
On 20 January 2026, the European Commission proposed a new package of measures focusing on cybersecurity.
Part of this package is the revised Cybersecurity Act (CSA2), which addresses risks in information and communication technology supply chains, in particular risks related to high-risk suppliers from third countries. The main objective of the proposal is to strengthen the cyber resilience of critical infrastructure through a horizontal framework for the security of trusted information and communication technology (ICT) supply chains.
The proposal also amends the EU cybersecurity certification framework so that certification schemes would, as a rule, be developed within 12 months, through a renewed European Cybersecurity Certification Framework (ECCF). These schemes, managed by the EU Agency for Cybersecurity (ENISA), are to become a voluntary tool enabling businesses to demonstrate compliance with EU rules.
At the same time, the package introduces amendments to the NIS2 Directive on cybersecurity, aimed primarily at simplifying compliance with the rules and risk management requirements, while also introducing a new category of small mid-cap enterprises.
The CSA2 proposal is designed as a complement to the forthcoming Cloud and AI Development Act (CADA) and the Digital Omnibus.
The Cybersecurity Act itself would become directly applicable immediately upon adoption by the European Parliament and the Council, while Member States would have one year from the adoption of the accompanying amendments to the NIS2 Directive to transpose them into national law.
Spring Digital Legal Update 2026 here.