Amending the NIS 2 Directive as regards simplification measures and alignment with the Cybersecurity Act 2
330 submissions from 266 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 594 submissions on this file. Shown here: the 330 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
Deliberations in Council working party · 28 May 2026
Feedback on adopted proposal closed: The EU Cybersecurity Act — 93 responses · 12 May 2026
Referral of the legislative proposal to the EP committee responsible (announced in plenary) · 25 Mar 2026
Who showed up
249 submissions from industry — companies and their trade associations — against 42 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.9 industry submissions for every one from civil society.
Industry 249Civil society 42Public authorities, academia, other 39
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
What the room declares
153 of 266
in the EU Register
601
full-time lobbying staff
€99.3M+
declared costs a year
455
EP accreditations declared
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.
The file, right now
The consultation closed on 12 May 2026 — it ran from 5 Feb 2026.
Stellungnahme des Deutschen Verkehrsforums e.V. zum Vorschlag für eine Richtlinie des Europäischen Parlaments und des Rates zur Änderung der Richtlinie (EU) 2022/2555 im Hinblick auf Vereinfachungsmaßnahmen und die Angleichung an den Vorschlag für die Cybersicherheitsverordnung 2 Berlin, 12.05.2026/dp 1.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Sungrow welcomes the opportunity to provide input on the European Commission's proposal for the revision of the Cybersecurity Act. We recognise the proposal's ambition to strengthen EU cyber resilience and reduce regulatory fragmentation.
Dear Members of the Commission, ISP Alliance a.s. represents more than 80 regional providers of publicly available electronic communications networks and services in the Czech Republic, most of them micro and small enterprises operating fixed networks.
We welcome the European Commission's initiative to revise the Cybersecurity Act and appreciate the opportunity to contribute to this important consultation. As a several European Financial institutions who operate across multiple Member States, we have a direct and substantial interest in ensuring robust cybersecurity frameworks that protect our operations, our customers, and the financial system as a whole.
IBM welcomes the opportunity to provide feedback on the revised draft EU Cybersecurity Act (CSA2) and the targeted amendments to the NIS2 Directive. As a global provider of enterprise technology and cybersecurity solutions, we welcome the steps taken to update ENISAs mandate and certification development framework in line with the new legislation such as NIS2, CRA, DORA, reflecting the changing needs, roles and…
The Chair in Cyber Policy at the University of Luxembourg would like to submit its feedback in order to contribute to the legislative debate on the Proposal for a Regulation CSA2 and the targeted amendments to the NIS2 Directive.
The Chair in Cyber Policy at the University of Luxembourg would like to submit its feedback in order to contribute to the legislative debate on the Proposal for a Regulation CSA2 and the targeted amendments to the NIS2 Directive.
Eurosmart welcomes the European Commissions proposal to amend Directive (EU) 2022/2555 (NIS2) through the Digital Omnibus simplification package and supports the objective of reducing unnecessary administrative burden while preserving a high level of cybersecurity across the Union.
Decathlon welcomes the European Commissions proposal for the Cybersecurity Act 2 and appreciates the opportunity to provide feedback on this proposal. The Cybersecurity Act has been an efficient instrument while letting room for improvement.
FOR FULL FEEDBACK PLEASE SEE THE ATTACHED PDF Eclipse Foundation Feedback on Proposals for the EU Cybersecurity Act COM(2026) 11 About this submission Headquartered in Brussels, and with 66% of its staff in Europe, Eclipse Foundation AISBL is Europes largest open source code-hosting foundation hosting over 400 open source projects that European industry relies on spanning cloud, IoT, automotive, AI, and developer…
Eurosmart welcomes the European Commissions proposal to revise the Cybersecurity Act (CSA2) and supports the objective of strengthening and scaling the European cybersecurity certification framework in response to evolving cybersecurity threats and increasing digital dependencies.
Our position Cybersecurity Act review AmCham EU speaks for American companies committed to Europe on trade, investment and competitiveness issues. It aims to ensure a growth-orientated business and investment climate in Europe. AmCham EU facilitates the resolution of transatlantic issues that impact business and plays a role in creating better understanding of EU and US positions on business matters.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The China Chamber of Commerce to the EU (CCCEU) welcomes the opportunity to provide feedback to the European Commission on the proposed revision of the Cybersecurity Act (CSA2). CCCEU acknowledges the importance of strengthening cybersecurity and protecting critical infrastructure.
WindEurope welcomes the opportunity to provide feedback on the proposed revision of the Cybersecurity Act (CSA) and the possible amendments to the NIS2 Directive. We broadly support the direction of the CSA revision, including the reinforcement of ENISA's mandate, the move towards EU-level cybersecurity certification schemes, the recognition of non-technical risks, and the establishment of an EU-level trusted ICT…
ISACA warns that the CSA2 risks creating a disproportionately burdensome attestation architecture for cybersecurity skills certifications and professional development. In the attached position paper, we argue that the EU does not need a new attestation market to make cybersecurity skills understandable.
The Federation of European Private Port Companies and Terminals FEPORT reply to the public consultation on the Cybersecurity Act II proposal Introduction FEPORT represents the interests of 2290 private port companies and terminals performing cargo handling and logistics related activities in European seaports.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
12 May 2026 VIA ELECTRONIC SUBMISSION Re: Proposal for the Cybersecurity Act 2 (CSA2) The Hacking Policy Council (“HPC”)1 submits the following comments in response to the European Commission’s open consultation on its Proposal for the Cybersecurity Act 2 (CSA2).2 We appreciate the opportunity to comment on the effort to modernise EU’s foundational cybersecurity legislation.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Microsoft recommendations regarding the EU Cybersecurity Act 2.0 May 2026 Executive summary Microsoft welcomes the European Commission’s proposal to revise the EU Cybersecurity Act (CSA 2.0) and supports its overarching objective of strengthening Europe’s cybersecurity resilience, trust, and regulatory coherence in an increasingly complex threat landscape.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The European Local Fibre Alliance (ELFA), representing more than 1,200 alternative electronic communications operators and service providers across more than 11 European countries, welcomes the objective of strengthening cybersecurity and resilience within Europes digital infrastructure.
May 2026 Dassault Systèmes’ position on the Cybersecurity Act Revision As a European software company, Dassault Systèmes welcomes the CSA2 proposal’s objective of reinforcing ENISA’s role, simplifying compliance requirements and improving the overall effectiveness and coherence of the European Cybersecurity Certification Framework (ECCF).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Confederation of Swedish Enterprise (SN) welcomes the goal of strengthening the EU's cybersecurity and reducing fragmentation in the internal market. Unfortunately, the European Commission is not taking the opportunity to significantly facilitate compliance and streamline the complex set of cybersecurity rules adopted in recent years.
FiberCop supports the overarching objective of the Cybersecurity Act 2 (CSA2) to ensure cybersecurity and resilience across the European digital ecosystem, recognising that secure and trustworthy digital infrastructure is fundamental to Europes competitiveness and technological sovereignty.
Zscaler feedback on the revised EU Cybersecurity Act Brussels, 12 May 2026 Zscaler welcomes the opportunity to provide feedback to the proposal for a revision of the EU Cybersecurity Act. We welcome the objectives of the draft regulation, namely to revise the mandate of EU Cybersecurity Agency ENISA, to modernize the European Cybersecurity Certification Framework, and to introduce a new mechanism for conducting…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Vodafone Spain welcomes the opportunity to contribute to the European Commissions public consultation on the proposed revision of the cybersecurity framework. Vodafone Spain fully supports the European Unions objective of achieving a high and common level of cybersecurity across the Union.
Spain is one of the few EU countries where the deployment of fiber optic (FTTH) is close to completion. An important reason for this success is the constant cooperation with major from China. We are concerned that European legislation.
ESIA supports a stronger role for ENISA in developing and maintaining EU cybersecurity certification schemes, provided processes remain transparent, technically driven, and closely aligned with industry realities. Global standards and interoperability must remain central to avoid market fragmentation.
Netnod sees three primary concerns. First, Netnod opposes the mandatory collection of entity IP ranges (Article 3(4)), suggesting ENISA retrieve this data directly from RIR systems (WHOIS/RDAP) to avoid duplicative, error-prone reporting. Second, we stress the need to reinforce the established global, multistakeholder model for Internet standards and limit new ENISA powers to policy, not operational protocols.
HOPE welcomes the CSA2 proposal in light of a changed cybersecurity threat landscape, with new threats and uncertain future developments faced by hospitals and health services. A flexible, needs-focused, horizontal cybersecurity framework is important at a time when AI-enabled automated attacks and social engineering, refocused ransomware attacks (including state-sponsored) and advances in quantum computing are…
Please find attached ISC2's response to the public consultation on the proposal for a Directive amending Directive (EU) 2022/2555 (NIS2) as regards simplification measures and alignment with the Cybersecurity Act 2 (COM(2026) 13). This submission focuses on the new ransomware disclosure obligations under Article 23, which directly impact cybersecurity professionals.
Please find attached ISC2's response to the public consultation on the proposal for a Regulation on the European Union Agency for Cybersecurity (ENISA), the European Cybersecurity Certification Framework, and ICT supply chain security (Cybersecurity Act 2, COM(2026) 11).
The proposed regulatory frameworks (CSA2 and Digital Omnibus) aim to create stronger alignment across EU cyber regulation and to reduce duplicative administrative burdens, particularly around incident reporting and certification. At the same time, they expand requirements in key areas such as ICT supply chains, cybersecurity certification, and EU-level governance (ENISA).
Titel Ref. Ares(2026)4818540 - 12/05/2026 Revision of the EU Cybersecurity Act Position of the German digital industry on the European Commission’s proposal for a CSA-2 1 Cybersecurity Act 2 Content 1 Summary 3 2 TITLE II: THE EUROPEAN UNION AGENCY FOR CYBERSECURITY 5 TITLE III: EUROPEAN CYBERSECURITY CERTIFICATION FRAMEWORK 8 3 Article 71: Objectives and scope of the European cybersecurity certification framework 9…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Position Paper 2026 May NIS-2 Amendments Summary The NIS-2 Directive set the goal to establish a unified legal framework to uphold cybersecurity in critical sectors across the EU. By defining technical and methodological requirements for cybersecurity risk management measures, it aims to create a harmonised baseline level of protection.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
FFTélécoms members share the goal of strengthening cybersecurity within the EU. They have already invested heavily in the resilience of their networks and continue to build on this dynamic process to face evolving connectivity needs.
NCC Group welcomes the opportunity to provide feedback on the European Unions Cybersecurity Act revisions and offer our expertise as a global cyber security firm. Our purpose is to create a more secure digital future. We are trusted by clients across the world to help protect their operations, systems, and products from evolving cyber threats.
Renault Group Position on Cybersecurity Act 2 CSA2 Responding to escalating cyber-threats, the EU's ambitious "Cybersecurity Package" enhances security for high-risk ICT suppliers. This initiative safeguards against non-EU countries posing cybersecurity concerns.
NCC Group welcomes the opportunity to provide feedback on the European Unions Cybersecurity Act revisions and offer our expertise as a global cyber security firm. Our purpose is to create a more secure digital future. We are trusted by clients across the world to help protect their operations, systems, and products from evolving cyber threats.
The Open Source Security Foundation (OpenSSF) welcomes the European Commissions proposed amendments to the NIS 2 Directive as an important step toward a more coherent, scalable, and simplified EU cybersecurity framework.
