Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogCompliance
EU Cybersecurity Act 2.0: What the January 2026 Proposal Means for Global Organizations

EU Cybersecurity Act 2.0: What the January 2026 Proposal Means for Global Organizations

The EU's January 2026 cybersecurity package reshapes compliance for global organizations. Discover what's changing, what's required, and how to update your strategy now.

August 7, 202612 min readBy Adil Karam

Your 2026 EU compliance roadmap is already obsolete. If your organization sells to, operates in, or processes data from the European Union, the regulatory ground shifted fundamentally on January 20, 2026. The European Commission published a sweeping new cybersecurity package that day, and most global organizations are only beginning to understand what it requires of them. This is not an incremental update.

The package introduces measures to simplify compliance rules and risk-management requirements for organizations operating in the EU, composed of two parts: a proposal to replace the existing Cybersecurity Act 2019 with a new Cybersecurity Act 2 (CSA2) and a proposal to simplify the NIS2 Directive and align it with the proposed Cybersecurity Act 2.

The challenge for CEOs and boards is not understanding any single regulation in isolation. The challenge is that CSA2 does not arrive in a vacuum. It lands on top of DORA, which has been live since January 2025, a Cyber Resilience Act with enforcement beginning in late 2027, and NIS2 transposition still unfolding across EU member states. Each of these frameworks carries its own penalty regime, its own governance obligations, and its own timeline. Organizations that treat them as separate workstreams will pay the price in duplicated effort, regulatory gaps, and mounting fine exposure.

What the January 2026 Package Actually Contains

CSA2 is built around four pillars: a stronger mandate for ENISA; a reform of the European Cybersecurity Certification Framework; new rules for ICT supply chain cybersecurity; and simplified, coherent compliance by providing a single cybersecurity certification mechanism which can serve as proof of compliance throughout the EU.

The NIS2 amendments that accompany CSA2 are equally significant from a compliance workload perspective.

On January 20, 2026, the Commission proposed targeted amendments to the NIS2 Directive to increase legal clarity. The amendments will simplify compliance with EU cybersecurity rules and risk-management requirements for companies operating in the EU, easing compliance for 28,700 companies, including 6,200 micro and small-sized enterprises.

The word "simplify" should not be mistaken for "reduce."

The amendments reduce paperwork friction; they do not reduce enforcement. In the same quarter the Commission published its simplification proposals, regulators across the EU were already moving into active supervisory and enforcement phases under NIS2. Both things are true at once: compliance is getting easier to navigate, and the consequences of failing to navigate it are getting harder to ignore.

Framing CSA2 as a "simplification" initiative misses the strategic reality. The Commission is consolidating fragmented requirements into a unified governance architecture that will be harder to sidestep and easier to enforce at scale.

The Penalty Exposure No CFO Has Modeled

The fine structures across converging EU frameworks create a cumulative exposure that most finance teams have not calculated. Consider what a single security incident could trigger across overlapping regimes:

FrameworkMaximum PenaltyWho It Targets
NIS2€10M or 2% of global turnoverEssential & important entities in 18 sectors
Cyber Resilience Act€15M or 2.5% of global turnoverICT product manufacturers & software publishers
CSA2 Supply Chain (non-compliance)Up to 7% of global annual turnoverEntities using banned high-risk ICT suppliers
CSA2 Disclosure ViolationsUp to 1% of global annual turnoverAll entities subject to ICT supply chain measures
DORAVaries by jurisdiction; ECB can impose unlimited fines on significant institutionsFinancial sector entities

Infringements of CSA2 Article 103 supply chain measures are subject to a tiered penalty framework: up to 1% of total worldwide annual turnover for certain disclosure-related violations; up to 2% for other non-compliance; and up to 7% for the most serious infractions.

For a mid-market technology company with €500M in global revenue, the theoretical maximum exposure across NIS2, CRA, and CSA2 supply chain provisions simultaneously exceeds €70M. That number belongs in board materials, not legal footnotes.

Fines for essential entities can reach €10M or 2% of total worldwide annual turnover, whichever is higher, with potential management accountability measures for senior leadership in serious cases.

The personal liability dimension is the one most C-suite leaders underestimate. Under NIS2's existing management body accountability provisions, now reinforced by CSA2's governance architecture, executives face direct personal liability for cybersecurity governance failures. The question boards need to answer is not whether they are compliant. It is whether they can demonstrate governance oversight if a regulator asks.

ENISA: From Advisory Body to Operational Authority

The resourcing behind this reform signals that enforcement intent is real.

