EU Parliament Amended Cybersecurity Act 2 Proposals

Proposed changes aim to shift from country-of-origin bans to individual supplier assessments for key infrastructure.

Updated on Sept. 28, 2026 in Cybersecurity

EU Parliament Amended Cybersecurity Act 2 Proposals

Live Poll

Should government cybersecurity rules restrict specific companies rather than imposing broad bans on foreign countries?

The European Parliament Committee on Industry, Research and Energy has drafted amendments to the proposed Cybersecurity Act 2, which aims to update 2019 cybersecurity standards. The current proposal, which is not yet in force, seeks to modify Articles 100 to 104 regarding the evaluation of suppliers.

Why it matters

The legislation aims to strengthen digital supply chain security across the European Union by setting new criteria for critical information and communications technology assets. The shift to individual supplier evaluation would represent a move away from the blanket funding restrictions on specific nations previously enacted by the Commission.

The proposed amendments to the Cybersecurity Act 2 seek to replace broad geographic exclusions with individual vendor assessments for components. This approach targets key ICT assets, which are critical infrastructure components that manage digital data and network operations.

The players

European Parliament Committee on Industry, Research and Energy

The parliamentary body responsible for shaping energy and industrial digital policy within the European Union.

European Commission

The executive branch of the European Union responsible for proposing new legislation and managing the bloc's budget and trade policy.

Chinese Ministry of Commerce

The government department overseeing China's trade relations and economic policy, which has challenged EU-led funding restrictions.

The details

The Cybersecurity Act 2, first proposed by the European Commission in January 2026, intends to establish a framework for securing digital supply chains. Amendment 28 specifically suggests evaluating solar inverter suppliers on an individual basis rather than by their country of origin. This change follows April 2026 restrictions that limited funding for projects utilizing hardware from China, Russia, Iran, and North Korea, a policy previously criticized by the Chinese Ministry of Commerce.

Timeline

  1. 2019: Original cybersecurity rules were established.

  2. January 2026: European Commission proposed the Cybersecurity Act 2.

  3. April 2026: Commission restricted funding for projects using specific country inverters.

The Tech Race

The proposed Cybersecurity Act 2 serves as a strategic update to the 2019 EU Cybersecurity Act to manage global hardware dependencies. This development follows the broader trend of nations establishing regulatory frameworks to gatekeep foreign-manufactured technology from critical infrastructure.

If passed, the legislation will create new compliance requirements for operators of critical ICT infrastructure in the European Union. Implementation remains subject to future approval by the European Parliament and the European Council.

The takeaway

The move toward individual supplier vetting signals a more granular approach to digital sovereignty that will require ongoing monitoring of trilogue negotiations. Stakeholders should track the forthcoming position of the European Council to determine how these criteria will be finalized.

Further reading

For broader context on how the EU manages emerging technical risks, see the Cybersecurity section.

Live Poll

Should government cybersecurity rules restrict specific companies rather than imposing broad bans on foreign countries?

EU Parliament Amended Cybersecurity Act 2 Proposals | Highwise Tech