HOPE acknowledges the proposal for a Directive amending Directive (EU) 2022/2555 (NIS2) as regards simplification measures and alignment with the proposal for the Cybersecurity Act 2. The delays experienced in the national NIS2 transposition demonstrated that its implementation is challenging, including in the hospital sector where financial, human, and operational resources are insufficient for adapting to…
Paris, May 12th 2026 POSITION PAPER Revision of the NIS 2 Directive L’Afep supports the Commission's intention to revise the NIS 2 Directive in order to simplify and harmonize its implementation and its overall aim of strengthening cybersecurity across the European Union (EU).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Connect Europe and GSMA Europe’s views on the Revised Cybersecurity Act (CSA2) May 2026 Connect Europe and GSMA Europe1, representing the views of European telecommunications operators in Europe, would like to share, in the following paragraphs, their detailed reactions to the Cybersecurity Package, including the proposal for a revised Cybersecurity Act (CSA2) and amendments to the Network and Information Security…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
EDF welcomes the opportunity to comment on the proposed Cybersecurity Act revision, to outline its concerns and structural needs as an organization that uses digital services. (1) The lack of relevance of the distinction between technical and non-technical risks.
Connect Europe and GSMA Europe’s views on the Revised Cybersecurity Act (CSA2) May 2026 Connect Europe and GSMA Europe1, representing the views of European telecommunications operators in Europe, would like to share, in the following paragraphs, their detailed reactions to the Cybersecurity Package, including the proposal for a revised Cybersecurity Act (CSA2) and amendments to the Network and Information Security…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
As a user organisation of digital services, Bpifrance wishes to express its structural concerns and needs regarding the revision of the CSA2, in particular its Title III on European cybersecurity certification. 1. Inadmissibility of the distinction between ‘technical risks’ and ‘non-technical risks’. Digital security is based on the triple DIC (Availability, Integrity, Confidentiality).
Filed in French · English published by the European Commission
Paris, 12th May 2026 POSITION PAPER Cybersecurity Act 2 L’Afep supports the Commission's intention to revise the 2019 Cybersecurity Act (CSA) and its overall aim of strengthening cybersecurity across the EU. With regard specifically to the issues of cybersecurity in cloud services, L’Afep is concerned about the delays in the presentation and progress of the Cloud and AI Development Act (CAIDA).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
12.5.2026 1 (2)- 12/05/2026 Ref. Ares(2026)4815347 SFS Suomen Standardit ry:n kommentit EU:n kyberturvallisuusasetukseen (CSA2) SFS Suomen Standardit pitää tärkeänä komission tavoitetta parantaa Euroopan kyberturvallisuutta ja vahvistaa digitaalista resilienssiä kyberturvallisuusympäristön muutos- ja uhkatilanteiden jatkuvasti lisääntyessä.
Filed in Finnish · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Connect Europe and GSMA Europe’s views on the Revised Cybersecurity Act (CSA2) May 2026 Connect Europe and GSMA Europe1, representing the views of European telecommunications operators in Europe, would like to share, in the following paragraphs, their detailed reactions to the Cybersecurity Package, including the proposal for a revised Cybersecurity Act (CSA2) and amendments to the Network and Information Security…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Connect Europe and GSMA Europe’s views on the Revised Cybersecurity Act (CSA2) May 2026 Connect Europe and GSMA Europe1, representing the views of European telecommunications operators in Europe, would like to share, in the following paragraphs, their detailed reactions to the Cybersecurity Package, including the proposal for a revised Cybersecurity Act (CSA2) and amendments to the Network and Information Security…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
12 May 2026 Ms. Henna Virkunen Executive Vice-President For Tech Sov ereignty, Security and Democracy European Commission Re: public consultation on the EU Cybersecurity Act 2 Dear Ms. Henna Virkkunen, on behalf of the members of our organizations: - Czech Telecommunications Cluster (CZ: Český telekomunikační klastr z.s.) is an association of internet service providers and telecommunications operators in the Czech…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Hikvision’s feedback to the European Commission's Consultation on the EU Cybersecurity Act revision proposal (CSA2) I. Executive summary Hikvision submits this contribution in response to the European Commission's consultation on the revision of the EU Cybersecurity Act (CSA2).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
EuroTube acknowledges the complexity of the current discussion around high-risk vendors, which involves not only technical cybersecurity considerations but also broader geopolitical factors. In this context, it is important to carefully balance risk mitigation with the benefits of continued openness and collaboration.
Recommendations: No mixing of cybersecurity and trade policy The Committee advises against making certain countries high-risk countries and proposes instead to apply the following security principles to the whole market and supply chains: 1.
Filed in German · English published by the European Commission
CrowdStrike appreciates the opportunity to contribute to the Proposal for a Regulation on the EU Cybersecurity Act (CSA2) and welcomes the Commissions leadership in addressing the rapidly evolving threat landscape.
Oncology is among the most data-intensive fields in medicine. From genomic sequencing and AI-assisted diagnostics to radiotherapy planning and cross-border clinical trial data sharing, oncology depends on digital systems that must be both interoperable and secure.
About eco: With approximately 1,000 member companies, eco (international.eco.de) is the leading Association of the Internet Industry in Europe. Since 1995, eco has been highly instrumental in shaping the Internet, fostering new technologies, forming framework conditions, and representing the interests of its members in politics and international forums. eco has offices based in Cologne, Berlin and Brussels.
The RIPE NCC welcomes the opportunity to provide feedback on the proposal for a Directive amending the NIS2 Directive and the proposal for a Regulation revising the Cybersecurity Act (CSA2). In summary, we recommend the following: 1) Reduce the administrative burden, particularly under the NIS2 framework, for small and micro DNS service providers and small to mid-cap enterprises.
Enedis is Frances main Distribution System Operator, delivering electricity to over 38 million customers and managing Europes largest electricity distribution grid. As an operator of critical infrastructure, Enedis is committed to strengthening the resilience of European electricity grids and of their ICT and OT supply chains.
Brussels, 12 May 2026 BDEW Bundesverband der Energie- und Wasserwirtschaft e.V. (German Association of Energy and Water Industries) BDEW Representation at the EU Avenue de Cortenbergh 52 1000 Brussels Position Paper Belgium www.bdew.de Cybersecurity Act (CSA) 2 Version: final The German Association of Energy and Water Industries (BDEW), Berlin, represents over 1,900 companies.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Fiber Carrier Association (FCA) welcomes the objective of strengthening cybersecurity and resilience within Europes digital infrastructure. As an association representing infrastructure-focused electronic communications operators and wholesale connectivity providers, FCA supports proportionate and effective measures aimed at improving cybersecurity risk management and operational resilience across the sector.
Position paper on the Cybersecurity Act 2 Luxembourg, A necessary upgrade of the EU Cybersecurity but not at the expense of competitiveness 12 May 2026 framework, EXECUTIVE SUMMARY I. Introduction and general remarks II. European Cybersecurity Certification Framework ................................ ................................ ...........5 1. Presumption of conformity and regulatory coherence 2.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Italian Internet Provider Association (AIIP) is the first and historic Italian association of Internet providers. For more than thirty years, it has been committed to promoting an open, competitive and innovative telecommunications market and to representing the needs of small and medium-sized operators with a strong local presence.
The Energy PT ISAC welcomes the European Commissions initiative to revise the Cybersecurity Act and sees it as a necessary response to a markedly hostile threat environment, characterized by geopolitical instability, hybrid threats and the industrialization of cybercrime.
The American National Standards Institute (ANSI), the private sector coordinator of the US standardization system whose members are stakeholders standards developers, companies, government agencies, academia, consumers, etc. welcomes the opportunity to provide comments in response to the European Commissions proposal for a revised Cybersecurity Act (CSA 2.0). Please see our full comments in the file attached.
The Enel Group, a multinational energy company, welcomes the revision of the Cybersecurity Act (EU) 2019/881 and considers the revision of the Cybersecurity Act (CSA 2.0) as a strategic step towards strengthening the European Unions cyber resilience.
European Distribution System Operators (E.DSO) is the association representing Europes leading electricity distribution system operators (DSOs), responsible for managing electricity distribution grids throughout Europe, with some 200 million connected customers. E.DSO works to enable the energy transition, foster innovation, and ensure a reliable and sustainable electricity supply for all European citizens.
The initiative will revise the Cybersecurity Act, clarify the mandate of the EU Agency for Cybersecurity (ENISA) and improve the European Cybersecurity Certification Framework to achieve better resilience. The initiative also aims to streamline, simplify and complement EU legislation to make the EU cybersecurity regulatory framework easier for users and businesses to implement and to prioritise measures to support…
Filed in Italian · English published by the European Commission
The TÜV Association welcomes the proposal for a Cybersecurity Act 2 that further develops the European cybersecurity framework in response to the evolving threat landscape. The proposal reflects a comprehensive understanding of cybersecurity, notably by including both ICT supply chain security and the cyber posture of entities.
ACEA, the European Automobile Manufacturers Association, represents Europes 17 major car, van, truck and buses manufacturers. We submit the document attached in response to the Commission's open consultation on its Proposal for a revision of the EU Cybersecurity Act.
THE DANISH CHAMBER OF COMMERCE Børsgade 4 1217 København K www.danskerhverv.dk [email removed] T. [phone removed] Ref. Ares(2026)4808384 - 12/05/2026 Directorate-General for Communications Networks, Content and Technology (DG Connect) Rue de la Loi 200 1049 Brussels, Belgium 12th of May 2026 The Danish Chamber of Commerce: Feedback to the European Commission’s Cybersecurity Package: Revision of the Cybersecurity Act…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Airlines for America welcomes the European Commission’s initiative to introduce targeted amendments to Directive (EU) 2022/2555 as part of the broader Digital Simplification Omnibus and the Union’s competitiveness agenda.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
4iG Telecommunications Holding Zrt. (formerly known as "ANTENNA HUNGÁRIA" Zrt.) is responsible for the coordination of the 4iG Group's telecommunications portfolio, as well as strategic real estate and asset management.
Eurelectric supports the European Commissions revision of the Cybersecurity Act and its work on harmonising cybersecurity frameworks across the Union and within the power sector. We welcome the opportunity to provide views on the revised EU Cybersecurity Act and supports its efforts to strengthen cyber resilience while improving harmonisation across the EU.
Cybersecurity Act 2 Contribution de POST Luxembourg à la consultation publique de la Commission Européenne portant sur le projet de règlement Cybersecurity Act 2 12/05/2026 Sommaire 1. Executive summary 2. Introduction 3. Observations de POST 3.1. High Risk Vendors 3.2. Gouvernance 3 5 6 6 7 2/7 Nom du fichier - 1.
Filed in French · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Summary: DE-CIX supports the objectives of the European Commissions Cybersecurity Act 2 (CSA2). However, DE-CIX has concerns regarding the current definition of key assets lacks sufficient precision, leaving room for broad and potentially inconsistent interpretation.
Green Power Denmark appreciates the opportunity to provide the European Commission with feedback on the European Commission's proposal for revision of the Cybersecurity Act. Green Power Denmark welcomes the Commissions ongoing work to reinforce the EUs cybersecurity framework in response to a shifting geopolitical context and an increasingly complex cyber threat environment.
ENTSO-E, as a European association representing electricity transmission system operators, is publishing its response to the EU Cybersecurity Act. Through this contribution, ENTSO-E aims to provide the perspective of the electricity sector on the proposed regulatory framework and its potential implications.
Thank you for the opportunity to provide feedback on the proposal for the revision of the Cybersecurity Act. eco welcomes the objective of strengthening cybersecurity, resilience and coherence across the Union and would like to contribute the following comments to support a proportionate, risk-based and workable framework.
DIN is the national standardisation body of Germany. As such we would like to recommend certain changes to the CSA2 draft, that allow it to achieve its aims while avoiding certain negative implications. Particularly, we recommend three things: Firstly, to advance the process of European standards development instead of creating a parallel standard setting system.
The European Committee for Interoperable Systems (ECIS) is an international non-profit association founded in 1989 that endeavours to promote a favourable environment for interoperable ICT solutions. We actively represent our members regarding issues related to interoperability and competition before European and international fora.
