Commission Cybersecurity Resilience and Capabilities Package
Commission Cybersecurity Resilience and Capabilities Package 2026
European Union
RAI-EU-NA-CYBERSE-2026The EU's 2026 Cybersecurity Package proposes a revised Cybersecurity Act and NIS2 amendments to bolster collective resilience and secure ICT supply chains.
Summary
The EU's 2026 Cybersecurity Resilience and Capabilities Package aims to significantly enhance the Union's collective cybersecurity posture against evolving global threats. It proposes a revised Cybersecurity Act (CSA2) to introduce the EU's first horizontal framework for ICT supply chain security and amends the NIS2 Directive for greater clarity and compliance. The package seeks to harmonize cybersecurity across Member States, strengthen ENISA's role, and protect critical infrastructure and democratic institutions from sophisticated cyberattacks.
Full article
Read full text ↗Overview
The Commission Cybersecurity Resilience and Capabilities Package 2026 represents a pivotal legislative initiative by the European Union to significantly enhance its collective cybersecurity posture against an increasingly complex and hostile global threat landscape. Proposed by the European Commission, this comprehensive package aims to bolster the EU's cybersecurity resilience and capabilities, ensuring the security of critical information and communication technologies (ICT) supply chains and protecting essential services and democratic institutions from sophisticated cyber and hybrid attacks. The initiative is a direct response to the evolving nature of cyber threats, which have grown in frequency, sophistication, and potential impact, targeting critical infrastructure, businesses, and the general public across Europe. It seeks to modernize and streamline the EU's existing cybersecurity framework, addressing fragmentation across the digital single market and reinforcing the role of key European cybersecurity bodies.
Central to this package is a proposal for a revised Cybersecurity Act, often referred to as 'Cybersecurity Act 2' (CSA2), which is designed to update and replace the previous Cybersecurity Act (Regulation 2019/881). This revision introduces the EU's first horizontal framework for ICT supply chain security, a crucial new addition that was not present in the original Act. This framework is expected to have substantial implications for organizations in sectors that rely on components from providers in high-risk jurisdictions, particularly in areas like telecommunications. Furthermore, the package includes proposed amendments to the NIS2 Directive, aiming to increase legal clarity, ease compliance for a vast number of companies, and streamline data collection on ransomware attacks. The overall objective is to foster a harmonized, proportionate, and risk-based approach to cybersecurity across all Member States, thereby strengthening the EU's ability to jointly identify and mitigate risks across its 18 critical sectors.
Definitions
Within the context of the Commission Cybersecurity Resilience and Capabilities Package 2026, several key terms are defined to ensure clarity and consistent application across Member States. 'Cybersecurity Resilience' refers to the ability of systems, networks, and organizations to withstand, recover from, and adapt to cyber incidents, maintaining their essential functions. This encompasses not only technical safeguards but also organizational processes, human factors, and strategic planning for continuous operation even under duress. The package emphasizes a proactive approach to resilience, moving beyond mere incident response to embed security by design and by default in all relevant ICT products and services.
Another fundamental concept is 'Critical ICT Supply Chains,' which denotes the interconnected network of entities, processes, and technologies involved in the development, manufacturing, distribution, and maintenance of information and communication technology products and services essential for the functioning of critical infrastructure and services within the EU. The package specifically addresses risks associated with third-country suppliers, particularly those posing 'serious and structural non-technical risks' due to potential foreign interference or critical dependencies. The definition of 'High-Risk Suppliers' is crucial, referring to entities that, following a Union-level coordinated security risk assessment, are deemed to pose significant cybersecurity concerns, potentially leading to targeted mitigation measures or prohibitions on their equipment in critical assets. The package also elaborates on the enhanced role of the 'EU Agency for Cybersecurity (ENISA),' defining its expanded responsibilities in capacity building, international cooperation, developing cyber threat repositories, operating the 'EU Cybersecurity reserve,' and overseeing the European Cybersecurity Certification Framework (ECCF).
Governance and Institutional Framework
The Commission Cybersecurity Resilience and Capabilities Package 2026 significantly strengthens the governance and institutional framework for cybersecurity across the European Union, primarily by expanding and clarifying the mandate of the EU Agency for Cybersecurity (ENISA). ENISA is poised to become a central pillar in the EU's cybersecurity architecture, taking on enhanced responsibilities that include capacity building to assist Member States, particularly in awareness-raising activities, and fostering international cooperation. The agency will be instrumental in developing repositories of cyber threats and incidents, performing in-depth analysis, and issuing early alerts to Member States and relevant stakeholders. Furthermore, ENISA will be responsible for operating the 'EU Cybersecurity reserve' and working in close collaboration with Europol, Computer Security Incident Response Teams (CSIRTs), and other competent authorities to ensure a coordinated and effective response to cybersecurity threats. This expanded role aims to overcome fragmentation and ensure a more unified approach to cybersecurity governance across the diverse national landscapes of the EU.
