EU Cybersecurity Act 2: A summary of the key points

The European Commission has proposed a new security package to further strengthen the EU’s resilience: the Cybersecurity Act 2. Why is CSA2 so important? What changes will it bring? And what role does System Hardening play? We answer these and other questions briefly and clearly.

The EU wants to establish a new cybersecurity framework

Europe is under attack. AI-powered attacks, complex ransomware networks, and geopolitically motivated sabotage are no longer merely theoretical scenarios but – unfortunately – a reality we are facing. Governments are trying to address these threats by introducing an ever-increasing number of IT security regulations and programs. The aim is to “encourage” government agencies, critical infrastructure organizations, and companies to (finally) take cybersecurity seriously.

Following NIS2, DORA and CRA, another initiative is now on the horizon. On January 20, 2026, the European Commission presented the EU Cybersecurity Act 2 (CSA2). This new legal framework is not a simple update to the existing European Cybersecurity Act, which has been in effect since 2019, but rather a fundamental reform.

What changes will CSA 2 bring?

The Cybersecurity Act 2 could completely replace the 2019 regulation. The old regulation would thus cease to be valid and be superseded by the new European Cybersecurity Act. In addition, the CSA2 reforms the EU certification framework.

This means that the new rules and standards will fundamentally change the way certifications are conducted in the EU. At the same time, ENISA (the European Union Agency for Cybersecurity) will be elevated from an advisory to an operational body.

Put simply, the core objectives of CSA2 are: Moving away from national fragmentation toward a coordinated EU response to cyber threats at highspeed!

How does CSA2 relate to NIS2, CRA and CER?

The European Cybersecurity Act 2 (CSA2) is intended to serve as a link between the new Network and Information Security Directive (NIS2), the Cyber Resilience Act (CRA), and the Critical Entities Resilience Directive (CER). Among other things, it will establish a single entry point for incident reporting. In this way, CSA2 could put an end to the current chaos of multiple reporting requirements under various regulations.

For example: A manufacturer of medical IoT devices must comply with both NIS2 and the Cyber Resilience Act. In the event of a cybersecurity incident, the company must report it to various authorities, often using different formats, deadlines, and requirements. This has led to a significant administrative burden due to duplicate work. The CSA2 addresses this issue by introducing a unified reporting channel.

Which companies are affected by CSA2?

CSA2 is aimed at manufacturers and providers of ICT products, services, and processes, including cloud providers, which serve as “high assurance” test cases. Managed Security Service Providers (MSSPs) will also be more heavily covered by the European certification in the future. Operators of critical infrastructure, as defined in the NIS2 sectors, as well as providers of electronic communications networks, are also affected.

Currently, CSA2 has not yet been finally adopted. The procedure is underway in the European Parliament under file number 2026/0011(COD) and is listed as “awaiting committee decision.” A specific date for its entry into force has not yet been set.

What role does system hardening play in CSA2?

As mentioned, the revision of the European Cybersecurity Act has not yet been adopted. There is currently only a draft (“Proposal for a Regulation on the EU Cybersecurity Act”). Nowhere in the accompanying downloads is the term “System Hardening” mentioned. Instead, the text refers to “Secure Configuration” and “Mitigation Measures,” among other things.

Ausschnitt aus dem EU CSA2 (Bild: EU Commission)

Manufacturers and providers of certified ICT products, services, or processes must provide users with “Guidance and Recommendations” for Secure Configuration, installation, deployment, operation, and maintenance. In addition, the draft requires a “Secure by Default and by Design” approach. This requirement is already familiar from the Cyber Resilience Act.

The CSA2 takes the same view: Configurations must be protected against unauthorized tampering, and there must be no known exploitable vulnerabilities. Regular testing and security audits, including high-assurance-level penetration tests, are also required.

Another key point is ongoing compliance. Certification schemes must include rules for how the compliance of certified products, services, or processes is continuously monitored and documented. A Secure Configuration (also known as System Hardening) is therefore not a one-time state, but a characteristic that must be demonstrated on an ongoing basis.

Conclusion

With the EU Cybersecurity Act 2, the “hope” approach is being set aside. Secure Configuration and System Hardening are no longer voluntary self-regulation measures but are becoming strategically important legal and market requirements.

For you as an IT decision-maker or security manager, this means that anyone who ignores the new requirements for supply chains, certifications, and Secure Configurations risks not only losing market access but also facing sanctions that could threaten the very existence of their business. CSA2 is therefore not just another bureaucratic paper tiger. It is becoming a fundamental set of requirements that you must comply with.

Not sure how to implement System Hardening in accordance with CSA2 and other regulations? Then contact us! We’d be happy to explain how you can implement a professional hardening process in your organization. We’d also be happy to show you how to use Enforce Administrator to automate the hardening of your systems and generate the necessary audit reports at the click of a button.

💬 Get in touch!

Images: Magnific , EU Commission

Leave a Reply