The Datacom Industry Association (DIA) AISBL, represented by its chair Prof. George Polyzos and by decision of its board, together with individual DIA members listed in the attached document, would like to submit the following position to the process of gathering feedback to the Commission Adoption of the revised EU Cybersecurity Act (CSA), called CSA2 in the following.
Proposal for a contribution to the public consultation on the revision of the Cybersecurity Act As a user organisation of digital services, CIGREF would like to express its concerns and structural needs regarding the planned revision of the Cybersecurity Act and in particular its Title III on the European cybersecurity certification framework. 1.
Filed in French · English published by the European Commission
Please find attached a joint position paper from seven business associations from the Czech Republic, Lithuania, and Poland regarding the draft CSA2. The participating associations are as follows: (1) Czech Telecommunications Cluster (CZ: Český telekomunikační klastr z.s.) is an association of internet service providers and telecommunications operators in the Czech Republic.
ERTICO welcomes the revision of the EU Cybersecurity Act as an important step to strengthen Europes cyber resilience. As a public-private partnership representing the ITS and mobility ecosystem, ERTICO stresses that cybersecurity policy must build trust while preserving innovation, interoperability, and the integrity of the Single Market.
FTTH Council Europe feedback on the “Proposal for a Regulation for the EU Cybersecurity Act” May 12th, 2026. Introduction The FTTH Council Europe (FTTH CE) is grateful for the opportunity to provide feedback on the revised CSA. What is now proposed have a potentially enormous effect on the fixed industry having been previously left outside the scope of the original CSA.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Oesterreichs Energie, the Association of Austrian Electricity Companies, welcomes the European Commissions objective to simplify the European cybersecurity framework, strengthen the resilience of critical infrastructure and reduce regulatory fragmentation. For the electricity sector, new requirements must be practical, proportionate and aligned with existing sector-specific rules.
Please find our full feedback text attached. We strongly support the move towards a comprehensive, risk-based Cybersecurity Act (CSA) framework that integrates both technical and non-technical risk factors, as well as the formalisation of a high-risk supplier framework. Europe's electricity infrastructure faces a critical and growing dependency on Chinese suppliers of inverter-based resources.
MasOrange, S.L. welcomes the opportunity to participate in the public consultation on the proposal for a Regulation on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2 -CSA2-).
Executive Summary of Comments of the China Chamber of International Commerce on the EUs Revised Cybersecurity Act The China Chamber of International Commerce holds that the draft CSA 2.0 introduces concepts such as nontechnical risks, a third country posing cybersecurity concerns and highrisk suppliers, which in essence equate corporate national identity with security risks.
BORR. INFORME CÁMARA DE COMERCIO DE ESPAÑA Consulta pública de Comisión Europea relativa a la propuesta de Reglamento del Parlamento Europeo y del Consejo relativo a la Agencia de la Unión Europea para la Ciberseguridad (ENISA), el marco europeo de certificación de la ciberseguridad y la seguridad de la cadena de suministro de las TIC, y por el que se deroga el Reglamento (UE) 2019/881 (Reglamento sobre la…
Filed in Spanish · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
GIMELEC welcomes the European Commissions initiative to revise the CSA, which provides a legally binding framework to address systemic supply chain risks affecting critical infrastructures, including those arising from geopolitical dependencies and manufacturer controlled remote or cloud based functionalities.
The International AI Governance Association (IAGA) welcomes the European Commissions continued efforts to strengthen the Unions cybersecurity framework and align it with the realities of an increasingly complex threat environment. The proposal reflects a thoughtful attempt to simplify compliance, improve coherence across regulatory instruments, and enhance the resilience of critical infrastructure.
The views of the Estonian Information Technology and Telecommunications Union (ITL) on the Cyber Package published by the European Commission on 20 January 2026, which includes proposals for the adoption of the Cybersecurity Act 2 (CSA2) and amendments to the NIS2 Directive, are as follows: (1) Cybersecurity is a very important area and its regulation is clearly necessary as a whole.
Filed in Estonian · English published by the European Commission
Akt EU o kybernetické bezpečnosti Stanovisko HK ČR Hospodářská komora ČR vnímá předložený návrh CSA2 jako materiál s potenciálně velmi významnými dopady na podnikatelské prostředí, konkurenceschopnost evropské ekonomiky i fungování vnitřního trhu.
Filed in Czech · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Onivia welcomes the European Commissions initiative to strengthen the resilience and security of critical ICT supply chains through the proposed revision of the EU Cybersecurity Act (CSA2). As a wholesale-only FTTH operator providing critical digital infrastructure in Spain, we support the objective of enhancing the cybersecurity and resilience of electronic communications networks across the European Union.
The Cybersecurity Act 2.0 (CSA 2.0) proposal represents a significant evolution of the existing EU cybersecurity framework established under Regulation (EU) 2019/881. It aims to strengthen the Unions capacity to address an increasingly complex cyber threat landscape while ensuring a harmonised approach across Member States.
Eurocities welcomes this opportunity to contribute to the Commissions call for evidence on the adoption of a Proposal for a Directive amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [proposal for the Cybersecurity Act 2] and a Proposal for a Regulation on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply…
12 May 2026 VIA ELECTRONIC SUBMISSION Re: Proposal for the Cybersecurity Act 2 (CSA2) The Cybersecurity Coalition (“the Coalition”) submits the following comments in response to the European Commission’s open consultation on its Proposal for the Cybersecurity Act 2 (CSA2).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Dedalus welcomes the opportunity to provide input to the Cybersecurity Act 2 and NIS2 Simplification Measures proposals. As a European leader in Software as a Medical Device (SaMD) and AIenabled medical devices (MDAI), serving large hospital networks across the Union, Dedalus strongly supports the objective of creating a predictable, innovationfriendly, and clinically safe digital regulatory environment.
Norlys welcomes the opportunity to give feedback on the European Commission's proposal for revision of the Cybersecurity Act. Norlys appreciates the Commission's continued efforts to strengthen the EU's cybersecurity framework in light of a rapidly changing geopolitical environment and an increasingly complex cybersecurity threat landscape.
The International AI Governance Association (IAGA) welcomes the European Commissions continued efforts to strengthen the Unions cybersecurity framework and align it with the realities of an increasingly complex threat environment. The proposal reflects a thoughtful attempt to simplify compliance, improve coherence across regulatory instruments, and enhance the resilience of critical infrastructure.
Catena-X Contribution to the EU Public Consultation on the Revised Cybersecurity Act (CSA2) Submitted by: Catena-X Automotive Network e.V., Berlin Reference: Proposal for a Revised Cybersecurity Act – Public Consultation I. About Catena-X Catena-X Automotive Network e.V. is the first end-to-end, open, and collaborative data ecosystem for the global automotive industry.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Response to the Consultation on the EU Cybersecurity Act Revision About Infoblox Infoblox is the recognised leader in next-generation Domain Name System (DNS) management and security at scale. We empower thousands of organisations worldwide — including 70 percent of the Fortune 500 — to simplify, secure, and scale their hybrid and multi-cloud networks in an increasingly complex digital landscape.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
OpenPolicy appreciates the opportunity to contribute feedback on the revised EU Cybersecurity Act (CSA2). OpenPolicy is a technology policy organization and coalition that connects innovators with the government stakeholders shaping their market. Our mission is to drive open, collaborative policymaking by improving access for startups and companies of all sizes.
The EE-ISAC welcomes the revision of the EU Cybersecurity Act as an important opportunity to strengthen the Unions cyber resilience in response to growing geopolitical tensions, increasingly sophisticated cyber threats, and vulnerabilities in ICT supply chains.
Revision of the Cybersecurity Act (CSA2) Feedback from NetApp 11 May 2026 NetApp welcomes the opportunity to contribute to the European Commission’s public consultation on the Cybersecurity Act 2. We consider that this proposal comes at a critical time where the importance of ICT supply chain security has never been more pressing.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
OpenSSF welcomes the positive direction reflected in the revised Cybersecurity Act proposal and strongly supports the recognition of OSS stewards within the revised CSA framework. The submission highlights the importance of deeper cooperation between ENISA and open source communities to strengthen Europes cybersecurity resilience, software supply chain security, and secure-by-design objectives.
Call for Evidence: The EU Cybersecurity Act (CSA2) EDP Contribution May 2026 edp.com Overall position EDP supports the European Commission’s objective to strengthen cybersecurity resilience and improve the coherence of the EU cybersecurity framework.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Please find attached ESMIGs position paper on the revised Cybersecurity Act (CSA). The paper focuses specifically on the proposed trusted ICT supply chain framework, which ESMIG considers of strategic importance for the smart metering and smart grid ecosystem.
AIOTI welcomes the move to regulate for greater cybersecurity. Our members are committed to integrating robust security into their products and services, and support initiatives aimed at fostering greater trust among users, consumers, businesses, and public authorities regarding the safety and security of digital technologies.
AIOTI welcomes the move to regulate for greater cybersecurity. Our members are committed to integrating robust security into their products and services, and support initiatives aimed at fostering greater trust among users, consumers, businesses, and public authorities regarding the safety and security of digital technologies.
E.ON submits the attached response to the Commissions Call for Evidence on the revision of the EU Cybersecurity Act (CSA2). E.ON recommends that CSA2 (1) sets an ICT supply chain framework based on verifiable, technology-based risk criteria and proportionality (including lifecycle and economic impact); (2) mandates an ENISA-operated single-entry point for security-relevant notifications, with clear thresholds and…
MedTech Europe welcomes the opportunity to provide feedback on the Proposal for a revised Cybersecurity Act, which seeks to strengthen the EUs cybersecurity capabilities and resilience while preventing fragmentation across the Digital Single Market.
The Association of Cable and Telecommunications Network Operators of the Czech Republic (APKT) welcomes the possibility of giving the European Commission its position on the proposal for a Cybersecurity Act 2 (CSA2).
Filed in Czech · English published by the European Commission
Cybersecurity Act Consultation Concerning Title II: The European Union Agency For Cybersecurity Leonardo supports the revised, strengthened role and mandate of ENISA, recognising the strategic added value that the proposition will bring to the European Cybersecurity landscape.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Association of Cable and Telecommunications Network Operators of the Czech Republic (APKT) welcomes the possibility of providing the European Commission with its opinion on the proposed amendments to the NIS2 Directive.
Filed in Czech · English published by the European Commission
As part of the public consultation launched by the European Commission in connection with the revision of the Cybersecurity Regulation, Groupe ADP wishes to share its concerns and structural needs. The Group, a global leader in the airport industry and owner of the European Unions largest airportParis-Charles de Gaullewishes to draw particular attention to Title III of the proposed revision, concerning the…
Feedback on the European Commission’s proposal to revise the EU Cybersecurity Act Digital Business Ireland is the leading representative body for Ireland’s digital and ecommerce sectors, representing a community of more than 8,000 businesses spanning multinationals, indigenous SMEs, and experts across law and academia.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Confederation of Danish Industry (DI) The Confederation of Danish Industry (DI) welcomes the European Commissions efforts to strengthen Europes cybersecurity and resilience framework in an increasingly complex geopolitical and technological environment.
We welcome the Commissions proposal as a necessary evolution of the EUs cybersecurity framework. In an increasingly complex geopolitical and technological threat landscape, the proposed Cybersecurity Act 2 and the targeted amendments to the NIS 2 Directive offer a critical opportunity to enhance Europe's cyber resilience, reduce market fragmentation, and streamline regulatory compliance for businesses.
Statement of the Chinese Chamber of Commerce in Italy on the Proposal for a Regulation for the EU Cybersecurity Act (CSA2) On 20 January 2026, the European Commission presented a proposal for a revised Cybersecurity Act (CSA2), aimed at significantly expanding cybersecurity regulation across strategic sectors.
