CSA 2.0: Cybersecurity & Sovereignty

Cybersecurity, Certification and Sovereignty: The Challenges of CSA 2.0


Related topics

Since the Cybersecurity Act entered into force in 2019, the European Union has faced a rapidly evolving cyber threat landscape, marked by increasingly frequent, sophisticated and systemic attacks.

Technological developments, including artificial intelligence and quantum computing, have further exposed structural vulnerabilities in Europe's digital ecosystem. The proposed revision of the Cybersecurity Act ("CSA 2.0") seeks to respond to these challenges by modernising the existing framework, strengthening governance, overhauling certification mechanisms, addressing supply chain risks and reducing regulatory fragmentation. CSA 2.0 represents a significant step forward in building a more coherent European cybersecurity architecture. At the same time, the proposal warrants a structured debate — not only on whether it effectively addresses cybersecurity challenges, but also whether it is adequately aligned with market realities, business capabilities, and the constitutional boundaries between EU and Member State competences.





I. Introduction to CSA 2.0 regulatory framework

CSA 2.0 delineates the mandate, objectives, functions, and organisational arrangements of the European Union Agency for Cybersecurity (ENISA). It further establishes a Union‑level framework for European cybersecurity certification schemes applicable to ICT products, services, processes, managed security services, and the cybersecurity posture of entities, with the dual objective of ensuring a high level of cybersecurity and mitigating regulatory fragmentation within the internal market.

Among its most significant innovations, CSA 2.0 introduces a trusted ICT supply chain framework for entities covered by Directive (EU) 2022/2555 ("NIS2") operating within the Union. This framework is designed to address both technical vulnerabilities and non‑technical risks — including geopolitical, governance, and third‑country supplier risks — that cannot be adequately managed through purely technical standards alone. In doing so, CSA 2.0 acknowledges that cybersecurity in modern critical infrastructure is not solely a matter of code or hardware, but also of trust, ownership structures, and the legal environments in which suppliers operate.

At the same time, the legal basis of CSA 2.0 raises legitimate questions. The proposal formally relies on Article 114 TFEU, yet provisions empowering the Commission to assess "non‑technical risks" associated with third‑country suppliers risk encroaching upon Article 4(2) TEU, which reserves national security to the exclusive responsibility of Member States. Determining whether a third country poses a "serious and structural" cybersecurity risk may, in practice, require evaluations of political systems, governance models and legal environments — considerations that extend beyond technical market regulation. As Michele Petite observed, "relying on Article 114 because it underpinned CSA 1 appears unconvincing, given that the new provisions venture into fundamentally different territory." These concerns, while legitimate, should be viewed in the context of an ongoing legislative process that offers opportunities for refinement rather than grounds for wholesale rejection of the framework's objectives.

II. Certification system in CSA 2.0

CSA 2.0 fundamentally reshapes the EU cybersecurity certification system. Its most notable extension is the inclusion of the cyber posture of entities and organisational risk‑management frameworks within the scope of certifiable requirements — a recognition that resilience must be assessed at the systemic level, not only at the level of individual products. The consolidation of governance at EU level, with ENISA playing a strengthened role in developing and overseeing certification schemes, aims to reduce regulatory fragmentation and build durable trust in the Digital Single Market.

Proponents of a centralised certification model argue that harmonisation eliminates the risk of a "race to the bottom" among Member States, provides businesses with a single, predictable compliance pathway, and creates economies of scale in certification infrastructure. This is particularly important as EU cybersecurity certification expands beyond products to cover services, processes and organisational security posture. A common framework also facilitates mutual recognition of certified solutions across borders, reducing duplication and enabling the Digital Single Market to function more effectively.

This centralised approach is already visible in practice through EU‑level cybersecurity certification schemes, most notably the EU cybersecurity certification scheme (EUCC). EUCC is one of the first concrete implementations of the Cybersecurity Act and serves as a key reference point for how certification may evolve under CSA 2.0, illustrating a model anchored in harmonised, technically defined assessment criteria.

EUCC provides a single, harmonised certification framework for ICT products across the EU, based on a common set of technical security requirements and evaluation methodologies derived from the Common Criteria standard.

Instead of navigating multiple national schemes with different scopes, assurance levels and interpretations, a vendor can have a product certified once under EUCC, with the resulting certificate recognised by all Member States. Certification is carried out by accredited conformity assessment bodies, under a common set of EU‑wide rules and oversight.

A defining feature of EUCC is its risk‑based assurance level structure, which allows certification efforts to be proportionate to the product’s criticality and threat exposure. Lower‑risk products can be assessed with lighter requirements, while products used in sensitive or high‑risk contexts can be certified against more stringent assurance levels.

This ensures that the scheme remains scalable for industry while maintaining technical credibility for regulators and customers alike.

In this way, EUCC illustrates how a centralised EU‑level scheme, based on clearly defined and technically oriented security criteria, can reduce fragmentation, enhance trust in certified solutions, and provide a practical and repeatable model for future EU cybersecurity certification schemes.

Nevertheless, there are strong arguments — practical, constitutional and empirical — in favour of preserving a significant role for national certification systems, particularly where national security is at stake.

