Low New document eu

EU proposes Cybersecurity Act 2 to update ENISA mandate, certification framework, and ICT supply chain security rules

Original title: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain

The European Commission has proposed a new regulation (Cybersecurity Act 2) to replace the current Regulation (EU) 2019/881 on ENISA and cybersecurity certification. The proposal aims to strengthen ENISA's role, modernize the European cybersecurity certification framework, and establish new requirements for ICT supply chain security. Organizations subject to EU cybersecurity regulations will need to monitor the legislative process and prepare for potential changes to certification requirements, regulatory oversight, and supply chain governance obligations.

What changed

  • The proposal repeals and replaces Regulation (EU) 2019/881 with a new comprehensive framework addressing ENISA's mandate, European cybersecurity certification framework, and ICT supply chain security requirements
  • Regulation (EU) 2019/881 (Cybersecurity Act) is proposed to be repealed and replaced by Cybersecurity Act 2
  • New provisions are introduced for ICT supply chain security governance alongside the existing cybersecurity certification framework

Who is affected

EU organizations subject to cybersecurity regulations, ICT manufacturers and service providers, certification bodies, entities in the EU ICT supply chain, and organizations seeking or maintaining cybersecurity certifications under EU framework

Language
EN

Frameworks

EU Cybersecurity Act ENISA

Open the original source