.
- Commission overview of certification framework: EU Cybersecurity Act – Certification
- EPRS summary of CSA2 certification changes: Cybersecurity Act Revision (CSA2) – European Parliament briefing789345_EN.pdf)
- Certification scope is extended beyond ICT products/services/processes to cover an entity’s overall cybersecurity posture, creating a presumption of conformity with NIS2 technical and organisational measures where schemes are aligned.
- Detailed explanation of extended certification scope and presumption of conformity: EU Commission Proposes Revised Cybersecurity Act – Jones Day
- Interaction with NIS2 simplification and certification‑based compliance pathways: European Commission Proposes Targeted Amendments to NIS2
- CSA2 introduces clear procedures and timelines for developing EU certification schemes, including a default 12‑month deadline for ENISA to prepare candidate schemes after a Commission request, to avoid lengthy delays.
- Description of 12‑month timeline and scheme governance: EU Commission Proposes Revised Cybersecurity Act – Jones Day
- EPRS note on improving governance and procedures of ECCF: Revision of the Cybersecurity Act – EPRS Briefing788144_EN.pdf)
3. Stronger and broader mandate for ENISA
- CSA2 redefines and strengthens the mandate of ENISA, the EU Agency for Cybersecurity, including roles in:
- EU‑level threat and incident monitoring and repositories
- Early alerts on significant threats
- Support for incident reporting, including a unified platform
- Assistance with ransomware response and recovery
- Expanded role in designing and operating cybersecurity certification schemes.
- ENISA’s general role: ENISA – European Union Agency for Cybersecurity
- Changes proposed in CSA2: Cybersecurity Act 2 – ENISA and certification overview – Acquis
- The proposal also addresses ENISA’s governance and procedures (e.g., Management Board, cooperation with national authorities, role in NIS2 supervision), aiming at clearer coordination with Member States.
- EPRS discussion of ENISA governance improvements: Revision of the Cybersecurity Act – EPRS Briefing788144_EN.pdf)
- Joint opinion by the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) on CSA2 and ENISA’s functions: EDPB‑EDPS Joint Opinion 4/2026 on Cybersecurity Act 2 proposals
4. Targeted NIS2 amendments and simplification measures
- Alongside CSA2, the Commission tabled a proposal to amend NIS2 to:
- Clarify scope and sector coverage
- Align technical measures with CSA2 certification and supply‑chain framework
- Introduce certification‑based compliance routes
- Simplify reporting and supervision processes and reinforce ENISA’s role.
- NIS2 text: Directive (EU) 2022/2555 – NIS2
- Overview of the NIS2 simplification proposal: European Commission Proposes Targeted Amendments to NIS2
- The EDPB‑EDPS Joint Opinion confirms there are two proposals in the package: one Regulation (CSA2) and one Directive amending NIS2, both published on 20 January 2026.
- See: EDPB‑EDPS Joint Opinion 4/2026
- Additional summary: EU CSA2 and NIS2 Updates – ISC2
Compliance Challenges
Because CSA2 is still a proposal, challenges are derived from impact assessments, legal analyses, and industry commentary.
1. Complexity of ICT supply‑chain mapping and risk assessment
- Organizations will need to identify “key ICT assets” in their supply chains, understand dependencies on third‑country suppliers, and assess both technical and non‑technical risks – a substantial analytical and data‑collection burden.
- Description of key ICT assets and high‑risk suppliers: EU Cybersecurity Act 2.0 proposal: new trade controls
- Commission impact assessment discussion of sectoral risk assessments: SWD(2026) 11 – Impact Assessment
- Firms operating critical infrastructure may face frequent reassessments as the Commission updates designations of high‑risk suppliers, adding compliance volatility and possible procurement disruption.
- Analysis of designation and phase‑out mechanisms: Strengthening EU cyber resilience – CMS Law overview
- Mayer Brown’s assessment of potential procurement and trade impacts: European Commission Proposes Major Cybersecurity Package
2. Certification adoption and scheme alignment
- While certification remains formally voluntary in the CSA2 proposal, industry expects de facto obligations as certification becomes a preferred route to demonstrate compliance with NIS2 and other sector‑specific requirements.
