International Edition
Latest News
Technology

EU Cybersecurity Act 2 & Digital Networks Act: Impact on Businesses

EU Cybersecurity Act 2 and Digital Networks Act: A New Era of Digital Resilience The European Commission has proposed sweeping new regulations – the Cybersecurity Act 2 (CSA2) and the Digital Networks Act (DNA) – aimed at bolstering…

EU Cybersecurity Act 2 & Digital Networks Act: Impact on Businesses

EU Cybersecurity Act 2 and Digital Networks Act: A New Era of Digital Resilience

The European Commission has proposed sweeping new regulations – the Cybersecurity Act 2 (CSA2) and the Digital Networks Act (DNA) – aimed at bolstering the EU’s cybersecurity posture and driving digital innovation. Announced on January 20, 2026, these proposals signal a significant shift towards enhanced digital resilience and competitiveness for entities operating within the European Union . The drafts are now under negotiation by the European Parliament and the Council .

Strengthening Cybersecurity Governance with CSA2

The Cybersecurity Act 2 (CSA2) focuses on three key areas: increasing Information and Communication Technologies (ICT) supply chain security, galvanizing the implementation of the European cybersecurity certification framework, and expanding the mandate of the European Union Agency for Cybersecurity (ENISA) . A particularly impactful element of the CSA2 is the potential designation of non-EU countries as posing cybersecurity concerns to ICT supply chains. Entities established in, or controlled by, such countries – or their nationals – could be deemed “high-risk suppliers,” facing restrictions on participation in public procurement and eligibility for European cybersecurity certificates .

Modernizing Digital Infrastructure with the DNA

The Digital Networks Act (DNA) aims to incentivize investment and innovation in advanced connectivity, accelerating the transition to fiber and 5G/6G networks, and promoting cloud-based computing infrastructures to support AI development and deployment . The DNA consolidates fragmented telecom, spectrum, and network frameworks into a single, harmonized legal instrument .

Implications for Businesses

These proposals carry significant implications for businesses operating within the EU. Key considerations include:

  • Stricter Supply Chain Due Diligence: Organizations will need to enhance their scrutiny of ICT supply chains to identify and mitigate cybersecurity risks.
  • Expanded Certification and Compliance Requirements: The scope of cybersecurity certification schemes is expected to broaden, requiring organizations to demonstrate compliance with evolving standards.
  • Significant Enforcement Risks: Non-compliance could result in substantial fines, potentially reaching up to 7% of global annual turnover.
  • Increased Regulatory Complexity: Businesses must navigate the interplay between the CSA2, DNA, NIS 2, and the Cyber Resilience Act, necessitating a reassessment of risk management, supply chain, and operational structures.

ENISA’s Evolving Role

The Commission is seeking to clarify the mandate of the EU Agency for Cybersecurity (ENISA) as part of the Cybersecurity Act revision , further solidifying its role in supporting cybersecurity efforts across the EU.

The CSA2 and DNA represent a proactive approach by the European Commission to address the growing challenges of cybersecurity and digital transformation. Businesses must proactively prepare for these changes to ensure continued compliance and maintain a competitive edge in the evolving digital landscape.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”