Beyond ENISA's reinforced position, the package establishes a more robust framework for coordinated action among Member States and the Commission. It introduces mechanisms for Union-level coordinated security risk assessments to identify and mitigate risks and vulnerabilities within specific ICT supply chains, particularly concerning third-country suppliers. This collaborative approach will enable the EU and its Member States to jointly address strategic risks of undue foreign interference and critical dependencies in critical ICT supply chains through targeted and proportionate measures. The Commission itself is granted increased powers, including the ability to designate certain 'third countries' as posing 'serious and structural non-technical risks' to ICT supply chains, which can trigger specific mitigation measures or prohibitions. This represents a significant step towards a more harmonized and centrally guided cybersecurity policy, ensuring that the EU can collectively respond to systemic risks that transcend national borders.
Key Focus Areas
The Commission Cybersecurity Resilience and Capabilities Package 2026 delineates several critical focus areas designed to comprehensively address the evolving cybersecurity landscape. A primary area of emphasis is the security of ICT supply chains, recognizing their fundamental importance to the functioning of critical services and infrastructure. The package introduces a horizontal framework for trusted ICT supply chain security, which aims to reduce risks from third-country suppliers with cybersecurity concerns. This involves establishing mechanisms to identify key ICT assets in critical supply chains and implementing appropriate mitigation measures, including the potential for emergency procedures in cases of significant cyber threats to the Union's security. The goal is to ensure that products and services reaching EU citizens are cyber-secure by design through a simpler certification process and to prevent operators of electronic communications networks from relying on high-risk suppliers for their critical assets.
Another significant focus is on strengthening cybersecurity capabilities and resilience across the EU. This involves enhancing the security of critical infrastructures and promoting a high level of security and trust in complex ICT supply chains for citizens, businesses, and public authorities. The package also aims to simplify compliance with existing EU cybersecurity rules and risk-management requirements for companies operating within the EU, complementing initiatives like the single-entry point for incident reporting. The revised European Cybersecurity Certification Framework (ECCF) is a key instrument in this regard, designed to make cybersecurity certification a more practical and efficient tool for companies, allowing certificates to serve as a presumption of conformity with EU law and accelerating the development of certification schemes. Furthermore, the package addresses the need for coordinated incident response and information sharing, with ENISA playing a central role in developing cyber threat repositories, performing analysis, issuing early alerts, and compiling an annual rolling program of EU-level cybersecurity exercises. These concerted efforts are intended to create a more robust and interconnected cybersecurity defense for the entire Union.
Implementation Framework
The implementation framework for the Commission Cybersecurity Resilience and Capabilities Package 2026 is structured to ensure a harmonized and effective application of its provisions across all European Union Member States. A central element of this framework is the revised European Cybersecurity Certification Framework (ECCF), which aims to streamline and simplify the process of cybersecurity certification for ICT products, services, and processes. The ECCF will facilitate the development of certification schemes within a shorter timeframe, typically 12 months, and introduce more agile and transparent governance to better involve stakeholders through public information and consultation. These certification schemes, managed by ENISA, are intended to be practical, voluntary tools for businesses to demonstrate compliance with EU legislation, thereby reducing administrative burdens and costs while fostering a high level of security and trust in complex ICT supply chains. The framework also envisions that certificates can serve as a presumption of conformity with EU law, further incentivizing their adoption and promoting a stronger single market for cyber-secure products and services.
Beyond certification, the implementation framework includes specific provisions for addressing risks in critical ICT supply chains. Member States will be required to phase out ICT components from high-risk suppliers for key ICT assets within a period not exceeding 36 months following the entry into force of the legislation. This measure underscores a robust sovereignty approach, empowering the European Commission to designate third countries posing serious and structural non-technical risks to ICT supply chains, following assessments by Member States and verification by the Commission. The framework also foresees the possibility of emergency procedures for immediate intervention to preserve the proper functioning of the internal market in the face of significant cyber threats. To support these efforts, ENISA's expanded role includes capacity building, international cooperation, and the operation of the 'EU Cybersecurity reserve,' providing Member States with resources and expertise to implement the package's requirements and enhance their national cybersecurity capabilities. The overall implementation strategy emphasizes a collaborative, risk-based, and proportionate approach to ensure a secure and resilient digital environment across the EU.
