About the Cybersecurity Act (CSA)
Full name: Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)
Type: Regulation
Objective and key elements:
- Sets the foundation for the cybersecurity strategy
- Security by design requirement introduced
- Reinforces ENISA, the EU Agency for Cybersecurity, link
- Creates a European cybersecurity certification framework for ICT products, services and processes
- Sets obligations for manufacturers and providers of certified ICT products, services or processes to make certain information publicly available
Relevant to: Mainly ENISA, national cybersecurity certification authorities, and suppliers of ICT products, services and processes. Status: In force, fully applicable since 28 June 2019.
On 19 December 2024, the European Parliament and the Council adopted a targeted amendment to the CSA, aiming to enhance EU’s cyber resilience by enabling the introduction of European certification schemes for managed security services, increasing their quality and comparability. The amendment was published in the Official Journal on 15 January 2025 and entered into force on 4 February 2025. You can access the amendments here
Guidance:
The revised Cybersecurity Act (2026):
Full name: REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)
Type: Regulation
Objective and key elements (as regards NIS2):
The four main problems that the proposed revision of the CSA aims to tackle:
- The misalignment between the Union’s cybersecurity policy framework and stakeholders’ needs in an increasingly hostile threat landscape
- The stalled implementation of the European cybersecurity certification framework (ECCF)
- The complexity and diversity of the cybersecurity-related policies impacting the Union’s cyber posture
- Increasing ICT supply chain security risks
Relevant to:
- ENISA, national cybersecurity certification authorities, suppliers of ICT products, services and processes, electronic communications network operators, and NIS2-regulated entities across critical sectors
Status: Proposal, submitted on 20 January 2026. The European Commission published proposals on 20 January 2026 to revise the Cybersecurity Act (CSA 2) and introduce targeted amendments to the NIS 2 Directive.
Next steps: Negotiations between the European Parliament and the Council are underway.
Hannes Snellman blog posts:
(Last updated 24 August 2026)
Implemented in Finland as:
Status: In force
National cybersecurity certification authority:The Finnish Transport and Communications Agency (Traficom)
The revised Cybersecurity Act (2026):
Status:The Finnish Government submitted a U-letter on the proposals to Parliament on 12 March 2026 (U 17/2026 vp).
Next steps: At EU level, negotiations between the European Parliament and the Council are ongoing. In Finland, the legislative preparations are being coordinated by the Ministry of Transport and Communications.
(Last updated 31 July 2026)
