EU proposes Cybersecurity Act 2 to update ENISA mandate, certification framework, and ICT supply chain security rules
Original title: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain
The European Commission has proposed a new regulation (Cybersecurity Act 2) to replace the current Regulation (EU) 2019/881 on ENISA and cybersecurity certification. The proposal aims to strengthen ENISA's role, modernize the European cybersecurity certification framework, and establish new requirements for ICT supply chain security. Organizations subject to EU cybersecurity regulations will need to monitor the legislative process and prepare for potential changes to certification requirements, regulatory oversight, and supply chain governance obligations.
What changed
- The proposal repeals and replaces Regulation (EU) 2019/881 with a new comprehensive framework addressing ENISA's mandate, European cybersecurity certification framework, and ICT supply chain security requirements
- Regulation (EU) 2019/881 (Cybersecurity Act) is proposed to be repealed and replaced by Cybersecurity Act 2
- New provisions are introduced for ICT supply chain security governance alongside the existing cybersecurity certification framework
Who is affected
EU organizations subject to cybersecurity regulations, ICT manufacturers and service providers, certification bodies, entities in the EU ICT supply chain, and organizations seeking or maintaining cybersecurity certifications under EU framework
- Language
- EN