EU Cybersecurity Act 2 and Digital Networks Act: A New Era of Digital Resilience
The European Commission has proposed sweeping new regulations – the Cybersecurity Act 2 (CSA2) and the Digital Networks Act (DNA) – aimed at bolstering the EU’s cybersecurity posture and driving digital innovation. Announced on January 20, 2026, these proposals signal a significant shift towards enhanced digital resilience and competitiveness for entities operating within the European Union . The drafts are now under negotiation by the European Parliament and the Council .
Strengthening Cybersecurity Governance with CSA2
The Cybersecurity Act 2 (CSA2) focuses on three key areas: increasing Information and Communication Technologies (ICT) supply chain security, galvanizing the implementation of the European cybersecurity certification framework, and expanding the mandate of the European Union Agency for Cybersecurity (ENISA) . A particularly impactful element of the CSA2 is the potential designation of non-EU countries as posing cybersecurity concerns to ICT supply chains. Entities established in, or controlled by, such countries – or their nationals – could be deemed “high-risk suppliers,” facing restrictions on participation in public procurement and eligibility for European cybersecurity certificates .
Modernizing Digital Infrastructure with the DNA
The Digital Networks Act (DNA) aims to incentivize investment and innovation in advanced connectivity, accelerating the transition to fiber and 5G/6G networks, and promoting cloud-based computing infrastructures to support AI development and deployment . The DNA consolidates fragmented telecom, spectrum, and network frameworks into a single, harmonized legal instrument .
Implications for Businesses
These proposals carry significant implications for businesses operating within the EU. Key considerations include:
- Stricter Supply Chain Due Diligence: Organizations will need to enhance their scrutiny of ICT supply chains to identify and mitigate cybersecurity risks.
- Expanded Certification and Compliance Requirements: The scope of cybersecurity certification schemes is expected to broaden, requiring organizations to demonstrate compliance with evolving standards.
- Significant Enforcement Risks: Non-compliance could result in substantial fines, potentially reaching up to 7% of global annual turnover.
- Increased Regulatory Complexity: Businesses must navigate the interplay between the CSA2, DNA, NIS 2, and the Cyber Resilience Act, necessitating a reassessment of risk management, supply chain, and operational structures.
ENISA’s Evolving Role
The Commission is seeking to clarify the mandate of the EU Agency for Cybersecurity (ENISA) as part of the Cybersecurity Act revision , further solidifying its role in supporting cybersecurity efforts across the EU.
The CSA2 and DNA represent a proactive approach by the European Commission to address the growing challenges of cybersecurity and digital transformation. Businesses must proactively prepare for these changes to ensure continued compliance and maintain a competitive edge in the evolving digital landscape.