As part of the public consultation launched by the European Commission in connection with the revision of the Cybersecurity Regulation, Groupe ADP wishes to share its concerns and structural needs. The Group, a global leader in the airport industry and owner of the European Unions largest airportParis-Charles de Gaullewishes to draw particular attention to Title III of the proposed revision, concerning the…
The Open Regulatory Compliance Working Group welcomes the opportunity to contribute to the revision of the EU Cybersecurity Act (CSA). We support the EUs efforts to strengthen cybersecurity resilience, trust, and harmonisation across the Single Market.
The comments of the Independent Industry Committee on the draft CSA2 are attached in the file. The Committee of the Independent ICT Industry brings together a significant number of ICT companies in the Czech Republic, in particular providers of fixed internet access.
Filed in Czech · English published by the European Commission
The comments of the Independent Industry Committee on the amendments to the NIS2 Directive are attached to the file. The Committee of the Independent ICT Industry brings together a significant number of ICT companies in the Czech Republic, in particular providers of fixed internet access.
Filed in Czech · English published by the European Commission
AMETIC considers that CSA2 should preserve a strictly technical, evidence-based and proportionate approach to cybersecurity, avoiding politically driven criteria in the designation of high-risk providers. The association highlights the importance of supplier diversification, legal certainty and harmonised EU rules to ensure resilience, competitiveness and secure digital infrastructure deployment across Europe.
The Chamber of Commerce of Slovenia welcomes the systemic regulation of information security and cybersecurity and the assurance of a high level of information security in areas that are essential for the smooth functioning of the country and for maintaining the provision of vital social and economic activities as required by EU legislation – NIS22 Directive, sectors in Annexes I and II.
Filed in Slovenian · English published by the European Commission
Siemens Energy considers that the revision of the Cybersecurity Act is key to ensuring that the EUs cybersecurity framework remains up to date and reflects the current cybersecurity and threat environment. We therefore welcome the reinforcement of ENISA's mandate, increase of its budget and the introduction of an EU level trusted ICT supply chain framework, both of which are important steps toward strengthening the…
Stellungnahme zur EU-Verordnung Cybersecurity Act II Mai 2026 EU Verordnung Cybersecurity Act II 1. Executive Summary Der Verband der Automobilindustrie (VDA) unterstützt die Zielsetzung des Cybersecurity Act II, die europäische Cybersicherheitsarchitektur an eine verschärfte Bedrohungslage und an geopolitische Risiken anzupassen.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The La Poste group welcomes the revision of the Cybersecurity Act and fully shares its objectives: strengthening European operational capabilities, simplifying and harmonising the regulatory landscape, improving certification governance and better managing ICT supply chain risks.
Filed in French · English published by the European Commission
Kaspersky welcomes the opportunity to provide feedback on the review of the Cybersecurity Act (CSA 2). During the previous legislative term, the EU co-legislators adopted a broad and complex cybersecurity framework, including the NIS2 Directive, the Digital Operational Resilience Act (DORA), the Critical Entities Resilience (CER) Directive, the Cyber Resilience Act (CRA), the Cyber Solidarity Act, the 5G…
In the Cybersecurity Act 2, CEN and CENELEC urge the Commission to: 1) Ensure that standards developed by the ESOs are maintained as the backbone of cybersecurity certification schemes. 2) Confirm that technical specifications developed by ENISA remain a last resort fallback option.
Developers Alliance welcomes the proposed revision of the Cybersecurity Act, to streamline the governance of the EU cybersecurity policy and the harmonized certification framework. Key points: 1. Strengthen ENISAs mandate, to provide independent technical expertise throughout the legislative process, including the implementation and enforcement phases. 2.
See attached the full position. Summary: In the recent years, the EU has built one of the worlds most ambitious regulatory frameworks for cybersecurity, driven by rising cybersecurity risks. The challenge the newly proposed cybersecurity package must meet is to make it work in practice.
Networld Europe takes note of the European Commissions proposal for a revised Cybersecurity Act (Regulation (EU) 2019/881) as part of broader measures to modernise and simplify the EU cybersecurity framework. As a European Technology Platform, Networld Europe focuses on the innovation and technical dimensions and their implications for the integrity of the European system.
The 6G Health Association gGmbH is an enterprise with focus on the interface of health and information communication technology. European sovereignty in all areas concerning citizens information and also technology is very relevant to us.
The China Chamber of Commerce for Import and Export of Machinery and Electronic Products (hereinafter referred to as "CCCME") extends its gratitude to the European Commission for the opportunity to submit comments.
Cybersecurity has become a foundational element of the digital ecosystem, influencing trust, resilience, and economic development. As digital transformation accelerates, the need for coherent and effective standardization frameworks grows accordingly. Standardization bodies play a critical role in ensuring interoperability, security, and alignment with regulatory expectations.
This memorandum is submitted in response to the European Commissions initiative to streamline and simplify the implementation of the NIS2 Directive and the broader EU cybersecurity framework. The Commission has clearly articulated its intention to reduce unnecessary administrative burden, improve legal certainty, and enhance cross-border consistency for entities operating within the internal market, while…
ESBG response to the EC Call for Feedback – Cybersecurity Act Review ESBG (European Savings and Retail Banking Group) Rue Marie-Thérèse, 11 - B-1000 Brussels April 2026 Title I: General Provisions, Subject Matter and Definitions Definitions In line with the Commission’s current mandate, ESBG strongly believes in simplification and harmonisation of definitions across European legislations.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Commissions proposal for a Cybersecurity Act 2 includes positive developments. In particular, harmonizing ICT supply chain security at the EU level is far more effective than maintaining twenty-seven separate national approaches for companies operating in different Member States, such as Airbus. Nevertheless, critical issues need to be addressed.
VATM welcomes the publication of the draft proposal for the revision of the EU Cybersecurity Act and the opportunity to provide feedback. The attached position paper outlines the perspective of alternative telecommunications network operators on key aspects of the proposal, including the Trusted ICT Supply Chain Framework, investment predictability, proportionality and the interaction with existing EU cybersecurity…
EuroISPA is recognised as the voice of the European Internet Services Providers industry, representing over 3,300 ISPs across the EU and EFTA countries. Internet Services Providers (ISPs) are small or large companies that help deliver internet access while protecting networks and users from cyber threats through monitoring, security measures, and incident response.In addition, ISPs often collaborate with…
The High Commission for Digital and Postal Services (CSNP) is composed of seven deputies nominated by the President of the National Assembly, seven senators nominated by the President of the Senate, and three qualified personalities nominated by the Minister of Economy, Finance and Industrial, Energy and Digital Sovereignty.
Filed in French · English published by the European Commission
Contribution du Groupe InVivo à la consultation publique sur la révision du Cybersecurity Act (COM(2026)11) 1. Contexte et positionnement du Groupe InVivo Le Groupe InVivo est un acteur agroalimentaire international et leader européen, opérant des activités critiques reposant sur des systèmes d’information complexes, interconnectés et fortement dépendants de prestataires numériques (services cloud, solutions…
Filed in French · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The EUCC ISAC is a stakeholder platform bringing together industry experts, National Cybersecurity Certification Authorities (NCCAs), Conformity Assessment Bodies (CABs), and Certification Bodies (CBs) to support the implementation and maintenance of the EUCC certification scheme.
Terragora would like to point out that cybersecurity is currently a major strategic issue for public institutions, businesses, local and regional authorities and European citizens. Cyber-attacks represent a considerable human, economic and security cost.
Filed in French · English published by the European Commission
Johnson & Johnson welcomes the European Commissions initiative to revise the EU Cybersecurity Act in response to the evolving threat landscape and the growing importance of cybersecurity for critical sectors, including healthcare and medical technologies.
Vewin, the Association of Dutch Drinking Water Companies, represents the collective interests of the public water utilities sector responsible for delivering safe and reliable drinking water across the Netherlands. Vewin welcomes the opportunity to provide feedback on the new Cybersecurity Act 2 that will repeal the former Cybersecurity Act Regulation (EU) 2019/811.
Vewin, the Association of Dutch Drinking Water Companies, represents the collective interests of the public water utilities sector responsible for delivering safe and reliable drinking water across the Netherlands. Vewin welcomes the opportunity to provide feedback on the simplification of the NIS2-Directive.
We appreciate the initiative to review the Cyber Security Act in the light of current geopolitical challenges, innovation leaps and clarity with regards to partially complimentary frameworks. We in particular support the strenghthening of the role of ENISA.
Panasonic greatly appreciates the opportunity in providing feedback on the Cybersecurity Act and NIS2 revision proposals. Panasonic endorses the European Commissions cyber resilience objectives within the proposed Cybersecurity Act (CSA2) and NIS2 Directive amendments, yet formally stipulates that immediate structural refinements are important to prevent market fragmentation and duplicative administrative burdens.
Siemens Healthineers welcomes the Commissions overarching objective to strengthen the Unions competitiveness while reducing unnecessary regulatory burdens, and at the same time ensuring a high level of cybersecurity and resilience across the EU.
From the banks perspective, The Cybersecurity Act 2 (CSA 2) represents a paradigm shift: away from a primarily technical and operational focus towards greater consideration of geopolitical risks, and from a technology-neutral approach towards more concrete guidelines for member states, for example regarding the transition to post-quantum cryptography.
As a digital services user organisation, Assistance Publique-Hôpitals de Paris wishes to express its concerns and structural needs regarding the planned revision of the Cybersecurity Act and in particular Title III thereof on the European cybersecurity certification framework. 1.
Filed in French · English published by the European Commission
Le règlement de l’UE sur la cybersécurité Le « tout numérique » est stratégiquement naïf : en cas de crise/conflit, l'électricité, la téléphonie mobile, Internet ou les fournisseurs d'accès peuvent être indisponibles pendant des jours/semaines.
Filed in French · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
InfraNum, the French Digital Infrastructure Federation, welcomes the publication of the public consultation on the Cybersecurity Act (CSA) and thanks to the European Commission for the opportunity to contribute to this consultation. First, InfraNum commends the Commissions ambition to strengthen the harmonisation and security of infrastructures as reflected in this proposal.
Filed in French · English published by the European Commission
The proposals to revise the Cybersecurity Act and amend the NIS2 Directive enhance the foundations of the European cybersecurity policy architecture, with the objectives of fostering legal certainty, reducing fragmentation, and strengthening cybersecurity governance across the Union.
The Association for Computing Machinery's Europe Technology Policy Committee (Europe TPC) is submitting the attached formal comments in response to the European Commission's Cybersecurity Act 2. ACM and its Europe TPC are non-profit, non-political, and non-lobbying organizations committed to providing technically grounded input to support sound public policymaking.
The revision of the 2019 Cybersecurity Act is a welcome and timely initiative considering the rapidly evolving threat landscape. Financial losses caused by cybercrime continue to rise, underscoring the urgency of strengthening Europes cybersecurity.
China-Europe Scientists Forum's Response to the European Commission's Proposal for the Cybersecurity Act 2 The China-Europe Scientists Forum welcomes the opportunity to provide feedback on the European Commission's proposal for a revised Cybersecurity Act.
Respuesta a la Consulta pública sobre reglamento (UE) sobre ciberseguridad 2 España cuenta con un ecosistema tecnológico y de conectividad seguro y resiliente que se basa en estándares internacionales en base a estrictos riesgos técnicos analizados y medidas de mitigación para afrontarlos de forma que se garantice la continuidad del servicio.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
ZVEI welcomes the objective of the proposed Cybersecurity Act 2 to reduce regulatory complexity and strengthen Europes cybersecurity framework. At the same time, the proposal should better reflect industrial realities and avoid creating additional burdens for companies.