First, many Member States already operate mature and well-regarded national cybersecurity certification frameworks. Germany's BSI (Bundesamt für Sicherheit in der Informationstechnik) is one of the most technically sophisticated and internationally respected cybersecurity authorities in the world. Its certification schemes — including the BSI IT-Grundschutz methodology and product-specific evaluations — have been developed and refined over decades, enjoy broad industry trust, and are closely integrated with German critical infrastructure protection. France's ANSSI (Agence nationale de la sécurité des systèmes d'information) similarly operates a well-established national certification regime, including its own Common Criteria-based evaluation process and sector-specific certifications for sensitive systems. These are functioning systems with established methodologies, trained personnel, accredited laboratories, and industry familiarity — assets that cannot easily or quickly be replicated at EU level.

Second, the Netherlands, Sweden and Finland have each developed national frameworks that reflect their specific threat perceptions, industrial structures and constitutional arrangements. Sweden's NCSA (National Cybersecurity Authority) and Finland's Traficom have both emphasised the importance of retaining national decision-making authority over which vendors are considered acceptable for use in critical infrastructure — a position grounded not only in practical expertise but in constitutional principle.

Third, and most fundamentally, matters of national security are constitutionally reserved to Member States under Article 4(2) TEU. The determination of which ICT suppliers pose an unacceptable risk to critical national infrastructure is, in substance if not always in form, a national security judgment. Countries such as Sweden, Germany and the Netherlands have publicly emphasized that assessments of ICT supplier risks are closely linked to national security and are therefore to be carried out by Member States within their own national competence.

This is not merely a political preference — it reflects the constitutional reality that Member States are accountable to their own citizens for protecting national security, and that this accountability cannot be meaningfully exercised if the relevant decisions are taken in Brussels.

This does not mean that EU-level coordination has no role to play. On the contrary, information-sharing between Member States, common minimum standards, and mutual recognition of national certifications all have clear value. The question is whether the CSA 2.0 model — which concentrates significant decision-making authority at the Commission level — strikes the right balance, or whether a model that preserves national primacy in security-related certification decisions while enabling voluntary harmonisation would better serve both security and constitutional requirements. A framework in which national authorities retain the primary role in sensitive security assessments, with EU-level coordination supporting rather than supplanting them, may ultimately prove more durable, more legitimate, and more effective.

III. Challenges and problems related to certification – identification and discussion

The proposed revision of the EU Cybersecurity Act has prompted critical concerns from experts and stakeholders. These centre on five areas: (i) potential politicisation of the certification process, (ii) discriminatory impacts on non-EU suppliers, (iii) implementation burdens for companies, (iv) insufficient transparency and weaknesses in risk‑assessment methodologies, and (v) uncertainty about legal remedies against EU decisions.

IV. Identification of areas for further clarification

Two areas require targeted clarification as the legislative process advances.

EU-level governance vs. Member State competences: This is the most structurally significant question raised by CSA 2.0. Granting the Commission authority to designate "high-risk" suppliers shifts core national security decisions to EU level, despite the treaty reservation of national security to Member States. Germany, Sweden and the Netherlands have all publicly insisted such determinations must remain a national responsibility. The pending Elisa Eesti AS case before the Court of Justice is expected to clarify the boundary between internal-market regulation and national security — with significant implications for the CSA 2.0 governance model. A framework preserving national primacy in security-sensitive decisions, with EU-level coordination supporting rather than supplanting it, may prove more legally and politically sustainable.

Judicial and administrative remedies: Much of the evidence underpinning "high-risk" designations may derive from classified intelligence, leaving affected companies with limited ability to understand or contest decisions. Periodic review of designations, clear procedures for suppliers to be heard, and accessible avenues for appeal are necessary both as rule-of-law requirements and as confidence-building measures for industry and trading partners alike.



Conclusion

CSA 2.0 is a significant and broadly welcome regulatory initiative. It addresses genuine and pressing security needs, responds to a threat landscape that the first-generation Cybersecurity Act was not designed to handle, and lays the groundwork for a more coherent European cybersecurity architecture. Its ambitions — harmonised certification, stronger supply-chain governance and elevated security standards across critical sectors — are well-founded and strategically necessary.

At the same time, the framework must be closely calibrated to market realities and constitutional boundaries. The centralisation of certification decision-making at EU level is not self-evidently superior to well-functioning national systems — and in areas touching directly on national security, there are strong legal, empirical and democratic reasons to preserve national primacy.

Ultimately, the legitimacy and effectiveness of CSA 2.0 will depend on transparent and auditable risk-assessment methodologies; on a governance model that respects the constitutional boundaries between EU and Member State competences; on realistic transitional arrangements; and on effective remedies for affected parties. Designed well, CSA 2.0 can strengthen European cybersecurity without becoming a structural market barrier or a source of legal and constitutional tension. Achieving that outcome will require the legislative process to engage seriously and openly with the concerns raised by industry, legal experts and Member States.

The article is co-authored by Karol Barasiński.


Contact us

About this article

Our Latest Thinking