The revised act allocates an estimated €341 million for ENISA from 2028 to 2034, representing an 81.5% increase compared to ENISA's 2025 baseline, along with an increase to around 118 full-time employees.

Under the revised regulation, ENISA will manage European repositories of threats and incidents, issue EU-wide early warnings, coordinate cybersecurity exercises, and operate the unified incident notification platform envisioned by the Digital Omnibus package.

This operational pivot matters to private sector organizations because a more capable ENISA means faster threat intelligence, more rigorous certification scheme development, and a closer institutional relationship between ENISA and national competent authorities conducting supervisory reviews.

A comprehensive study commissioned by the European Commission and published in January 2026 found that the agency's mandate had expanded significantly over time without a commensurate increase in resources or formal powers, which limited its ability to deliver impact beyond advisory and coordination functions.

CSA2 corrects that structural imbalance deliberately.

The ICT Supply Chain Provisions: The Most Disruptive Element for Global Organizations

For non-EU organizations supplying software, hardware, or managed services to EU entities, the ICT supply chain provisions of CSA2 represent genuinely new legal territory.

CSA2 introduces the EU's first horizontal framework for ICT supply chain security, an entirely new addition not contained in the original Cybersecurity Act, with significant implications for organizations in sectors that procure components from providers located in high-risk jurisdictions.

This is the first time the EU is using a mandatory instrument to impose trade restrictions, grounded in geopolitical and national security concerns, affecting critical sectors' ICT supply chains.

The mechanism works as follows:

the European Commission aims to introduce EU-wide instruments to classify non-EU suppliers as "high risk" and prohibit their products and services in critical ICT components through implementing acts.

Non-technical risks include the likelihood of the supplier being subject to influence by a third country in ways that can disrupt the service provided or compromise the product manufactured to include concealed vulnerabilities. They also include instances linked to technological lock-in or supplier dependency, potentially affecting the availability of communication networks and electricity grids.

The phase-out timelines add operational urgency.

The Commission will be empowered to specify the time periods for phasing out each type of ICT component. For mobile networks, these periods shall not exceed 36 months from the publication of the high-risk supplier list.

Organizations with long-cycle procurement programs and multi-year vendor contracts need to begin supplier risk mapping now, not after high-risk designations are published.

Framework Alignment: How CSA2 Maps to Existing Standards

Organizations that have already invested in ISO 27001 or NIST CSF are not starting from zero, but they should not assume those certifications provide sufficient coverage. CSA2's certification schemes, once developed, will carry a presumption of NIS2 conformity, creating a direct efficiency incentive for organizations to pursue EU certification rather than relying solely on international frameworks.

The expanded certification scope covers cyber posture and managed security services, with a 12-month default scheme timeline, mandatory maintenance, and a presumption of conformity with NIS2.

The ENISA cybersecurity certification page provides the authoritative source for scheme development timelines as they evolve through the legislative process.

Standard / FrameworkCSA2 RelevanceGap to Address
ISO 27001:2022Strong foundation; maps to risk management and incident responseAdd EU-specific supply chain risk assessment per CSA2 Articles 98-117
NIST CSF 2.0Useful governance structure; recognized but not EU-certifiedCertification scheme equivalency not yet established
CIS Controls v8Technical controls baseline; well-aligned to NIS2 security measuresSupplement with management accountability documentation
DORA (financial sector)Direct sectoral overlap with CSA2 ICT third-party risk provisionsAlign ICT risk frameworks to avoid duplicative audits
Cyber Resilience ActProduct security requirements; separate but complementary to CSA2SBOMs, vulnerability disclosure, and conformity assessments required

Certification as a Market Access Requirement

Although CSA2 certification currently remains voluntary for businesses, the trajectory is clear.

CSA2 looks to address the limited uptake of the existing European cybersecurity certification framework with schemes expected to be simpler and quicker, within 12 months, to develop.

For SaaS providers and technology vendors operating in regulated EU sectors, certification will function as a de facto market access requirement long before any mandatory provisions take effect. Procurement teams at EU financial institutions, energy companies, and public administrations will demand it contractually.

Geopolitical Risk Enters the Compliance Function

CSA2 formally introduces geopolitical risk assessment into vendor management programs.

For the first time, the Commission would be able to designate third countries as posing cybersecurity concerns, ban or phase out certain suppliers, and impose EU-wide usage restrictions via implementing acts.

Compliance teams that have never conducted geopolitical risk assessments of their ICT vendors now need the capability to do so. This is not a security architecture exercise alone; it requires legal, procurement, and executive input.