- Jones Day’s explanation of certification‑based presumption of conformity with NIS2: EU Commission Proposes Revised Cybersecurity Act
- ISC2 perspective on how CSA2 certification will be used by organizations: EU CSA2 and NIS2 Updates – ISC2
- Organizations may face overlap between multiple EU schemes (CSA2, NIS2, sectoral regulations and potentially the Cyber Resilience Act) and struggle with scheme selection, governance, and maintenance.
- EPRS discussion of overlapping EU cybersecurity instruments: Revision of the Cybersecurity Act – EPRS Briefing788144_EN.pdf)
- Commission policy context page: EU Cybersecurity Act – Shaping Europe’s digital future
3. Governance and coordination with ENISA and national authorities
- ENISA’s expanded mandate means entities may need to adapt incident reporting processes, coordinate with EU‑level platforms, and align with new guidance from ENISA on supply‑chain and certification issues.
- Outline of ENISA’s unified incident notification role: EU Commission Proposes Revised Cybersecurity Act – Jones Day
- ENISA’s broader role in CSA2 supply‑chain framework and certification: Your Guide to the Proposal for the Cybersecurity Act 2 – Acquis
- The EDPB‑EDPS Joint Opinion notes privacy and data‑protection implications of centralized threat/incident data, highlighting governance challenges around data sharing and oversight.
- See data‑protection concerns: EDPB‑EDPS Joint Opinion 4/2026
- ENISA’s existing incident cooperation role: ENISA – Cyber incidents and reporting
Implementation Best Practices (for organizations preparing for CSA2)
Because CSA2 is not yet law, best practices focus on preparing for its likely direction and leveraging existing NIS2 and certification frameworks.
1. Establish end‑to‑end ICT supply‑chain visibility
- Develop a comprehensive inventory of ICT assets and suppliers across critical functions, aligning with the CSA2 concept of key ICT assets in critical sectors.
- Definition and examples of key ICT assets: EU Cybersecurity Act 2.0 proposal – new trade controls
- Risk‑based supply‑chain framework description: Strengthening EU Cyber Resilience – CMS Law
- Implement supply‑chain risk methodologies aligned with NIS2 and ENISA guidance, covering technical risks (vulnerabilities, patching, secure development) and non‑technical risks (jurisdiction, ownership, geopolitical exposure).
- NIS2 security requirements: Directive (EU) 2022/2555 – NIS2
- ENISA guidance on supply‑chain cybersecurity (background): ENISA – Cybersecurity in the Supply Chain
2. Use existing EU certification schemes and prepare for CSA2 alignment
- Start adopting current EU cybersecurity certification schemes (e.g., EUCC for cloud, EUCS where applicable, or other schemes under the existing Cybersecurity Act) to build internal processes and governance for certification.
- Current EU cybersecurity certification framework: EU Cybersecurity Certification Framework – European Commission
- ENISA role in candidate schemes: ENISA – Certification
- Design internal controls such that certification can demonstrate compliance with NIS2 and anticipated CSA2 requirements (incident handling, secure development, supply‑chain risk, continuous monitoring).
- Link between certification and presumption of conformity with NIS2: EU Commission Proposes Revised Cybersecurity Act – Jones Day
- NIS2 core security measures: Directive (EU) 2022/2555 – NIS2
3. Strengthen incident management and reporting in line with ENISA’s evolving role
- Prepare for EU‑level incident reporting and coordination, including:
- Centralized logging and incident management platforms
- Clear internal workflows to respond to ENISA alerts and guidance
- Capability to feed data into EU repositories while managing privacy and regulatory constraints.