Monitoring and Evaluation
The monitoring and evaluation framework for the Commission Cybersecurity Resilience and Capabilities Package 2026 is designed to ensure continuous oversight of its effectiveness, identify areas for improvement, and adapt to the rapidly evolving cyber threat landscape. A key aspect of this framework involves ENISA's expanded role in collecting and analyzing data related to cyber threats and incidents. The agency will be responsible for developing repositories of cyber threats and incidents, performing in-depth analysis, and issuing early alerts, thereby providing crucial intelligence for ongoing monitoring. This data-driven approach will enable the Commission and Member States to assess the prevalence and impact of cyberattacks, evaluate the efficacy of implemented security measures, and identify emerging vulnerabilities across critical sectors. Regular reporting mechanisms will be established, requiring Member States to submit data on their cybersecurity posture, incident responses, and the implementation of the package's provisions, facilitating a comprehensive overview of the EU's collective cybersecurity resilience.
Furthermore, the package mandates periodic reviews of its provisions, including the effectiveness of the revised Cybersecurity Act and the European Cybersecurity Certification Framework. These reviews will assess whether the legislation is achieving its stated objectives of strengthening EU cybersecurity resilience and capabilities, enhancing ICT supply chain security, and preventing fragmentation across the digital single market. The monitoring process will also involve evaluating the impact of the measures on businesses, particularly small and medium-sized enterprises (SMEs), to ensure that compliance costs are proportionate and that the framework supports, rather than hinders, innovation. The Commission will leverage insights from ENISA's annual rolling program of EU-level cybersecurity exercises to test the preparedness and response capabilities of Member States and critical entities, providing valuable feedback for refining policies and operational procedures. This iterative process of monitoring, evaluation, and adaptation is crucial for maintaining a dynamic and effective cybersecurity framework in the face of persistent and evolving threats.
Penalties, Liability, and Appeals
The Commission Cybersecurity Resilience and Capabilities Package 2026 introduces a robust framework for penalties and liability, designed to ensure compliance and deter non-adherence to its stringent cybersecurity requirements. While the specific details of penalties will likely be further elaborated in national transpositions of the revised NIS2 Directive and the Cybersecurity Act, the overarching principle is to establish effective, proportionate, and dissuasive sanctions for infringements. For instance, the proposed amendments to the NIS2 Directive aim to increase legal clarity and ease compliance, but also imply a stronger enforcement regime for critical entities that fail to implement adequate cybersecurity measures or report incidents as required. Non-compliance with the obligations related to risk management, incident reporting, and supply chain security, particularly for critical entities and providers of essential services, is expected to incur significant administrative fines, similar to those seen in other major EU regulations. These penalties are intended to reflect the severity of the breach and its potential impact on the security of the Union and its citizens.
Regarding liability, the package is expected to clarify and potentially expand the legal responsibility of entities for cybersecurity incidents, especially concerning product security and supply chain vulnerabilities. The emphasis on 'security by design' and the enhanced European Cybersecurity Certification Framework (ECCF) imply a greater onus on manufacturers and service providers to ensure the inherent security of their ICT products and services before they enter the market. While the package may not introduce a completely new liability regime, it is likely to reinforce existing legal principles by making it easier to demonstrate a lack of due diligence or negligence in cybersecurity practices. This could lead to increased claims for damages from affected parties in the event of a cyber incident caused by inadequate security measures. The appeals process for penalties and other enforcement actions will typically follow national administrative and judicial procedures, ensuring due process and the right to a fair hearing for affected entities. The reinforced role of ENISA in monitoring and coordinating enforcement efforts will also contribute to a more consistent application of penalties across the EU, fostering a level playing field and ensuring that all entities are held to a high standard of cybersecurity accountability.
Relationship to Other Instruments
The Commission Cybersecurity Resilience and Capabilities Package 2026 is meticulously designed to operate in synergy with, and build upon, existing European Union legislative instruments, rather than creating an entirely isolated framework. A crucial relationship exists with the NIS2 Directive (Directive (EU) 2022/2555), which the package proposes to amend. These targeted amendments aim to increase legal clarity, simplify jurisdictional rules, streamline data collection on ransomware attacks, and facilitate the supervision of cross-border entities, with ENISA playing a reinforced coordinating role. The package seeks to ensure coherence and avoid duplication of efforts, recognizing that industry is already navigating overlapping cyber obligations under NIS2, the Cyber Resilience Act, and various sectoral rules. The intention is to create a more streamlined and effective cybersecurity rulebook, where the revised Cybersecurity Act and NIS2 amendments complement each other to provide a comprehensive and robust framework for digital security across the EU.