On January 20, 2026, the European Commission (EC) presented a new cybersecurity package with the objective of strengthening the European Unions cybersecurity governance to prevent, detect, and respond to cybersecurity threats in a coordinated, interoperable, and effective manner. The package consists of two proposals: The proposal for a Regulation that revises the Cybersecurity Act (The Cybersecurity Act 2).
On January 20, 2026, the European Commission (EC) presented a new cybersecurity package with the objective of strengthening the European Unions cybersecurity governance to prevent, detect, and respond to cybersecurity threats in a coordinated, interoperable, and effective manner. The package consists of two proposals: The proposal for a Regulation that revises the Cybersecurity Act (The Cybersecurity Act 2).
# CSA 2 Needs an Execution Substrate: SMB-Viable Continuous Governance for Cyber Resilience *A practitioner response to the European Commission public consultation on the proposed Cybersecurity Act 2 (COM(2026)13)* **Narnaiezzsshaa Truong · Soft Armor Labs · April 2026** DOI: [10.5281/zenodo.19834324](https://doi.org/10.5281/zenodo.19834324) --- ### Portal Submission Text *(Plain text formatted for direct entry into…
The draft revision of the EU Cybersecurity Act (CSA2) presented by the European Commission has the important objective of ensuring a high level of cybersecurity across the Union and strengthening the resilience of critical digital infrastructures. However, in its current form, the proposal raises significant legal, technical and economic concerns.
Filed in German · English published by the European Commission
From INBUSINESS 5.0 we would like to send our comments to the European Commission on the proposed Cybersecurity Act 2, which aims to strengthen the EU's resilience and capabilities in the field of cybersecurity to adapt to the complexity of the current circumstances.
The ever-increasing cybersecurity threat landscape requires both regulators, industry and operators of critical infrastructures to adopt risk-adequate cybersecurity measures. Such concrete measures should be supported by a lean regulatory framework that outlines requirements and provides companies with the necessary support framework.
The ever-increasing cybersecurity threat landscape requires both regulators, industry and operators of critical infrastructures to adopt risk-adequate cybersecurity measures. Such concrete measures should be supported by a lean regulatory framework that outlines requirements and provides companies with the necessary support framework.
Revision of the Cybersecurity Act Commission Adoption: Feedback Submission Submitted by M. Raphael LLC (Raphael Legal) Feedback period: 5 February 2026 to 12 May 2026 | COM(2026)11 Ref: Ares(2025)2970891 | 24 April 2026 Raphael Legal | M. Raphael LLC Page 1 of 9 1.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Red Alert Labs welcomes the ambition of CSA2 to reinforce ENISA, simplify compliance, and enhance the overall effectiveness of the ECCF. From the perspective of a CAB, we believe the proposal could be further strengthened by providing additional legal certainty, proportionality, and predictability in the interaction between ICT supply chain security measures and the ECCF.
On behalf of Inria, the French National Institute for Research in Digital Science and Technology, we welcome the opportunity to provide our views with regards to the Cyber Resilience Act and the proposal to amend Directive (EU) 2022/2555. Our feedback is in particular related to the development of a secure and resilient supply chain, where we see potential future axes of research (see document attached).
In todays fast-evolving energy landscape and geopolitical situation, electricity transmission system operators (TSOs) are confronted with a variety of challenges that threaten the very backbone of Europes energy security, including new sophisticated cyber-attacks and rising hybrid threats targeting critical infrastructure on- and offshore.
In todays fast-evolving energy landscape and geopolitical situation, electricity transmission system operators (TSOs) are confronted with a variety of challenges that threaten the very backbone of Europes energy security, including new sophisticated cyber-attacks and rising hybrid threats targeting critical infrastructure on- and offshore.
German industry welcomes the European Commissions aim to significantly strengthen Europes cyber-resilience and to create a level playing field for essential and important entities across the European Union. Cyber and IT security are the basis for a long-term secure digital transformation of the state, economy and society.
COMMENTS OF THE MINISTRY OF COMMERCE OF THE PEOPLE’S REPUBLIC OF CHINA ON THE EU’S PROPOSAL FOR A REVISED CYBERSECURITY ACT The Ministry of Commerce of China has noted that the European Union published on January 20, 2026 a Proposal for a revised Cybersecurity Act and invited interested parties to comment. China is gravely concerned about the Proposal and hereby makes the following comments. I.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
ETSI is pleased to provide feedback to the proposed Cybersecurity Act 2, which seeks to strengthen EU-wide cybersecurity, reinforce ENISAs role, improve certification and introduce an EU-level framework for ICT supply-chain security.
Ibec welcomes the opportunity to provide feedback on the Cybersecurity Act review (CSA2) proposal. As Irelands largest representative trade association, we represent businesses across critical sectors of the Irish economy.
ETSI is pleased to provide feedback to the proposed Cybersecurity Act 2, which seeks to strengthen EU-wide cybersecurity, reinforce ENISAs role, improve certification and introduce an EU-level framework for ICT supply-chain security.
Christian Council International (CCI) appreciates the opportunity to provide feedback on the call for evidence on the revision of the Cybersecurity Act and the targeted amendments to Directive (EU) 2022/2555 (NIS 2 Directive). In this feedback, we address governance and regulatory coherence, proportionality, fundamental rights and the societal impacts of cybersecurity policy.
Christian Council International (CCI) appreciates the opportunity to provide feedback on the call for evidence on the revision of the Cybersecurity Act and the targeted amendments to Directive (EU) 2022/2555 (NIS 2 Directive). In this feedback, we address governance and regulatory coherence, proportionality, fundamental rights and the societal impacts of cybersecurity policy.
Public Comment on The EU Cybersecurity Act Logos Research Centre Claire Yang1, Abhinav Kokkula2, Ellta T. Abraham2, Suryaa Kalyan2, Saathvik Valvekar3 April 2026 1 First/Lead Author Secondary Author 3 Advisor; Logos Research Centre 2 Executive Summary This paper announces the 2026 revision to the European Union Cybersecurity Act, an update designed to strengthen the EU’s resilience to increasingly sophisticated…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Suivi : - [name removed] – Directeur Général des Services – Mission Ecoter [email removed] - Quentin MEULLEMIESTRE – Directeur Général des Services Adjoint – Mission Ecoter [email removed] Réponse à la Consultation sur le projet de révision du Cybersecurity Act (CSA2) [Bandeau d’explication de la Mission Ecoter] L’association Mission Ecoter salue l’ambition de la Commission européenne visant à renforcer la sécurité…
Filed in French · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
ACA Feedback on the Scope of the Food Sector under Annex II NIS2 Introduction The Airline Catering Association (ACA) welcomes the European Commission’s efforts to simplify and harmonise the implementation of Directive (EU) 2022/2555 (NIS2).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Telit Cinterion welcomes the opportunity to contribute to the public consultation. As a European provider of secure cellular and IoT connectivity modules deployed across critical and missioncritical systems, Telit Cinterions comments focus on strengthening Europes cybersecurity, supplychain integrity, and strategic autonomy.
Comments on the Regulation on the European Union Agency for Cybersecurity (ENISA), the European Cybersecurity and ICT Supply Chain Security Certification Framework, and repealing Regulation (EU) 2019/881 (Cybersecurity Act 2).
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The Austrian Chamber of Commerce welcomes the objectives of simplification, increased legal certainty and harmonisation of key provisions of the EU Cybersecurity Package (CSA 2 and amendment NIS 2) – the current proposal offers some opportunities to update the cybersecurity framework of the European Union. In particular, attempts to narrow down the scope of the relevant rules in a targeted manner seem promising.
Filed in German · English published by the European Commission
The business representatives of the German KRITIS Implementation Partnership (UP KRITIS), a public-private partnership between operators of critical infrastructures and the relevant authorities with more than 1000 member organizations in Germany, want to give feedback to the 4 main topics in the revision of the Cyber Security Act (CSA2) in the attached position paper 1. Expanded ENISA Mandate 2.
TIC Council, the global trade association representing the Testing, Inspection and Certification (TIC) sector, welcomes the CSA2 and proposes the attached recommendations. Our members play a key role in the operationalisation of the Cybersecurity Act by acting as Certification Bodies (CBs) and Information Technology Security Evaluation Facilities (ITSEFs).
To whom this may concern, PHOENIX group is the largest European integrated healthcare provider with 224 sites in the business areas of pharmaceutical wholesale and pre-wholesale across 29 European countries and with more than 3,200 pharmacies in 17 European countries.
The current proposal places a strong emphasis on strengthening cybersecurity and resilience, which is of course important, but risks creating new barriers for persons with disabilities -- specifically visually impaired people -- if accessibility is not structurally embedded in these measures, especially in the design and implementation of authentication and verification processes, such as captchas, multi-factor…
Infineon Technologies AG welcomes the European Commissions proposal for a review of the Cybersecurity Act (CSA2). The proposed updates of the mandate for the European Union Agency for Cybersecurity (ENISA) account for regulatory developments and an evolving cybersecurity threat landscape.
In principle, Amadeus welcomes the coordinated approach and uniform guidance outlined in the proposal. Amadeus also welcomes the intent to streamline certification processes as well as the objective of making the EU supply chains more resilient and secure. In our detailed comments (attached), we mainly raise awareness about the challenges that might arise with additional powers of NCAs (e.g.
Strengthening ENISAs Mandate on Standardization Danish Standards supports the Commissions proposal to strengthen ENISAs mandate in the field of standardization. Cybersecurity is an area developing rapidly, and a more active and coordinated contribution from ENISA can support the development of relevant European standards, ensure higher quality, and promote coherence across regulation, standardization, and industry…
Strengthening EU Cybersecurity Through Technical Excellence and International Cooperation We welcome the opportunity to contribute to the consultation on the proposed amendment of the EU Cybersecurity Act. A well-calibrated and future-proofed regulatory framework is essential to strengthening Europe's cybersecurity resilience, while maintaining innovation, openness, and competitiveness.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
LMA Response to the European Commission Call for Evidence on the Cybersecurity Act About the LMA The Lloyd’s Market Association (LMA) represents the fifty-one managing agents at Lloyd’s, with ninety-four active syndicates underwriting in the market and also the four members’ agents, which act for third party capital.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Deutsche Telekom welcomes the opportunity to contribute to the Call for Evidence on the revision of the Cybersecurity Act (CSA). Our views on the mandate of ENISA, potential improvements of the framework for cybersecurity certifcation schemes and regulatory simplification are detailed in the attached paper.
CIO Platform Nederland welcomes the opportunity to share its insights, and those of the CIO associations in Belgium and Germany, on the Cyber Security Act with the Commission. You can find these in the attached document, which has been drafted in close coordination with Beltug and VOICE e.V. We are off course available to explain our positions to the Commission, should that be desirable.
Marsh & McLennan Companies, Inc Avenue Herrmann-Debrouxlaan 2 B - 1160 Brussels T [phone removed] [email removed] www.mmc.com Memo To: European Commission, DG CNECT, Directorate H, Unit H1 Date: 20 June 2025 From: Aloïs Thiant, Director of Government Relations for Europe Subject: Review of the Cybersecurity Act About Marsh McLennan Marsh McLennan is the world’s leading professional services firm in the areas of…
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
From AMETIC, employers in the digital industry sector, we recognise the essential role played by the Cybersecurity Act (CSA) in shaping the cybersecurity governance and certification framework in the European Union.
Filed in Spanish · English published by the European Commission
CrowdStrike welcomes the opportunity to respond to the European Commissions Call for Evidence on the revision of the EU Cybersecurity Act (CSA). As a global, AI-native cybersecurity provider, we bring insights informed by frontline experience defending organizations from sophisticated, rapidly evolving cyber threats.
