Cybersecurity Act review: AmCham EU calls for greater industry engagement and evidence-based certification criteria
News
21 Jan 2026
Digital

The European Commission’s proposal to revise the Cybersecurity Act (CSA2) comes at the right moment, as Europe faces an evolving range of cyber threats. With its measures to reinforce ENISA and make harmonisation the key to a more resilient Single Market, the proposal brings the Act closer to the realities of today’s fast-moving cybersecurity ecosystem. 

However, the Commission’s proposal still fails to go far enough on providing a platform for more active industry engagement. It rightly formalises existing structures but falls short of creating mechanisms that allow for regular expert-level exchanges and meaningful industry feedback into the CSA2 framework, building on lessons learned from the past years. Such exchanges are essential, given industry’s role as a front-line defender against cyber threats. 

Now, as the file moves to the European Parliament and the Council of the EU, the co-legislators must ensure certification schemes under the CSA2 remain based on technical criteria. The EU’s cybersecurity needs should be a matter for sober, technical analysis. AmCham EU therefore supports the proposal's structural distinction between technical certification and non-technical supply chain risks. Maintaining this separation prevents restrictive requirements that limit choice, reduce competition and slow innovation. 

The same approach is necessary for the proposal’s provisions to secure critical infrastructure under the new ‘Trusted ICT Supply Chain Framework’ (Title IV). These measures must also be underpinned by an objective, evidence-based approach to ‘non-technical risks’. At the same time, measures involving restrictions on data transfers must be aligned with international agreements to avoid unintended disruptions to global operations. 

Ultimately, US companies share the EU’s commitment to securing the region’s digital resilience. AmCham EU members invest heavily in security and stand ready to support the delivery of a framework that keeps Europe open, secure and competitive. 

Related items

News
21 May 2026

A year of giving back

Intel has called Ireland home since 1989, investing more than €30 billion and supporting 4,900 jobs. Alongside this long-term commitment, the company is helping strengthen local communities through its Signature Charity initiative. For the past 16 years, the Intel Foundation and Intel employees have selected a charity each year to support through volunteering and fundraising. In 2025, Intel Ireland chose Teach Tearmainn, the only organisation in County Kildare dedicated to supporting women and children experiencing domestic violence and abuse. Through fun runs, cycling events, a triathlon, a giving campaign, employee-led fundraising and recycling initiatives, Intel employees raised €80,000 for the charity – the company’s largest charity donation to date. These efforts show how long-term investment, employee engagement and community partnerships can help deliver meaningful support where it is needed most. Read the full story on Invested in Europe.

Social impact, inclusion and skills
Digital
Read more
Read more about A year of giving back
Position Paper
13 May 2026

Strengthening Europe’s cybersecurity framework through simplification

The review of the Cybersecurity Act (CSA 2.0) is an opportunity to build a more coherent, outcome-oriented EU cybersecurity framework. While the proposal recognises fragmentation across the Single Market, further simplification is needed to reduce overlaps and support effective compliance.

A harmonised approach to risk assessment and supervision can strengthen resilience while avoiding duplicative obligations. Certification and supply-chain measures should remain risk-based, objective, technical and aligned with international standards. Structured industry engagement and clear designation thresholds under the ICT Supply Chain Framework and a secure-by-design approach to policymaking will be essential to support cybersecurity and global interoperability. Read more on how CSA 2.0 can strengthen resilience across the Single Market.

Digital
Read more
Read more about Strengthening Europe’s cybersecurity framework through simplification
Close-up of a laptop keyboard with blue backlighting, highlighting the shift key and adjacent keys in a soft-focus perspective.
News
13 Apr 2026

Industry calls for ambitious and simplified implementation of the AI Act 

Together with 14 other associations, AmCham EU has signed a joint statement on the European Commission’s Digital Omnibus on AI, calling for a clear, simple and innovation-friendly implementation of the AI Act. Co-legislators should swiftly reach an agreement on an ambitious final text that keeps simplification at its core. Measures to streamline overlaps with existing EU legislation and improve legal certainty are essential, alongside targeted adjustments to ensure the framework remains practical. This includes extending grace periods for generative AI labelling requirements, ensuring greater legal clarity for AI systems entering the EU market, preserving the risk-based approach of the AI Act by exempting non high-risk systems from registration, and supporting fixed compliance deadlines for high-risk systems.

Learn how the EU can support a clear and innovation friendly framework in the joint statement.

Digital
Read more
Read more about Industry calls for ambitious and simplified implementation of the AI Act