Furthermore, the package interacts significantly with the Digital Omnibus, particularly concerning the single-entry point for incident reporting. The measures introduced in the Cybersecurity Resilience and Capabilities Package are intended to complement this single-entry point, simplifying compliance with EU cybersecurity rules and risk-management requirements for companies. The Cyber Resilience Act (CRA) is another key piece of legislation with which the package seeks alignment. While the CRA focuses on ensuring cybersecurity for products with digital elements throughout their lifecycle, the revised Cybersecurity Act within this package focuses on enhancing the security of ICT supply chains and providing a framework for cybersecurity certification. The goal is to ensure that any new supply chain security measures are proportionate, justified by clear risk assessments, and designed to align seamlessly with existing frameworks like the CRA. This integrated approach aims to prevent regulatory fragmentation and ensure a cohesive and effective cybersecurity ecosystem across the EU, leveraging the strengths of each legislative instrument to achieve a higher collective level of digital security.
International Alignment
The Commission Cybersecurity Resilience and Capabilities Package 2026 places significant emphasis on international alignment, recognizing that cybersecurity threats transcend national borders and require a coordinated global response. The package aims to reinforce the European Union's stance towards nation-state cyber powers and fosters discussions among Member States on a robust sovereignty approach. This includes measures to address strategic risks of undue foreign interference and critical dependencies in critical ICT supply chains, particularly concerning third-country suppliers. The framework allows the EU and Member States to jointly identify and mitigate these risks, considering economic impacts and market supply, and ensures that operators of electronic communications networks do not rely on high-risk suppliers for their critical assets. This proactive stance on supply chain security is a clear signal of the EU's commitment to protecting its digital infrastructure from external threats and ensuring its strategic autonomy in the digital sphere.
Moreover, the package promotes international cooperation as a vital component of its overall strategy. ENISA's expanded role includes contributing to and promoting international cooperation, which is essential for sharing cyber threat intelligence, coordinating responses to cross-border incidents, and developing common cybersecurity standards. The revised European Cybersecurity Certification Framework (ECCF) is also designed with international alignment in mind, aiming to develop certification schemes that are aligned with international standards and offer mutual recognition with like-minded allies. This approach not only facilitates global trade in secure ICT products and services but also strengthens the EU's position as a reliable partner in international cybersecurity efforts. By actively engaging with international partners and promoting common standards and frameworks, the Commission Cybersecurity Resilience and Capabilities Package 2026 seeks to contribute to a more secure and resilient global cyberspace, addressing shared challenges through collaborative action and fostering trust in the digital ecosystem.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Commission Proposal for Package Adoption | 2026-01-19 | The European Commission officially proposed the comprehensive cybersecurity package, including the revised Cybersecurity Act and amendments to the NIS2 Directive. |
| European Parliament and Council Approval | 2026-12-31 | Expected approval by the European Parliament and the Council of the EU for the revised Cybersecurity Act and NIS2 Directive amendments. |
| Entry into Force of Revised Cybersecurity Act | 2027-01-01 | The revised Cybersecurity Act is expected to enter into force immediately after approval, establishing the new framework for ICT supply chain security and certification. |
| Member State Transposition of NIS2 Amendments | 2028-01-01 | Member States will have one year from the adoption of the NIS2 Directive amendments to transpose them into national law and notify the Commission. |
| Phase-out of High-Risk ICT Components | 2030-01-01 | Member States are expected to complete the phase-out of ICT components from high-risk suppliers for key ICT assets within 36 months of the legislation's entry into force. |
| First Review of Package Effectiveness | 2031-01-01 | Initial comprehensive review of the package's effectiveness, including the Cybersecurity Act and NIS2 amendments, to assess impact and identify areas for refinement. |
Sources and References
| Source | Type |
|---|---|
| Commission strengthens EU cybersecurity resilience and capabilities (Press Release) | official |
| Proposal for a Regulation for the EU Cybersecurity Act | legal |
| ENISA welcomes new EU cybersecurity package (Press Release) | government |
| COM(2026) 11 - Proposal for a Regulation for the EU Cybersecurity Act | legal |
| The EU Cybersecurity Act (Overview) | government |
Requirements for a company
What an organisation has to do under Commission Cybersecurity Resilience and Capabilities Package, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.
Must do
7- Phase out ICT components from high-risk suppliers for key ICT assets.Member States and entities using critical ICT assets.
- Embed security by design and by default in all relevant ICT products and services.Manufacturers and providers of ICT products and services.
- Identify and mitigate cybersecurity risks within ICT supply chains, particularly from third-country suppliers.Entities relying on critical ICT supply chains.
