ISACA warns that the CSA2 risks creating a disproportionately burdensome attestation architecture for cybersecurity skills certifications and professional development. In the attached position paper, we argue that the EU does not need a new attestation market to make cybersecurity skills understandable.
ISACA
Other · Belgium · EU Transparency Register 374119228970-51
Counts here are a floor, never a total: they cover the 326 consultation files tracked so far (29,503 submissions, mostly 2025–26), so an organization's real filing history is larger, not smaller.
Who they are
Among the 784 non-governmental organisations on this site, they rank #439 by legislative files engaged — a count of participation, not a measure of influence.
Declares membership of
- Members of the European Cybersecurity Organisation (ECSO).
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026).
- Register category
- Non-governmental organisations
- Head office
- Illinois, United states
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026); cost bands are floors, not audited totals. Reused under Commission Decision 2011/833/EU.
Track ISACA in PolicySpeak: request access →
Work at ISACA? so we know who speaks for it.
Their record over time
ISACA filed 2 positions between 5 Jun 2025 and 12 May 2026, across 1 of the 326 legislative files tracked here, attaching a full position paper 2 times.
What they argued
ISACA welcomes the CSA revision as a key opportunity to harmonise EU cybersecurity rules, enhance ENISAs mandate, and build digital resilience. It calls for a stronger role for ENISA in policy implementation, technical coordination, and skills development. ISACA supports making cybersecurity certification more structured and tailored, including professional certifications to close the cyber skills gap.
Looking for an argument rather than an organization? Search every submission for a phrase and see everyone who used it.
Is this your organization?
Everything on this page comes from ISACA’s own submissions to the European Commission — we have added nothing and interpreted nothing. If something is wrong or out of date, email info@policyspeak.com and we will correct it. If you are an individual named in a record, our privacy policy sets out your rights to correction, objection and removal.
Quotes are verbatim from submissions published by the European Commission, trimmed to their opening passage and never summarized by a model. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.