logo

EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act

ID: 3b3f200d-fc4a-54a4-876c-56bfdb438d14

STIX ID: report--3b3f200d-fc4a-54a4-876c-56bfdb438d14

Feed Name: Infosecurity Magazine (News)

Date Published: 2026-01-21

Date Updated: 2026-04-22

...
...

The European Commission proposed Cybersecurity Act 2.0 to address shortcomings of the 2019 CSA by aligning policy with stakeholder needs, accelerating and simplifying EU cybersecurity certification (including default 12-month scheme development and presumption of conformity), and creating a trusted ICT supply chain security framework across 18 critical sectors. The proposal expands ENISA’s mandate to lead or support major incident response with the CSIRTs network, maintain an exercise repository with EU-CyCLONe, share non-sensitive threat intelligence, help vet critical tech suppliers, assess harmonized standards, and pilot a cybersecurity skills attestation scheme, while mandating the derisking of EU mobile networks from high-risk suppliers. It would apply immediately after adoption, with member states given one year to implement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.