- Establish robust procedures for detecting, handling, and reporting cybersecurity incidents to authorities.Critical entities and providers of essential services.
- Prevent reliance on high-risk suppliers for critical assets in electronic communications networks.Operators of electronic communications networks.
- Comply with Union-level coordinated security risk assessments and resulting mitigation measures or prohibitions.Entities affected by Union-level risk assessments.
- +1 more in the table below
Must not do
0Nothing in this category.
Should do
3- Seek voluntary certification under the European Cybersecurity Certification Framework (ECCF) for relevant ICT products.Providers of ICT products, services, and processes.
- Engage in national and EU-level cybersecurity exercises to test and improve incident response capabilities.Member States and critical entities.
- Continuously monitor guidance from ENISA and national cybersecurity authorities for updates and best practices.All entities subject to the regulation.
Should not do
0Nothing in this category.
Who must do what
The obligations under Commission Cybersecurity Resilience and Capabilities Package, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Member States and entities using critical ICT assets. | Phase out ICT components from high-risk suppliers for key ICT assets. “Member States will be required to phase out ICT components from high-risk suppliers for key ICT assets within a period not exceeding 36 months...” | Jan 1, 2030 | — | Critical |
| 2 | Manufacturers and providers of ICT products and services. | Embed security by design and by default in all relevant ICT products and services. “The package emphasizes a proactive approach to resilience, moving beyond mere incident response to embed security by design and by default in all relevant ICT products and services.” | Before placing on market | — | Critical |
| 3 | Entities relying on critical ICT supply chains. | Identify and mitigate cybersecurity risks within ICT supply chains, particularly from third-country suppliers. “The package introduces a horizontal framework for trusted ICT supply chain security, which aims to reduce risks from third-country suppliers with cybersecurity concerns.” | Jan 1, 2027 | — | Critical |
| 4 | Critical entities and providers of essential services. | Establish robust procedures for detecting, handling, and reporting cybersecurity incidents to authorities. “Non-compliance with the obligations related to risk management, incident reporting, and supply chain security... is expected to incur significant administrative fines.” | Jan 1, 2028 | — | Critical |
| 5 | Operators of electronic communications networks. | Prevent reliance on high-risk suppliers for critical assets in electronic communications networks. “The goal is... to prevent operators of electronic communications networks from relying on high-risk suppliers for their critical assets.” | Jan 1, 2030 | — | Critical |
| 6 | Entities affected by Union-level risk assessments. | Comply with Union-level coordinated security risk assessments and resulting mitigation measures or prohibitions. “The Commission itself is granted increased powers, including the ability to designate certain 'third countries' as posing 'serious and structural non-technical risks' to ICT supply chains, which can trigger specific mitigation measures or prohibitions.” | Jan 1, 2027 | — | Critical |
| 7 | Companies operating within the EU. | Review and update internal risk management policies and technical and organizational measures. “Non-compliance with the obligations related to risk management... is expected to incur significant administrative fines.” | Jan 1, 2027 | — | Critical |
| 8 | Providers of ICT products, services, and processes. | Seek voluntary certification under the European Cybersecurity Certification Framework (ECCF) for relevant ICT products. “The revised European Cybersecurity Certification Framework (ECCF) is a key instrument... allowing certificates to serve as a presumption of conformity with EU law...” | — | — | Recommended |
| 9 | Member States and critical entities. | Engage in national and EU-level cybersecurity exercises to test and improve incident response capabilities. “ENISA's annual rolling program of EU-level cybersecurity exercises to test the preparedness and response capabilities of Member States and critical entities...” | — | — | Recommended |
| 10 | All entities subject to the regulation. | Continuously monitor guidance from ENISA and national cybersecurity authorities for updates and best practices. “The monitoring and evaluation framework... is designed to ensure continuous oversight of its effectiveness, identify areas for improvement, and adapt to the rapidly evolving cyber threat landscape.” | — | — | Recommended |
Related Regulations
Digital Omnibus Package — Simplifying EU Digital Rules on AI, Cybersecurity, and Data
European Union90% similar
Act on Cybersecurity (Zákon o kybernetické bezpečnosti), No. 264/2025 Sb.
Czech Republic89% similar
National Cybersecurity Strategy 2021–2025
Slovakia88% similar
Code of Practice on AI-Generated Content Transparency
European Union87% similar
Ley N° 21.663 — Ley Marco de Ciberseguridad (Framework Law on Cybersecurity and Critical Information Infrastructure)
Chile86% similar
© Regulations.AI — created on 26-Jan-2026 using Gemini 2.5 Flash