Position papers & reports
27 July 2026
Cybersecurity Act II – a BusinessEurope position paper
Documents
EU single marketDigital economy
Key messages
- A unified EU approach to trusted ICT supply chains is preferable to 27 divergent national regimes that would fragment the Single Market. However, harmonisation must not come at the expense of legal and investment certainty for businesses. The framework needs stronger safeguards against legal and operational divergence to ensure consistent application and predictable conditions for cross-border business.
- The effectiveness of the ICT framework hinges on legally robust design, particularly around the Commission’s implementing powers and the delegation of politically sensitive decisions. High-impact designation and restriction powers must be clearly grounded in Treaty-compatible legal bases, with safeguards ensuring compliance with Articles 290 and 291 TFEU to avoid legal and business uncertainty and legal challenges.
- Mandatory phase-outs or forced replacement of ICT components can have far-reaching implications for industry, investment, business continuity, compliance costs and competitiveness. Such restrictions should only be used as a measure of last resort following a comprehensive, sector-specific risk and impact assessments, demonstrating that the benefits outweigh their economic and societal costs. Where such restrictive measures are adopted, a structured EU-level compensation mechanism must also be put in place, but compensation availability shall not be at the expense of robust and clear regulation.
- Entities to be designated as high-risk, as well as EU critical infrastructure entities and integrating companies, must be meaningfully involved before decisions are taken.
- Certification should remain voluntary to support innovation and SMEs and operate alongside standards and other conformity routes rather than as the sole compliance pathway. Industry should have an institutionalised role for regular input in certification development process.
- ENISA’s mandate should be measurable, and impact driven. Clear KPIs are needed to assess performance, including scheme uptake, operational effectiveness, and real-world improvements in EU cybersecurity posture.
- The proposal as a whole must strengthen Europe’s global competitiveness, avoid isolation from international standards, and ensure proportionate rules that do not undermine investment, trade, or cross-border operations.
- The revised Cybersecurity Act (CSA2) should deliver meaningful burden reduction. New obligations under CSA2 must be assessed in light of existing requirements under NIS2 Directive, Digital Operational Resilience Act, Cyber Resilience Act, Critical Entities Resilience Directive, and other cybersecurity legislation to avoid duplication, legal uncertainty and unnecessary compliance costs.