EU Commission publishes Cybersecurity Act revision proposal
The Cybersecurity Act, adopted back in 2019, was meant to establish a high level of cybersecurity, cyber resilience, and trust across the EU. However, the cybersecurity landscape has significantly evolved since then with a surge of more sophisticated cyberattacks targeting critical infrastructure, businesses and the general public. Following calls by Mario Draghi in his “future of European Competitiveness” report in 2024 the EU Commission has worked to put cybersecurity at the center of its resilience agenda. The culmination of this work is now embodied by this new Cybersecurity legislative proposal which seeks to achieve two main goals:
The strengthening the European Union’s cybersecurity governance and helping relevant bodies to respond to cybersecurity threats in a coordinated and effective manner
supporting the development, implementation and uptake of common Union cybersecurity instruments, such as certification schemes, and providing harmonised frameworks that build trust and interoperability across Member States.
What’s in the proposal?
Clarifying the role of ENISA
The proposal clarifies and expands the role of the EU’s cybersecurity agency (ENISA) by giving it capacity building responsibilities to aid and assist member states, especially in the awareness raising activities. Additionally, the agency will contribute to promoting international cooperation.
ENISA would seek to achieve these goals by developing repositories of cyber threats and incidents (performing analysis and issuing early alerts), operating the “EU Cybersecurity reserve” and work alongside Europol, CSIRT and other competent authorities. It would also compile an annual rolling programme of EU level cybersecurity exercises, and provide a single reporting platform reporting cybersecurity incidents (as announced previously in the EU’s Digital Omnibus)
ENISA would also play a role in the development and implementation of the EU’s Cybersecurity Certification Framework.
The EU Cybersecurity Certification Framework
This act aims to establish a cybersecurity certification framework which would seek to harmonise approaches across the EU when it comes to certifying ICT products, services, processes, managed security services or cyber posture of entities. ENISA, under certain conditions will be in charge of developing a submitting a framework (which would need to be adopted by the EU Commission), and would support its development and maintenance by drawing up technical specifications
Trusted ICT supply chain framework
Most importantly, the legislative proposal establishes a mechanism to identify key ICT assets in critical ICT supply chains and sets out “appropriate and proportionate mitigation measures”.
The proposal also foresees the possibility of an emergency procedure if “an immediate intervention is justified to preserve the proper functioning of the internal market and where the Commission has sufficient reason to consider that there is a significant cyber threat for the security of the Union in relation to critical ICT supply chains”.
The proposal will allow for the EU Commission to designate whether certain “third countries” pose “serious and structural non-technical risks to ICT supply chains”. Entities established in such third countries, “or controlled by such third country, by an entity established in such third country, or by a national of such third country will not be allowed to carry out a number of activities”.
Additionally, the EU Commission, through implementing acts can decide that entities operating in sectors of high criticality and other critical sectors have to be subject to specific mitigating measures. It will also be given the power, through further implementing acts, the establishment of a list of “high-risk suppliers” which will be relevant for prohibitions and mitigation practices mentioned above.
The proposed act goes even further by seeking bolder action on the ICT supply chain framework for communication networks. Indeed, the legislation would force EU Member States to phase out ICT components from high-risk suppliers for key ICT assets in a period of time that should not exceed 36 months following the entry into force of the legislation.
What does this mean?
The proposal is of consequence as it was expected by some that the EU Commission would seek to reintroduce certification frameworks similar to the ones previously suggested under the EU’s Cloud Certification Schemes, which initially sought to embed degrees of sovereignty requirements as seen in France’s national SecNumCloud certification for cloud service providers. While this is not the case, we can expect that as the proposal undergoes the next legislative steps, the issue will likely resurface.
The proposal, through its annexes also makes clear that its assessments of critical sectors could covers areas such as semiconductors, cloud services, and medical devices. However the field of telecoms would likely be hit the hardest by the current proposal. Annex II indicates that all mobile and fixed network assets would be covered and would need to be replaced should they be considered to come from “high risk vendors”. This means that many EU Member States who still rely on Huawei and ZTE equipment would likely need to force network operators to phase out their equipment within a relatively short time frame.
Next steps
The proposal will now be sent to EU Member States and the European Parliament, where both sides will need to establish their negotiating positions before beginning interinstitutional negotiations and agreeing on a final version of the text. Do not hesitate to reach out to techUK should you have any questions on the proposal.
For more information, please contact:
Theophile Maiziere
Policy Manager - EU, techUK
Theophile Maiziere
Policy Manager - EU, techUK
Theo joined techUK in 2024 as EU Policy Manager. Based in Brussels, he works on our EU policy and engagement.
