Cybersecurity Act 2 & Simplification Package
On this page
Summary
Cybersecurity Act 2 would repeal the current Cybersecurity Act and reform ENISA, the European cybersecurity certification framework and ICT supply-chain security rules. The proposal aims to strengthen EU cyber capabilities and resilience, improve coordinated governance, speed certification schemes and reduce fragmented compliance requirements. It would provide a harmonised framework for non-technical ICT supply-chain risks, including measures addressing high-risk suppliers, while a related directive would simplify scope, definitions, ransomware reporting and supervision of cross-border service providers.