Find a lawyerOur capabilitiesYour career
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Technology Quotient
  4. Cybersecurity Act 2.0: the EU’s new framework for ICT supply chains
6MIN

Cybersecurity Act 2.0: the EU’s new framework for ICT supply chains

Sep 4 2026

Cybersecurity Act 2.0: the EU’s new framework for ICT supply chains

The European Commission’s draft Cybersecurity Act 2.0 (CSA2), published on 20 January 2026, introduces a new “Trusted ICT Supply Chain Framework”, which would give the European Commission far-reaching powers to restrict the use of information and communications technology (ICT) components from so-called “high-risk suppliers” across sectors regulated by the NIS2 Directive. 

Addressing non-technical supply chain risks

Existing rules on cybersecurity such as NIS2, the Cyber Resilience Act and the EU cybersecurity certification framework are principally concerned with technical vulnerabilities. The Trusted ICT Supply Chain Framework instead targets non-technical risks, namely concerns that suppliers may be exposed to influence from third countries in ways that could undermine the security or resilience of ICT supply chains, including through service disruption, concealed vulnerabilities or unauthorised access to data.

The European Commission’s stated concern is that dependence on suppliers linked to countries capable of exerting such influence leaves critical ICT supply chains structurally exposed. This concern sits within a broader EU policy shift towards reducing strategic dependencies, a priority underlined, among others, by Mario Draghi’s 2024 report on European competitiveness and echoed across the European Commission’s recent security and economic security strategies. The same policy direction is reflected in the proposed Cloud and AI Development Act, which addresses European dependency concerns in cloud and AI infrastructure. 

How the mechanism works

In essence, the framework allows the European Commission to move from a general assessment of supply-chain risks to legally binding restrictions on specific suppliers or technologies.

The process consists of five main steps:

Step one: a coordinated risk assessment. The European Commission, or a group of at least three Member States, can ask the NIS Cooperation Group – an EU forum bringing together national cybersecurity authorities, the European Commission and ENISA – to assess a specific ICT supply chain, identifying key threat actors, vulnerabilities and mitigation options. Risk assessments by the NIS Cooperation Group that have already been carried out or which are under way indicate where the European Commission’s initial focus may lie: 5G networks, detection equipment and connected and automated vehicles. The draft CSA2 itself offers further indications, referring to a broad range of sectors as areas of particular concern, including detection equipment, electricity supply systems and electricity storage, water supply systems, drones and counter-drone systems, cloud computing services, medical devices, surveillance equipment, space services and semiconductors.

Step two: designating third countries of concern. The European Commission can designate a third country as posing “serious and structural non-technical risks” to ICT supply chains. Ongoing policy debate suggests that China will be amongst the first countries designated. Once a country is designated, entities established there or controlled from there automatically qualify as “high-risk suppliers” under CSA2. 

This step is among the most contested elements of the proposal. Several Member States are reportedly concerned that it risks shifting the assessment away from technical cybersecurity risk towards broader geopolitical considerations, since entities linked to a designated country become high-risk suppliers automatically, by virtue of their location or ownership alone, without any individual assessment of the entity itself, with limited grounds for exemptions, as set out below. 

Step three: identifying key ICT assets. The European Commission then identifies, by means of an implementing act, the specific “key ICT assets” within a sector that warrant protection. Relevant factors include whether the ICT asset performs an essential and sensitive function, whether an incident could cause serious supply-chain disruption or data exfiltration, and whether there is a dependency on a limited number of suppliers.

Step four: listing high-risk suppliers. Separately, the European Commission maps and assesses suppliers in a relevant sector, based on their place of establishment, ownership and control. Following that mapping, the European Commission publishes a list of high-risk suppliers relevant to the intended sector-specific restrictions on the use of ICT components.

Step five: restriction and mitigating measures. Once these elements are in place, the European Commission can, again by means of an implementing act, prohibit entities that are regulated under the NIS2 Directive from using, installing or integrating ICT components from listed high-risk suppliers in key ICT assets, subject to a transition period. Where a full prohibition would be disproportionate, the European Commission can instead impose targeted mitigation measures, such as supply-chain transparency duties or technical safeguards. Exemptions from the restrictions applicable to suppliers from designated third countries are available only on a narrow basis under the CSA2. The supplier must submit a reasoned request evidencing that effective mitigating measures will be put in place to address the relevant non-technical risks, with the assessment and decision resting with the European Commission.

The emergency procedure

The draft also foresees an emergency prohibition that would bypass most of the above process. If the European Commission has “sufficient reason” to consider that components from a specific supplier pose a significant risk to the economic or societal activities of at least three Member States, it can – after consulting Member States and hearing the supplier – impose a prohibition directly by means of an implementing act, without first designating a country, identifying key assets or listing the supplier through the ordinary process.

The emergency arrangements have also raised concerns, as the European Commission may launch a fast-track risk assessment where it has “sufficient reason to believe” that a significant cyber threat exists, without awaiting the ordinary coordinated assessment by the NIS Cooperation Group. Several Several Member States consider this threshold too vague and are seeking clearer criteria, stronger governance arrangements and closer Member State involvement.

Where the legislative process stands

As of September 2026, CSA2 remains at an early stage of the EU’s ordinary legislative procedure. The Council has begun its technical examination of the proposal, with Member States seeking further clarity on the methodology and procedures for identifying key ICT assets and high-risk suppliers, the scope and potential impact of the proposed measures, governance and the use of implementing acts. More broadly, Member States have called for greater involvement in politically sensitive decisions, more objective and evidence-based risk assessments, proportionate measures and clearer definitions of key concepts. In the European Parliament, the file has been assigned to the Committee on Industry, Research and Energy (ITRE), with Markéta Gregorová appointed as rapporteur. The Parliament is expected to begin its internal work in the fourth quarter of 2026, potentially allowing negotiations between the Parliament and the Council to start in early 2027. The proposal may therefore still change materially as the legislative process progresses.

What this means in practice

If adopted in its current form, CSA2 would significantly expand the EU’s toolkit for addressing ICT supply-chain risks. Unlike existing cybersecurity legislation, the framework would permit restrictions based not only on technical security concerns but also on broader dependency, resilience and economic-security considerations. The implications are therefore likely to extend beyond cybersecurity compliance and into procurement, vendor-management and supply-chain strategy.

Businesses with exposure to suppliers from third countries, particularly in sectors already identified as areas of concern or subject to coordinated risk assessments, may wish to assess their supply-chain dependencies now and consider engaging in the legislative process while the proposal remains under negotiation. For many organisations, that exercise may be more complex than it first appears. The proposal allows restrictions to apply not only to direct suppliers but also to products that contain ICT components sourced from high-risk suppliers. A prohibited component may therefore sit several tiers down a supply chain, embedded within a product sourced from an otherwise unproblematic vendor.

As a result, organisations may increasingly require visibility beyond their immediate contractual counterparties and into lower tiers of their supply chains. This may prove particularly challenging in sectors characterised by complex manufacturing chains and a limited pool of alternative suppliers for critical components.

Tags

regulatory frameworkeu digital strategydata cybersecurity and tech regulationdigital infrastructuretechnology

Authors

Düsseldorf

Christoph Werkmeister

Global Co-Head of Data & Technology
Düsseldorf

Elena Brandt

Partner
Berlin

Max Grewe

Principal Associate
San Francisco

Vera Ibes

Principal Associate
Berlin

Dr. Leonie Wittershagen

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome