What the EU's new cyber security package means for business?
Cyber attacks have taken on an entirely new scale in recent years. Increasingly, they are backed by state actors, and their targets are critical infrastructure and key institutions across Europe. The voluntary measures that the EU introduced with its original Cybersecurity Act in 2019 are no longer enough. That is why Brussels has put together a comprehensive set of new rules, combining an updated Cybersecurity Act (CSA 2) with amendments to the NIS2 Directive. Under this package, business resilience against cyber attacks becomes mandatory rather than optional. At the same time, for the first time, the geopolitical landscape becomes a direct factor in technical security decisions.
Geopolitics enters the law
One of the most significant changes is a three-step process for assessing risks within the ICT supply chain. For the first time, security assessments include so-called "non-technical risk factors." In practice, this means that laws of third countries are also examined, where they could compel a supplier to hand over sensitive data or build backdoors into their systems.
The process works on three levels. First, countries with a high risk of foreign interference are identified. Then, specific suppliers from those countries are designated. Finally, key ICT assets such as core network functions and radio access networks that require protection are singled out. The greatest impact is expected in the telecommunications sector.
Clear prohibitions are introduced for high-risk suppliers. They will not be allowed to participate in the deployment of core network functions across mobile, fixed-line, and satellite infrastructure. They will also be barred from public procurement involving key ICT assets. In addition, they are prohibited from carrying out conformity assessments, which effectively means they cannot audit or certify the security of other companies.
Relief for smaller companies
The new package introduces a "small mid-cap" category, bridging the gap between small and medium-sized enterprises (SMEs) and large corporations. This change affects around 28,700 companies. Approximately 22,500 of them are now classified as "important" rather than "essential," which means less oversight and simpler compliance requirements. Whether this will genuinely ease the burden in practice remains to be seen.
In addition, around 6,200 micro and small enterprises, including small DNS providers, are now exempt from regulation. The aim is to place the main burden on large operators of critical infrastructure while allowing smaller companies to grow without excessive red tape.
Faster certification with real impact
The European Cybersecurity Certification Framework (ECCF) has suffered from a slow pace of progress. The EUCC scheme, for example, took 57 months from initiation to adoption. CSA 2 addresses this by setting a default 12-month deadline for ENISA to develop new certification schemes.
A new type of certificate for "cyber posture" is also introduced. Holding such a certificate acts as a protective mechanism. Competent authorities may not impose additional measures such as audits or enhanced supervision for requirements already covered by a valid certificate. A single certificate can satisfy regulators and business partners across the entire EU, significantly reducing costs.
Mandatory reporting of ransom payments
Ransomware remains a primary weapon of cyber criminals. The new package introduces harmonised data collection aimed at reducing the financial incentives for attackers. When an entity makes a ransom payment and receives an inquiry from a competent authority, it is required to provide a detailed report. The goal is greater transparency and a clearer picture of the scale of the problem.
Preparing for the quantum era
One of the most important aspects of the new legislation concerns the "harvest now, decrypt later" threat. It is already established that malicious actors are collecting encrypted data with the intention of decrypting it once quantum computers become powerful enough.
The amendment to the NIS2 Directive requires Member States to include policies for transitioning to post-quantum cryptography (PQC) in their national cybersecurity strategies. For lawyers and company executives, this sets a new standard of due diligence.
The legislation lays down clear deadlines. By 2030, critical applications must migrate to post-quantum cryptography. By 2035, the same is expected for medium and low-risk applications. Failure to meet these deadlines could lead to serious negligence claims, as current encryption standards will become obsolete.
The price of digital sovereignty
CSA 2 transforms ENISA from an advisory agency into an operational centre with real authority. The agency will coordinate joint inspection teams and provide mutual assistance. Its budget increases by 80 percent and its staff grows by 100, bringing the total to 230 full-time positions.
The EU expects the simplified rules to deliver around EUR 15.3 billion in long-term compliance savings. At the same time, the cost of removing high-risk suppliers from mobile networks is estimated at EUR 3 to 4 billion per year over five years. This poses a serious challenge for telecom operators and infrastructure providers. Every company will need to weigh whether these changes represent an opportunity or a threat to their business.