Secção 1: Mandato da ENISA. 1. Competências operacionais Reforçar substancialmente. A ENISA ainda atua mais como facilitadora do que como entidade executiva. É necessário: • Dotá-la de capacidades de resposta direta a incidentes cibernéticos de grande escala, à semelhança de um “centro europeu de ciberdefesa civil”.
Filed in Portuguese · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The TU Wien Cybersecurity Center supports the overall approach of the EU Cybersecurity Act (CSA), recognizing its potential to enhance the security of digital products and services across the European Union. We appreciate the emphasis on avoiding fragmentation of cybersecurity standards and certifications within the EU, and the strong role envisioned for the European Union Agency for Cybersecurity (ENISA) in…
At this time, we believe it is important not to make changes to the current text of the TUCA. We propose that ENISA's capacities and resources be strengthened, so that it can consolidate its current mandate and facilitate the effective implementation of existing legislation, contributing to the reduction of barriers to market entry and achieving a minimum level of maturity and adaptation before considering further…
Lenovo welcomes the Commissions revision of the Cybersecurity Act (CSA) and supports efforts to enhance cybersecurity, simplify regulatory frameworks, and foster an open, competitive digital economy. We underline the importance of maintaining a technical, risk-based approach to ICT security, grounded in international standards, and caution against the use of non-technical criteria or measures that could undermine EU…
Comprehensive feedback is provided in the attached PDF. We believe the Cybersecurity Act is in urgent need of being repealed, and replaced by more cohesive and modern EU regulations. Additionally, ENISA should be given more resources and responsibility, so that the EU truly works as a Single Market in the cybersecurity sector. National Cybersecurity Schemes should be abolished.
Clusit welcomes the opportunity to contribute to the impact assessment for the CSA, to provide feedback on the effectiveness of its adoption, and to suggest possible actions to improve this regulation. We will focus on the two main topics being discussed: the European Cybersecurity Certification Framework and the role and mandate of ENISA.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The European Telecommunications Standards Institute (ETSI) is pleased to provide its feedback on the call for evidence regarding an assessment of the Cybersecurity Act (CSA) adopted in 2019. Cybersecurity is a major focus area of ETSIs work with its Technical Committee CYBER being active for a long time supporting European and global market needs for improving cybersecurity and boosting resilience of the…
We are a Hungarian law firm, representing a local and international clientele with a strong focus on regulatory and compliance matters and on advising clients in contentious matters resulting from cyberfraud / cybersecurity incidents.
EuroCommerce welcomes the possibility to contribute to the call for evidence on the Cybersecurity Act (CSA). The CSA has provided a strong EU cybersecurity governance framework and increased trust in digital technologies.
ADERENTE A CONFINDUSTRIA RISPOSTA ASSTEL A CONSULTAZIONE UE SU REVISIONE DEL CYBERSECURITY ACT ___________________________________________________________________ 20 giugno 2025 1 ADERENTE A CONFINDUSTRIA ASSTEL (Associazione di categoria aderente a Confindustria che rappresenta la Filiera delle telecomunicazioni) riconosce il compito fondamentale del Regolamento Europeo del Cybersecurity Act nella costruzione del…
Filed in Italian · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Please find attached the position paper of NXP, in two parts, the first reviews the value of security certification from our experience. The second part discusses the possible improvement points of the CSA: - Simplification, - Unification, - Business centric, - CSA update in alignment with the reality of today, - Certification of devices, processes, systems (solutions), and people, - Development time and process.
The European Crypto Initiative (EUCI) and its members welcome the opportunity to contribute to the European Commissions call for evidence on the revision of the Cybersecurity Act (CSA). We support the objective of reinforcing Europes cyber resilience while simplifying obligations and fostering an environment that encourages innovation.
OVHcloud welcomes the revision of the Cybersecurity Act as a timely opportunity to both ensure secure and resilient IT services and strengthen ENISAs mandate, especially in the context of recent geopolitical challenges that have exposed Europes strategic vulnerabilities.
Insurance Europe is the European insurance and reinsurance federation. Through its 39 member bodies the national insurance associations it represents insurance and reinsurance undertakings active in Europe and advocates for policies and conditions that support the sector in delivering value to individuals, businesses, and the broader economy.
NetApp welcomes the opportunity to contribute to the European Commissions public consultation and call for evidence on the revision of the EU Cybersecurity Act. Recognizing the current pressures of the geopolitical landscape, we consider that the development and application of objective trusted vendor criteria in public and private sector procurement can advance the objective of securing the ICT supply chain.
Submitted by Hacken, a Web3 Cybersecurity Auditor. The EU has a real opportunity to lead in digital trust and innovation. But this requires regulation that ensures strong cybersecurity without blocking the development of new technologies. Clear, forward-looking rules are essential to let responsible innovation grow without legal uncertainty.
Ibec welcomes the opportunity to provide input to the review of the EU Cybersecurity Act. Ibec is Irelands largest lobby and business representative group, with a diverse membership and 39 sectoral trade associations. Please find our feedback in the attached paper.
Circularise is a technology company at the forefront of digital transparency and traceability in global supply chains. Through our Digital Product Passports (DPPs), we enable secure and standardized data exchange across a wide range of industrial sectors. Our solution supports regulatory compliance while directly contributing to the development of sustainable, resilient, and transparent value chains.
The Open Cloud Coalition (OCC) welcomes the European Commissions initiative to review the EU Cybersecurity Act (CSA) in light of evolving cyber threats. The Commissions call for feedback emphasizes goals of strengthening resilience,simplifying rules, and addressing ICT supply chain security.
Google welcomes the opportunity to provide feedback to the European Commission on the revision of the EU Cybersecurity Act. Consistent with the EUs International Digital Strategy, revising the Cybersecurity Act will help boost Europes competitiveness and innovation while improving security outcomes for European businesses, governments, and citizens.
In the context of the revision of the EU Cybersecurity Act (CSA), we welcome the steps taken to update ENISAs mandate and certification development framework in line with the new legislation such as NIS2, CRA, DORA, and better reflecting the changing needs, roles and tasks across the EU cybersecurity ecosystem.
June 20, 2025 Arvamus EL-i küberturvalisuse määruse kohta Lugupeetud Komisjon, Täname Teid võimaluse eest esitada oma seisukoht küberturvalisuse määruse kohta. Esitame alljärgnevalt oma üldised märkused ja tagasiside. Üldine tagasiside Täname SK ID Solutions AS-i kaasamise eest Euroopa Komisjoni küberturvalisuse määruse 2029/881 (edaspidi: määrus) ülevaatamise konsultatsiooni teemal.
Filed in Estonian · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Trellix, as a global leader in cybersecurity solutions serving both private and public sector clients, welcomes the European Commissions initiative to revise the Cybersecurity Act (CSA) and to simplify the EUs cybersecurity legislative framework.
POSITION PAPER on the Call for Evidence for an Impact Assessment of the Revision of the Cyber Security Act (CSA) Berlin, 20.06.2025 On 11 April 2025, the European Commission launched a consultation on the review of the Cybersecurity Act. This initiative is part of the Commission's current work programme, which places a strong focus on simplification alongside other points.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
I-Com agrees on the necessity to streamline cybersecurity requirements and reporting obligations. The current European regulatory ecosystem appears as a vast constellation, imposing a significant volume of duties and obligations often on the same entities which must carry out numerous activities, sometimes with differing timelines and procedures, to achieve identical or very similar objectives.
I. INTRODUCTION On April 11, 2025, the European Commission initiated a public consultation to support the revision of the EU Cybersecurity Act (Regulation (EU) 2019/881). The proposed updates aim to clarify ENISAs role, improve the European Cybersecurity Certification Framework, and ensure that cybersecurity measures are better aligned with the evolving digital ecosystem and legal framework.
Gen Digital, the global leader in consumer cyber safety and digital protection solutions, with renowned brands including Norton, Avast, LifeLock, Avira, and AVG, welcomes the European Commissions timely initiative to revise the EU Cybersecurity Act.
Consultation response European Commission Cybersecurity Act consultation AmCham EU speaks for American companies committed to Europe on trade, investment and competitiveness issues. It aims to ensure a growth-orientated business and investment climate in Europe.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Amadeus welcomes the opportunity to provide feedback on the European Commissions review of the EU Cybersecurity Act (CSA). Cybersecurity is central to Amadeuss systems in terms of application design and operations, providing high-performance transaction processing under strict system availability, security, and performance requirements.
Eurelectric welcomes the evaluation and upcoming review of the existing EU Cybersecurity Act. The review can, if designed appropriately, be useful to support the electricity sector in reinforcing energy security in Europe. ENISA plays a vital role in coordinating cybersecurity measures across the electricity sector, particularly in ensuring the resilience and security for the European grid.
Tim welcomes the opportunity to comment on the revision of the CSA. We support GSMA-Connect Europe input on the CSA review but wish to further elaborate on the European Cybersecurity Certification Framework and its possible evolution toward an instrument that can address, where needed and justified, also non-technical risks.
The Italian Association of Internet Providers (AIIP) is the first and longest-standing Italian association representing Internet operators, infrastructure and network providers, including FTTH, as well as providers of electronic communications services, data center and cloud services.
Berlin, 20. Juni 2025 Deutsche Industrie- und Handelskammer Stellungnahme Überarbeitung des Rechtsakts zur Cybersicherheit, Cybersecurity Act Das Ziel der Überarbeitung des Cybersecurity Act (CSA) besteht darin, Cybersicherheitsmaß nahmen zu straffen, die Cyberresilienz zu stärken sowie ein hohes gemeinsames Cybersicher heitsniveau in der gesamten EU zu erreichen und gleichzeitig einen Beitrag zur Vereinfa…
Filed in German · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The EUs cybersecurity framework has undergone substantial expansion since the adoption of the Cybersecurity Act (CSA) in 2019. Alongside the CSA, new legislative instruments including NIS2, the Cyber Resilience Act (CRA), DORA and the Cyber Solidarity Act now define a much more comprehensive and multi-layered regulatory architecture for cybersecurity across the single market.
The Estonian Information Technology and Telecommunications Union (ITL) welcomes the European Commission’s Cybersecurity Regulation 2029/881 (hereinafter: Regulation), as we consider that it has not been able to meet its objectives. The main concern is that ENISA has not managed effectively with the role attributed to it.
Filed in Estonian · English published by the European Commission
Please find attached the contribution of Sopra Steria to the public consultation on the review of the Cybersecurity Act (CSA). Sopra Steria welcomes this review as a timely and necessary initiative. We advocate for an ambitious revision that moves beyond technical adjustments to truly enhance the Union's strategic autonomy and digital resilience.
The Spanish Chamber of Commerce considers the initiative to revise the Cybersecurity Act to be timely and necessary, as an opportunity to strengthen existing instruments without compromising legal certainty or unnecessarily increasing the regulatory burden on the European business ecosystem.
Filed in Spanish · English published by the European Commission
Established in 1997, EuroISPA is the world's largest association of Internet Services Providers Associations, representing over 3,300 Internet Service Providers (ISPs) across the EU and EFTA countries. EuroISPA is recognised as the voice of the EU ISP industry, reflecting the views of ISPs of all sizes from across its member base. EuroISPA's feedback is attached below.
Response to public consultation on EU Cybersecurity Act CSA Response Proposal Recognizing the pivotal role of the Cybersecurity Act (CSA) in shaping the EU's cybersecurity governance and certification framework, we greatly value the opportunity to provide feedback and contribute to building a more efficient and effective regulatory environment.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Orgalim supports the initiative to review the Cybersecurity Act (CSA) and the opportunity to offer feedback to the wide-reaching public consultation on the cybersecurity legislative landscape. Orgalim emphasizes: the need for ENISA to employ a structured coordination approach with other stakeholders; the importance of CSA certification schemes to remain voluntary and the significance of simplifying cybersecurity…
Please see attached FIA's response to the European Commissions consultation on the cybersecurity act (CSA). FIA welcomes the Commission's stakeholder engagement to ensure improved and fit-for-purpose cyber risk management rules apply to financial entities. We recommend cyber risk management rules should apply from one ruleset if there is overlap and/or the same objectives.
