Proposal for a revised Cybersecurity Act (CSA2)

April 2026

DIGI LU 2

On 20 January 2026, the European Commission proposed a new package of measures focusing on cybersecurity.

Part of this package is the revised Cybersecurity Act (CSA2), which addresses risks in information and communication technology supply chains, in particular risks related to high-risk suppliers from third countries. The main objective of the proposal is to strengthen the cyber resilience of critical infrastructure through a horizontal framework for the security of trusted information and communication technology (ICT) supply chains.

The proposal also amends the EU cybersecurity certification framework so that certification schemes would, as a rule, be developed within 12 months, through a renewed European Cybersecurity Certification Framework (ECCF). These schemes, managed by the EU Agency for Cybersecurity (ENISA), are to become a voluntary tool enabling businesses to demonstrate compliance with EU rules.

At the same time, the package introduces amendments to the NIS2 Directive on cybersecurity, aimed primarily at simplifying compliance with the rules and risk management requirements, while also introducing a new category of small mid-cap enterprises.

The CSA2 proposal is designed as a complement to the forthcoming Cloud and AI Development Act (CADA) and the Digital Omnibus.

The Cybersecurity Act itself would become directly applicable immediately upon adoption by the European Parliament and the Council, while Member States would have one year from the adoption of the accompanying amendments to the NIS2 Directive to transpose them into national law.

Spring Digital Legal Update 2026 here.

The information contained in this bulletin is presented to the best of our knowledge and belief at the time of going to press. However, specific information related to the topics covered in this bulletin should be consulted before any decision is made. The information contained in this bulle-tin should not be construed as an exhaustive description of the relevant issues and any possible consequences, and should not be fully relied on in any decision-making processes or treated as a substitute for specific legal ad-vice, which would be relevant to particular circumstances. Neither Weinhold Legal, s.r.o. advokátní kancelář nor any individual lawyer listed as an author of the information accepts any responsibility for any detriment which may arise from reliance on information published here. Fur-thermore, it should be noted that there may be various legal opinions on some of the issues raised in this bulletin due to the ambiguity of the relevant provisions and an interpre-tation other than the one we give us may prevail in the future.

Automatic text and data mining, as well as reproduction or extraction of their content for the purposes of automated analysis from this information material, is prohibited pursuant to Article 4 of Directive (EU) 2019/790 and Section 39c of Act No. 121/2000 Coll., the Copyright Act, without the prior express written consent of Weinhold Legal, s.r.o., law firm, unless, in any such use, the authorship of Weinhold Legal, s.r.o., law firm is expressly acknowledged together with a reference to the location of such text and data.

© 2025 Weinhold Legal

All rights reserved.

Get in touch
with us

Office Prague 

View on Map

Office Brno

View on Map

Get in touch with us

Get the news from the world of law

How we handle personal data is described here.

Omlouváme se, ale pro tuhle stránku neexistuje překlad