NIS2 Transposition Creates a Patchwork That Certification Will Resolve

As of May 2026, 21 of 27 EU member states have transposed NIS2 into national law.

The six remaining member states create jurisdictional complexity for organizations operating across the bloc.

The Commission now aims to clarify the scope of the law, harmonize technical measures, introduce certification-based compliance pathways, and strengthen cross-border supervision through an expanded role for ENISA.

Organizations that wait for full transposition before acting will have missed 12 to 18 months of preparation time.

Legislative Timeline: Plan for Late 2026 to 2027

The proposals are expected to be adopted no earlier than late 2026 or early 2027. The Cybersecurity Act 2, as a regulation, will be directly applicable in all Member States, while the NIS2 amendments will need to be transposed into national law within one year.

That timeline is tighter than most organizations realize. Direct applicability as a regulation means CSA2 takes effect without any member-state transposition step, removing the buffer that NIS2's directive structure provided.

Board-Level Readiness Assessment: Where Does Your Organization Stand?

Use this checklist to identify your highest-priority gaps before implementation deadlines arrive.

Governance & Accountability

  • [ ] Board-level cybersecurity governance documented with clear C-suite ownership
  • [ ] Management liability exposure under NIS2 and CSA2 reviewed with legal counsel
  • [ ] Cybersecurity risk formally integrated into enterprise risk management framework
  • Compliance Program

  • [ ] NIS2 applicability confirmed across all EU operating entities and subsidiaries
  • [ ] DORA compliance program operating (financial sector) or scope exclusion confirmed
  • [ ] CRA obligations assessed for any software or connected products sold in the EU
  • [ ] CSA2 certification pathway identified for relevant ICT products, services, or processes
  • ICT Supply Chain

  • [ ] Vendor inventory completed for ICT suppliers serving EU critical sector operations
  • [ ] Geopolitical risk assessment process established for third-country ICT suppliers
  • [ ] Contractual flow-down requirements reviewed for EU customer agreements
  • [ ] Phase-out contingency plans initiated for any suppliers at high-risk designation risk
  • Incident Management

  • [ ] Incident reporting procedures aligned to NIS2's 24-hour early warning and 72-hour notification requirements
  • [ ] Cross-border incident coordination process defined for multi-member-state operations
  • [ ] Ransomware response capabilities documented per ENISA's expanded support mandate
  • Certification Readiness

  • [ ] Current certifications mapped against EU certification scheme equivalency
  • [ ] ISO 27001 or equivalent controls baseline validated against NIS2 security measures
  • [ ] ENISA certification scheme development timeline monitored for relevant sectors
  • Organizations that score fewer than 10 of these items as complete face material compliance gaps with real deadlines attached.

    How I Help

    The convergence of CSA2, NIS2, DORA, and the Cyber Resilience Act is not a compliance problem you solve with a checklist. It requires a structured program with executive sponsorship, clear ownership, and an approach that addresses all four frameworks simultaneously rather than sequentially.

    My Compliance & Certification practice is purpose-built for exactly this situation. I help organizations build unified EU compliance programs that map existing controls to NIS2, DORA, and CSA2 requirements, identify the shortest path to certification, and produce the board-level documentation that regulators and auditors expect. Whether you are preparing for an ISO 27001 gap assessment, building NIS2 readiness from scratch, or rationalizing overlapping DORA and CSA2 ICT risk obligations, I design programs that reduce duplication and accelerate defensible compliance, without building a full-time internal team for every regulation.

    For organizations that lack an internal security executive to own this program, my Fractional CISO service provides the strategic leadership to drive EU compliance governance at the C-suite level on a right-sized engagement model. Other supporting services include Board Advisory for governance documentation and director briefings, Security Architecture for ICT supply chain risk mapping, and AI Governance where AI systems intersect with CSA2 certification scope.

    The 30-minute EU compliance gap assessment I offer is the lowest-friction way to understand where your biggest exposure sits before implementation deadlines force your hand. No sales pitch, no commitment: just a clear-eyed view of where you stand against the frameworks that will define your EU market access through 2027 and beyond.

    Book your EU compliance gap assessment today before the legislative calendar closes the planning window.

    #EU Cybersecurity Act#Regulatory Compliance#GDPR#Risk Management#Cybersecurity Policy#Global Operations
    PDFShare:

    Adil Karam

    Security & AI Governance Advisor

    Helping organizations navigate security leadership and AI governance challenges.

    Ready to Put These Insights Into Action?

    Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.