Eurosmart supports a focused revision of the EU Cybersecurity Act (CSA) to strengthen ENISAs role, preserve the integrity of the European Cybersecurity Certification Framework (ECCF), and streamline certification. The CSA remains central to the EUs cybersecurity framework, and its alignment with other regulations (e.g., CRA, NIS2, AI Act) is essential to reduce duplication and simplify compliance.
The Computer & Communications Industry Association (CCIA Europe) appreciates the opportunity to submit its observations on the review of the Cybersecurity Act. The Cybersecurity Act remains a solid piece of legislation that is resolutely pro-Single Market.
Please find below our feedback. For your convenience, it is also attached as a PDF with structured formatting. Dear Commission Reviewer, The Open Source Initiative (OSI) is a global charity at the heart of the Open Source Community for over 25 years, recognized globally as the authority defining Open Source.
From: Philip Lee LLP Date: 20 June 2025 Re: Feedback on the EU Cybersecurity Act 1. Introduction 1.1 On April 11, the European Commission published its call for evidence regarding a potential revision of the cybersecurity framework established in Regulation (EU) 2019/881.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Connect Europe & GSMA views on the Cybersecurity Act Review June 2025 Section 1: Mandate of ENISA Connect Europe and GSMA welcome the opportunity to comment on ENISA’s mandate and to share our views on its future mandate and prioritization of tasks.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
APPLiA Response to Have Your Say - Open Ended Question APPLiA supports the Commission's simplification agenda and believes that aligning definitions, streamlining reporting mechanisms, and avoiding overlapping legislation will significantly reduce unnecessary administrative burdens and improve compliance across the EU.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
1. ON THE SIMPLIFICATION OF CYBER REPORTING European companies face an increasingly challenging environment, marked by the rising volume, complexity, and sophistication of cyber threats: since 2018, cyberattacks are considered as the most critical risk by Risk Managers worldwide (see: FERMAs Global Risk Manager survey, 2024).
The EUCC Information Sharing and Analysis Centre (ISAC) has submitted feedback on the revision of the EU Cybersecurity Act (CSA), emphasizing the need to institutionalize collaborative mechanisms between public and private stakeholders.
The European Publishers Council (EPC), representing leading European editorial media and publishing groups, welcomes the opportunity to contribute to the European Commission's Call for Evidence on the revision of the Cybersecurity Act (CSA).
In early 2025 the US National Vulnerability Database (NVD) the global hub for information on vulnerabilities and vulnerability management incurred the very real risk of being shut down due to lack of funding, only to receive a last-minute extension of less than a year.
As a European software company, Dassault Systèmes recognizes that robust cybersecurity is fundamental to ensure the integrity of digital operations and maintaining trust in increasingly interconnected industrial ecosystems.
Connect Europe & GSMA views on the Cybersecurity Act Review June 2025 Section 1: Mandate of ENISA Connect Europe and GSMA welcome the opportunity to comment on ENISA’s mandate and to share our views on its future mandate and prioritization of tasks.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
The App Association is a policy trade association for the small business technology developer community. Our members are entrepreneurs, innovators, and independent developers within the global app ecosystem that engage with verticals across every industry.
Feedback on the EU Cybersecurity Act The EU Cybersecurity Act (CSA) was introduced with the aim of strengthening cybersecurity across the Union. However, in its current form, the benefits for the industrial and critical infrastructure sectors are not preponderant, but the struggling with, especially in the railway domain.
In light of the CSA review and wider need for harmonisation of vulnerability disclosure requirements across several EU regulations (e.g. CRA, NIS2, DORA, AI act) as well as further sharing of supply-chain best-practices, the Open Regulatory Compliance (ORC) Working Group of the Eclipse Foundation wishes to share and reiterate the importance of the Common Vulnerabilities and Exposures (CVE) system and a stronger…
Vodafone welcomes the opportunity to comment on the revision of the Cyber Security Act and sees this exercise as an opportunity to drive forward much needed simplification of cybersecurity regulation impacting the digital services sector. We support a much larger role for ENISA in simplifying rules of the currently fragmented and overly complex cybersecurity landscape.
Given the continuously evolving nature of cyber-threats affecting the hospital and healthcare sector, HOPE is generally in favour of targeted European coordination and measures that improve resilience, lend support national, regional and institutional stakeholders cybersecurity actions, and enhance the protection of fundamental rights.
The Coalition to Reduce Cyber Risk (CR2) submits the attached comments in response to the European Commissions Public Consultation on revising the Cybersecurity Act. The Coalition appreciates the opportunity to provide input and looks forward to working with the European Commission as the Cybersecurity Act is updated.
OpenForum Europe (OFE) welcomes the opportunity to provide input to the public consultation on the revision of Regulation (EU) 2019/881 (Cybersecurity Act). The revision of the Cybersecurity Act presents a timely opportunity to align ENISAs mandate with the realities of the rapidly developing cybersecurity field.
Orange welcomes the opportunity to provide input in the context of the review of the Cyber Security Act. It is a timely review of both the mandate of ENISA and of the European Cybersecurity Certification Framework, allowing us to take stock and plan for the future.
The Confédération des Petites et Moyennes Entreprises (CPME) represents French SMEs across all sectors and regions. In its response to the consultation on the EU Cybersecurity Act, CPME supports the objective of strengthening cybersecurity, but stresses the need for a more accessible, consistent and proportionate framework.
The Cybersecurity Act (the CSA) set a permanent mandate for the European Union Agency for Cybersecurity (ENISA) and established a European Cybersecurity Certification Framework (ECCF) for voluntary European cybersecurity certification schemes for ICT products, services and processes.
ENISAs mandate needs to be critically assessed, focusing its tasks on areas where it can provide the most European value added that member states cannot achieve independently. It has far too many tasks in its mandate (even approx. 80 various tasks) and there is a need to significantly reduce them.
Ports are increasingly becoming information-rich environments, meaning cybersecurity is now an essential element of the security of port ecosystems. It is critical for the protection of physical infrastructure and companies performing cargo handling and logistics activities in ports, but also for protecting sensitive data and ensuring operational continuity in ports as well as the maritime and hinterland logistics…
Positionspapier r zur Überarbeitung des EU-Rechtsakts zur Cybersicherheit Sondierung der EU-Kommission Kernforderungen der Kommunalwirtschaft: • Bürokratie abbauen; • Security-by-Design als Grundelement sicherstellen; • Gänzliche Sicherheit in der IKT-Lieferkette verankern.
Filed in German · English published by the European Commission
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Recognizing the CSA's critical role in creating the EU's cybersecurity governance and certification landscape, Adigital, the Spanish Association of Digital Economy, appreciates the opportunity to provide feedback and contribute to a more efficient and effective regulatory framework.
The Charter of Trust, a coalition of global companies dedicated to cybersecurity, welcomes the opportunity to submit our consolidated response to the European Commissions public consultation on the revision of the Cybersecurity Act. We endorse policy option2, which advocates for targeted regulatory interventions to resolve current issues without adding complexity.
Amazon response to the European Commission Call for Evidence regarding the revision of the Cybersecurity Act, 19 June 2025 Executive Summary At Amazon, security is job zero. Our top priority is safeguarding the security and confidentiality of our customers’ information.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
U.di.Con. APS Union for Consumer Defence, included in the list of consumer associations and representative users at national level, of which it is alarming. 137 of Legislative Decree No 206 of 6 September 2005 and member of the National Council of Consumers and Users (CNCU), summarises the following comments in relation to the above.
Filed in Italian · English published by the European Commission
Microsoft welcomes the opportunity to contribute to the Call for Evidence on the revision of the Cybersecurity Act (CSA). We firmly believe that cybersecurity is a shared responsibility, achievable through collaboration between service providers and consumers.
The CRC in Vienna welcomes any initiative to strengthen cybersecurity resilience, but warns against putting geopolitical factors on the same level or above the relevant technical standards. As regards the strengthening of ENISA, we take the view that resources should be strengthened for the existing areas of activity instead of expanding the Agency’s competence.
Filed in German · English published by the European Commission
Red Alert Labs welcomes the EC's initiative to revise the CSA and is pleased to contribute as a CAB/ITSEF actively engaged in cybersecurity certification across multiple regulatory domains. We support the goals of reinforcing ENISAs mandate, improving the ECCF, and streamlining cybersecurity legislation.
The European Solar Manufacturing Council, which represents around 70 companies involved in European solar manufacturing, including many inverter manufacturers, welcomes the opportunity to contribute to the revision of the Cybersecurity Act (CSA).
CECIMO, representing European Manufacturing Technologies, welcomes the European Commissions initiative to revise the Cybersecurity Act (Regulation (EU) 2019/881). As highlighted in our publication Cybersecurity for the Machine Tool Industry, the increasing digitalisation of manufacturing has raised cybersecurity risks that threaten operations, safety, and intellectual property, especially for SMEs operating in…
Position Paper June 2025 Cybersecurity Act Revision Summary The Cybersecurity Act (CSA) was introduced in 2019 as a central instrument of the European Union to strengthen the cyber security of information and communication technologies. At the time, there were no other European harmonized requirements for products concerning cybersecurity.
Opening of the attached position paper · the full paper is on the Commission’s record (source link above)
Nokia welcomes the opportunity to comment on the EU's CSA and the overall simplification agenda in the area of cyber security. The outcome should consist in optimizing cybersecurity protection, while enhancing the consistency and clarity of the EUs regulatory framework, increasing the efficiency of private sector compliance.
Digital Business Ireland (DBI) is Irelands national representative body for the e-commerce, digital and tech sectors in Ireland" Digital Business Ireland believes that existing and cybersecurity laws guidelines should be implemented and enforced fully at MS level, as opposed to enacting new regulations or looking to develop completely new legislation.
The Test & Measurement Coalition (TMC, represented by its permanent secretariat EPPA) welcomes the Commissions initiative to revise the Cybersecurity Act. As a coalition representing approximately 60 percent of global production in the industrial test and measurement sector, we appreciate the opportunity to provide input on the future direction of the EU cybersecurity framework.
Alliance for AI, IoT and Edge Continuum Innovation is providing the following feedback: One of the key tasks of the Cybersecurity Act (CA) is to create the European Cybersecurity Certification Framework ECCF. In this context, we agree that the Cybersecurity Certification should be based on technical standards, which can be measurable and assessable with measurable and EU Member States aligned cybersecurity criteria.
As one of Europes leading research organisations, the CNRS (French National Centre for Scientific Research) is deeply committed to advancing a secure, resilient, and innovative European research landscape. The digital transformation of research and innovation activities brings both unprecedented opportunities and new cybersecurity challenges for institutions such as the CNRS.
This is the Open Source Security Foundation (OpenSSF) Global Cyber Policy Working Groups response to the European Commissions Public Consultation for The EU Cybersecurity Act Call for Evidence (with comments from the OpenSSF Public Policy Committee). See the attached file for details of our response.
The VÖB (Association of German Public Banks) welcomes the opportunity to provide input on the review of the Cybersecurity Act (CSA) and supports the EUs objective to enhance cybersecurity across sectors. At the same time, we underline the urgent need to reduce regulatory complexity and avoid duplicative compliance burdensparticularly in the area of incident reporting.
Hikvision welcomes the opportunity to contribute to the revision of the EU Cybersecurity Act. We believe a harmonized, risk-based, and proportionate approach is essential for a thriving digital single market. We advocate for clear, practical certification schemes aligned with international standards (e.g. ISO 27001, ETSI EN 303 645) and a strengthened ENISA with a clear mandate.