- ENISA incident coordination information: ENISA – CSIRT Network
- Discussion of ENISA’s unified incident notification platform in CSA2: EU Commission Proposes Revised Cybersecurity Act – Jones Day
- Incorporate data‑protection safeguards compatible
Recent developments
- — The European Parliament’s legislative train notes that on 2026-01-20 the Commission published the **Cybersecurity Act revision (CSA2)** as part of a new cybersecurity package, aiming to clarify ENISA’s mandate, improve the European Cybersecurity Certification Framework (ECCF), and introduce measures for secure and resilient ICT supply chains, including restrictions and phase‑out obligations for high‑risk vendors’ components in electronic communications networks[2][1]. (source)
- — Jones Day reports that CSA2 is advancing through the EU legislative process with a proposed horizontal framework for ICT supply‑chain security; it would empower the Commission to designate “high‑risk” third‑country‑linked suppliers, triggering exclusion from EU funding, standardization, procurement, and mandatory phase‑out of their equipment across critical sectors, while some Member States raise concerns over EU competence and the breadth of these powers[10]. (source)
- — An EPRS (European Parliament Research Service) briefing on the **Cybersecurity Act Revision (CSA2)** explains that the proposal repeals and replaces the 2019 Cybersecurity Act, reforms ENISA and the ECCF, and establishes a horizontal framework to address non‑technical security risks in critical ICT supply chains, alongside targeted amendments to the NIS2 Directive[1][3]. (source)
- — ISC2’s June 2026 analysis of CSA2 and NIS2 proposals highlights four core reforms: a new EU framework for ICT supply‑chain security with powers to classify high‑risk third‑country‑controlled suppliers, a simplified and time‑bounded certification framework including “cyber posture” certifications linked to NIS2, voluntary EU‑level individual cybersecurity skills attestations, and a reinforced ENISA with over 75% budget increase and expanded operational roles; ISC2 broadly welcomes the ambition but flags implications for organizations’ compliance and skills needs[5]. (source)
- — Council documentation on COM(2026)11 related to CSA2 discusses recognition of the European cybersecurity certification framework across all Member States and legal details of the proposed regulation, indicating early Council‑level examination of automatic mutual recognition and harmonization mechanisms for EU‑wide cybersecurity certifications[11]. (source)
- — A joint opinion by the European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) on the CSA2 proposal assesses the Commission’s draft regulation on ENISA, the certification framework, and ICT supply‑chain security, focusing on fundamental rights, data protection, and governance issues raised by expanded EU powers to classify high‑risk suppliers and manage cross‑border cybersecurity risks[9]. (source)
- — Cullen International’s legal update describes how CSA2 would introduce binding 12‑month timelines for developing certification schemes, expand the ECCF to include “cyber posture” certifications to ease NIS2 compliance for cross‑border operators, and strengthen ENISA’s role in guidance and promotion of certification, thereby reducing fragmentation and providing clearer obligations for ICT product and service providers[6]. (source)
- — McDermott Will & Emery’s February 2026 article on the new EU cybersecurity package explains that the CSA2 proposal and NIS2 amendments have entered the legislative process, with trilogue negotiations expected and a target of political agreement by early 2027; it stresses that once adopted CSA2 will apply directly in the EU and will significantly strengthen ENISA, streamline certification, and impose new supply‑chain security obligations on companies[4]. (source)
- — CMS’s overview of the new cybersecurity package notes that CSA2 aims to strengthen EU cyber resilience by reducing regulatory fragmentation, supporting faster and clearer compliance, and raising security across critical sectors through an updated certification framework and robust ICT supply‑chain security rules, impacting telecoms, cloud, and other ICT‑dependent industries[7][8]. (source)
- — Inside Privacy’s analysis of the Commission’s CSA2 proposal details that the regulation would replace the 2019 Cybersecurity Act, introduce the EU’s first horizontal ICT supply‑chain security framework with significant consequences for organizations sourcing components from high‑risk jurisdictions, update and expand the ECCF, and substantially broaden ENISA’s mandate, with companies urged to assess future procurement, certification, and compliance impacts[13]. (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
Put it into practice
- Generate the policy: NIST CSF policy generator (generatepolicy.com)
- Buy the policy pack: Enterprise Security Bundle (cyberpolicy.shop)
- Build it yourself: Compliance Program Starter (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates