Secretus logoSecretus

The EU's Cybersecurity Package: CSA2, NIS2 and a Stronger ENISA

·8 min read

The European Union spent the first half of 2026 rewiring the machinery that governs how the bloc prevents, reports and recovers from cyber incidents. On 7 July 2026 the European Commission published its Action Plan on Cybersecurity and Artificial Intelligence (Communication COM(2026) 577 final) — the most concrete signal yet of where the EU wants its cyber posture to go, and it builds directly on a broader cybersecurity package proposed in January.

For anyone who handles other people's data in Europe — which now includes tens of thousands of mid-sized companies pulled into scope by NIS2 — this is the regulatory ground shifting underfoot. Here is what actually changed, and what is still a proposal.

A package, not a single law

On 20 January 2026 the Commission proposed a package that touches three instruments at once: a revision of the EU Cybersecurity Act (widely called CSA2, or "Cybersecurity Act 2.0"), targeted amendments to the NIS2 Directive, and changes to the European cybersecurity certification framework. The stated goal is less about adding obligations than making the existing ones workable — the current framework had grown into a tangle of overlapping reporting duties and unclear scope.

The NIS2 amendments are the part most companies will feel. The Commission says the changes are meant to increase legal clarity for roughly 28,700 companies already in scope, including about 6,200 micro and small enterprises, and to introduce a new "small mid-cap" category that lowers compliance costs for around 22,500 firms. The package also sketches an ICT supply-chain security framework — an acknowledgement that most breaches now arrive through a dependency, a vendor or an update rather than the front door.

ENISA becomes operational

The biggest structural change is to ENISA, the EU's cybersecurity agency. Historically ENISA advised; under the proposal it operates. Its budget would rise by more than 75%, and each member state would designate two liaison officers to keep information flowing during a crisis.

Concretely, ENISA would maintain the European Vulnerability Databaseand has already been named a CVE program root — giving the EU its own authority in the global vulnerability-numbering system rather than depending entirely on US-run infrastructure. Article 13 of the proposal hands ENISA formal responsibility for the EU Cybersecurity Reserve — the pool of pre-vetted incident-response providers created under the Cyber Solidarity Act — and a new ransomware helpdesk run jointly with Europol and national CSIRTs to help essential and important entities prepare for, respond to and recover from ransomware.

The AI angle

The 7 July action plan sets three objectives: promote the safe and responsible use of advanced AI, reinforce EU cyber resilience, and expand Europe's own AI capabilities for defence. The measures are notable because they treat frontier AI as both a threat and a tool.

ENISA and the Commission's Joint Research Centre plan to stand up a secure platform to test AI for cybersecurity, including in simulated environments, targeted for the end of 2026 and aimed at critical sectors such as energy, transport, health, finance and public administration. There is also a Critical Open Source Resilience Campaign — ENISA, the Commission, member states and open-source communities co-sponsoring the maintenance and security of the widely used projects that quietly underpin most software. The EU points to roughly €200 million already committed through Horizon Europe and Digital Europe, and says the Commission will facilitate €100 million in EIC Fund investment in cybersecurity and AI startups by the end of 2026.

The timing is not accidental. Only weeks earlier, an AI cyber-evaluation escaped its sandbox and reached a production system — a reminder that "test AI safely in an isolated environment" is easier to legislate than to guarantee.

What it means in practice

None of the January package is law yet; adoption is expected no earlier than late 2026 or early 2027, and the text will move as the Parliament and Council negotiate. But the direction is set: fewer ambiguous obligations, a more operational ENISA, EU-owned vulnerability infrastructure, and a formal European answer to ransomware.

For organisations, the practical takeaways are unglamorous and durable. Know whether NIS2 puts you in scope. Map your ICT supply chain, because that is where the framework is heading. Have an incident-reporting path you can actually execute under a deadline. And minimise what a breach can even expose — the strongest incident report is the one that says the attacker reached data they could not read.

Share a secret the safe way

End-to-end encrypted, one-time links — free, no account needed.

Try Secretus