Theo is an experienced policy adviser who has helped connect EU and non-EU decision makers.
Prior to techUK, Theo worked at the EU delegation to Australia, the Israeli trade mission to the EU, and the City of London Corporation’s Brussels office. In his role, Theo ensures that techUK members are well-informed about EU policy, its origins, and its implications, while also facilitating valuable input to Brussels-based decision-makers.
Theo holds and LLM in International and European law, and an MA in European Studies, both from the University of Amsterdam.
techUK International Policy and Trade Programme activities
techUK supports members with their international trade plans and aspirations. We help members to understand market opportunities, tackle market access barriers, and build partnerships in their target market. Visit the programme page here.
International Trade Conference 2026 | Time to Trade: Taking UK Tech to the World in 2026
On 3 March, we will bring together tech experts, policy makers, academics and thought leaders at techUK’s flagship International Policy & Trade Conference
Our members develop strong networks, build meaningful partnerships and grow their businesses as we all work together to create a thriving environment where industry, government and stakeholders come together to realise the positive outcomes tech can deliver.
Sabina Ciofu is International Policy and Strategy Lead at techUK, where she heads the International Policy and Trade Programme. Based in Brussels, she shapes global tech policy, digital trade, and regulatory cooperation across the EU, US, Canada, Asia-Pacific, and the Gulf region. She drives strategy, advocacy, and market opportunities for UK tech companies worldwide, ensuring their voice is heard in international policy debates.
With nearly a decade of previous experience as a Policy Advisor in the European Parliament, Sabina brings deep expertise in tech regulation, trade policy, and EU–US relations. Her work focuses on navigating and influencing the global digital economy to deliver real impact for members.
A passionate community-builder, Sabina co-founded Young Professionals in Digital Policy (800+ members) and now runs Old Professionals in Digital Policy (more experience, better wine, earlier nights). She is also the founder of the Gentlewomen’s Club, a network of 500+ women supporting each other with kindness.
She holds advisory roles with the UCL European Institute, Café Transatlantique (a network of women in transatlantic tech policy), and The Nine, Brussels’ first members-only club for women.
Recognised by ComputerWeekly as one of the most influential women in UK tech, Sabina is also a sought-after public speaker on tech, trade and diversity.
Sabina holds an MA in War Studies from King’s College London and a BA in Classics from the University of Cambridge.
Senior Policy Manager for International Policy and Trade, techUK
Daniel Clarke
Senior Policy Manager for International Policy and Trade, techUK
Dan joined techUK as a Policy Manager for International Policy and Trade in March 2023.
Before techUK, Dan worked for data and consulting company GlobalData as an analyst of tech and geopolitics. He has also worked in public affairs, political polling, and has written freelance for the New Statesman and Investment Monitor.
Dan has a degree in MSc International Public Policy from University College London, and a BA Geography degree from the University of Sussex.
Outside of work, Dan is a big fan of football, cooking, going to see live music, and reading about international affairs.
Theo joined techUK in 2024 as EU Policy Manager. Based in Brussels, he works on our EU policy and engagement.
Theo is an experienced policy adviser who has helped connect EU and non-EU decision makers.
Prior to techUK, Theo worked at the EU delegation to Australia, the Israeli trade mission to the EU, and the City of London Corporation’s Brussels office. In his role, Theo ensures that techUK members are well-informed about EU policy, its origins, and its implications, while also facilitating valuable input to Brussels-based decision-makers.
Theo holds and LLM in International and European law, and an MA in European Studies, both from the University of Amsterdam.
Tess joined techUK as an Policy and Public Affairs Team Assistant in November of 2024. In this role, she supports areas such as administration, member communications and media content.
Before joining the Team, she gained experience working as an Intern in both campaign support for MPs and Councilors during the 2024 Local and General Election, and working for the Casimir Pulaski Foundation on defence and international secuirty. She has worked for multiple charities, on issues such as the climate crisis, educational inequality and Violence Against Women and Girls (VAWG). In 2023, Tess obtained her Bachelors of Arts in Politics and International Relations from the University of Nottingham.
Theo joined techUK in 2024 as EU Policy Manager. Based in Brussels, he works on our EU policy and engagement.
Theo is an experienced policy adviser who has helped connect EU and non-EU decision makers.
Prior to techUK, Theo worked at the EU delegation to Australia, the Israeli trade mission to the EU, and the City of London Corporation’s Brussels office. In his role, Theo ensures that techUK members are well-informed about EU policy, its origins, and its implications, while also facilitating valuable input to Brussels-based decision-makers.
Theo holds and LLM in International and European law, and an MA in European Studies, both from the University of Amsterdam.