We welcome the opportunity to provide feedback on the revision of the Cybersecurity Act. The attached document, prepared by FieldUnit, outlines our key concerns and recommendations based on the evolving realities of the cybersecurity landscape.
The TÜV Association welcomes the Commissions intention of revising the Cybersecurity Act (CSA). The CSA has been the first horizontal EU cybersecurity legislation by establishing cybersecurity requirements for products, services and processes. While being a relevant pillar still today, the CSA with its European Cybersecurity Certification Framework (ECCF) has unfortunately never reached its full potential.
epicenter.works welcomes the European Commissions initiative. Cybersecurity is not merely a technical issue. It is a core pillar of democratic resilience, fundamental rights, and inclusive digitalisation. From our perspective, three key priorities must be at the heart of this revision (This is a shortened version for further details please see the Annex): 1.
This is Adolfo Borrero Villalón, CEO of AALTO Consultores, a strategic Smart Territories Consultancy, founded in 2014 and headquartered in Sevilla, Spain. We specialize in strategic advisory services for Smart Cities and Smart Territories, combining expertise in public administrations and private sector clients.
Attached is feedback from APKT – Association of Cable and Telecommunication Networks Operators. APKT members are small to medium-sized cable network operators using FTTH or DOCSIS technologies. We can already see that the regulatory measures that affect us are significant, and next year, in the electronic communications the obligations from the new Cybersecurity Act will be added, which apply to every business…
Filed in Czech · English published by the European Commission
To ensure safe digitalisation at all levels, we, the undersigned members of the Inter-Parliamentary Alliance on China call for the introduction of observer status in the European Union Agency for Cybersecurity (ENISA) for Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia and Serbia.
Thank you for the opportunity to provide comments on the revision of the EU Cybersecurity Act. Please find attached the submission of the Information Technology Industry Council (ITI). ITI is the premier global advocate for the technology sector, representing the worlds most innovative companies.
ENISA, as a cybersecurity agency of increasing importance (digitalisation), should be able to focus on further developing its own capabilities and providing technical support, for example on standards and certification processes. However, an amendment to the EU Cybersecurity Act would not necessarily contribute to strengthening ENISA’s competences or providing additional resources.
Filed in German · English published by the European Commission
Axis Communications appreciates the opportunity to contribute to the public consultation on the revision of the EU Cybersecurity Act (CSA). As stakeholders in the cybersecurity ecosystem, we believe that the revision of the CSA is a crucial step towards enhancing the EU's cyber resilience and ensuring a high common level of cybersecurity across the Union.
TIC Council, the international trade association representing the independent testing, inspection, and certification (TIC) industry, believes that the current revision of the Cybersecurity Act (CSA) is a key opportunity to fully realise its potential.
The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to contribute to the European Commissions consultation on the revision of Regulation (EU) 2019/881 (the Cybersecurity Act).
Recognizing the CSA's critical role in creating the EU's cybersecurity governance and certification landscape, we strongly appreciate the opportunity to give its feedback in and provide input to contribute to a more efficient and effective regulatory framework.
I believe that the EU must become more competitive and develop better business environment due to the rise of serious competetition on a global scale. Nonetheless, the EU must care for personal privacy and basic human rights that are the cornerstone of the Union.
As the EUs cybersecurity policy landscape evolves at an unprecedented pace, the European Commissions ongoing evaluation of ENISA marks a pivotal moment to reassess the agencys capacity and clarify its strategic direction. Recent legislation, including the Cyber Resilience Act and the Cyber Solidarity Act, has significantly expanded ENISAs workload.
We are happy with the current text of the CSA and the support given by ENISA. We find Recital (94) and Article 57 of the CSA very important in order to prevent fragmentation of the market by multiple and different cyber security certification approaches. In combination with the CRA and the use of EUCC it would prevent further fragmentation of the cyber security certification approaches we currently see in Europe,
The European fem Institute recommends the inclusion of gender-based violence as a non-technical risk factor in a European cybersecurity certification scheme. The current framework focuses mainly on technical risks, while leaving aside the systemic and societal risks associated with the use of technology for bullying, intimidation and violence against specific groups, in particular women.
Filed in Polish · English published by the European Commission
Infineon Technologies AG fully supports expanding the mandate of the EU Agency for Cybersecurity (ENISA), improving the European Cybersecurity Certification Framework (ECCF), and simplifying existing cybersecurity legislation. The problems identified in the Call for Evidence warrant a regulatory intervention in accordance with Policy Option 3.
GMVV & Co. GmbH is a strategic think tank, registered with the Parliament of the European Union and the Commission in the EU Transparency Register under Section IV, specialized in research in the field of criminal law and justice in connection with the protection of human and civil rights. In April 2023, the European Commission presented a proposal to amend Regulation (EU) 2019/881 (Cybersecurity Act, CSA).
The Business Software Alliance (BSA) welcomes the opportunity to provide an answer to the European Commissions Call for Evidence on the Review of the EU Cybersecurity Act (CSA). BSAis the global trade association of the enterprise software industry, representing companies that are leaders in artificial intelligence, cybersecurity, cloud computing, and other cutting-edge technologies.
Please find enclosed the feedback from the APMS (the Association of Mobile Network Operators), which brings together the three largest mobile operators in the Czech Republic. We strongly oppose giving ENISA additional powers in the field of vendor screening. In the Czech Republic, several state institutions already have this power.
Filed in Czech · English published by the European Commission
The Cybersecurity Act (CSA) establishes a harmonized approach to cybersecurity certification in the EU, and the European Cybersecurity Certification Framework (ECCF) should be implemented in accordance with its mandates. By reinforcing existing technical standardsrather than introducing subjective criteriathe ECCF can maintain consistency and avoid regulatory fragmentation.
ISACA welcomes the CSA revision as a key opportunity to harmonise EU cybersecurity rules, enhance ENISAs mandate, and build digital resilience. It calls for a stronger role for ENISA in policy implementation, technical coordination, and skills development. ISACA supports making cybersecurity certification more structured and tailored, including professional certifications to close the cyber skills gap.
This policy brief provides targeted recommendations to support the revision of the EU Cybersecurity Act, with a focus on improving regulatory coherence, certification uptake, and systemic resilience. It argues that the Act should evolve into an interoperable regulatory backbone (not merely a certification toolkit) capable of supporting Europes digital sovereignty while remaining technically neutral and operationally…
The position of VNICTP z.s. on the revision of the Cybersecurity Act (CSA) thank us for the possibility to provide feedback in the context of the public consultation on the revision of the Cybersecurity Act. We build on the practical experience of our members, including SMEs in digital, electronic communications and financial services.
Filed in Czech · English published by the European Commission
The Cultural Foundation for Innovation, an accredited training body for the Campania Region, which has for years been dealing with the digital transformation of the new generations and suffers from schools, wishes to work together on a long-term basis, setting out the following thoughts: Among the proposed options, we consider that the best scenarios are 1 (maintaining the status quo) or 2 (non-legislative measures)…
Filed in Italian · English published by the European Commission
We are a foundation dealing with technology and innovation in the south of Italy and a Cybrec laboratory department dedicated to cyber technologies to combat cybercrime in organised crime (https://fondazionemagnagrecia.it/cybrec-cybercrime-research-center/).
Filed in Italian · English published by the European Commission
This document presents feedback from DigitalTrade4.EU, a pan-European consortium of trade, logistics, and technology experts, to the European Commission. It advocates for aligning digital trade solutionsparticularly interoperable standards like MLETR and eIDAS 2.0with the EU's cybersecurity and defense initiatives.
The existing framework of the Cybersecurity Act (CSA) should be maintained and no legislative changes should be made. The 2019 CSA, most recently completed in January 2025, already provides a solid basis for cybersecurity in the EU. ENISA’s role has been strengthened by its permanent mandate, increased resources and a central role in operational cooperation and crisis management in MS.
Filed in German · English published by the European Commission
The response to the call for evidence for the impact assessment – Revision of the Cybersecurity Act Czech Fintech Association (ČEFTAS) appreciates the possibility of submitting evidence for the impact assessment on the revision of the Cybersecurity Act (CSA).
Filed in Czech · English published by the European Commission
As a law Firm with expertise in telecom, digital law and business tech, we welcome the opportunity to participate in the consultation initiated by the European Commission. We share the Commissions view that the evolution of networks and technology requires regular reassessment of cybersecurity risks.
As a general observation, I have been advising various stakeholders in the ICT and other industries on technology and information security matters for the past 30 years. I find it very concerning that recent soft-law EU initiatives, such as the EU Toolboxes, along with legal instruments developed under Article 288 TFEU, are attempting to introduce geopolitical questions into regulations that should be purely…
The 2025 revision of the EU Cybersecurity Act (CSA) arrives at a pivotal moment, as the digital threat landscape evolves rapidly in scale and complexity. Originally adopted in 2019 to establish ENISA's permanent mandate and introduce the European Cybersecurity Certification Framework (ECCF), the CSA has since become misaligned with the current needs of stakeholders due to a surge in geopolitical tensions, supply…
As a cybersecurity consulting company based in Austria, we appreciate the opportunity to comment on this initiative. Zettasecure is dedicated to supporting resilient, secure, and sustainable infrastructure globally. While we are mostly advocating deregulation in European law, we think that option 3 would be the only way in which SMEs would consider cybersecurity as an important topic.
As owner of a small and medium-sized enterprise, I recognise and appreciate the crucial role of the EU Cybersecurity Agency (ENISA) in shaping the cybersecurity governance and certification framework in the European Union. We highly appreciate the possibility to share our knowledge and contribute to our views. We believe that the most efficient and balanced course of action is Option 1 to maintain the status quo.
Filed in Greek · English published by the European Commission
The ongoing revision of the EU Cybersecurity Act presents a unique opportunity to reflect critically on the current state of cybersecurity legislation and to reshape it in a way that is pragmatic, technically sound, and truly supportive of Europes digital resilience.
EU initiatives can create value for our companies and citizens but we need to streamline associated overhead. It would be highly appreciated if a central EU instance (e.g., ENISA) provides a single point of contact for all notifications required by any EU initiative like NIS2. Then, in the background this information is made available to any relevant national authority.
The establishment of an EU scheme for certifying the cybersecurity of cloud services (EUCS) has been under discussion for years. However, debates about the inclusion of so-called sovereignty requirements in an EUCS are delaying an agreement. In a comprehensive publication attached, the Centre for European Policy (cep) outlines ways out of the deadlocked discussion surrounding the EUCS.
Kaspersky, a global cybersecurity company committed to supporting secure and resilient digital infrastructure across the EU and globally, welcomes the European Commissions initiative to revise the Cybersecurity Act. We recognize the CSAs pivotal role in defining the EUs cybersecurity governance and certification landscape and we are grateful for the opportunity to share our experience and to provide feedback.
SmartAvatar's cybersecurity principle: Designed not just to comply with the threats of today, but to anticipate and outpace the adversaries of tomorrow. To secure Europes digital future, cybersecurity must evolve from an optional add-on to an embedded, living infrastructure.
The EU Cybersecurity Act (2019) aims to enhance cybersecurity across the Union by strengthening the European Union Agency for Cybersecurity (ENISA) and establishing a framework for cybersecurity certification of ICT products, services, and processes. Improving it could address emerging threats, technological advancements, and implementation challenges.
Cybersecurity cooperation is especially relevant given that European Commission President Ursula von der Leyen has stated the 6 billion Growth Plan is intended to among others d [] allow the Western Balkans to benefit soon from key areas of our single market, including free movement of goods, services and workers, the single euro payments area, transport, energy and the digital single market.
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.