Cybersecurity Act review: AmCham EU calls for greater industry engagement and evidence-based certification criteria
News
21 Jan 2026
Digital

The European Commission’s proposal to revise the Cybersecurity Act (CSA2) comes at the right moment, as Europe faces an evolving range of cyber threats. With its measures to reinforce ENISA and make harmonisation the key to a more resilient Single Market, the proposal brings the Act closer to the realities of today’s fast-moving cybersecurity ecosystem. 

However, the Commission’s proposal still fails to go far enough on providing a platform for more active industry engagement. It rightly formalises existing structures but falls short of creating mechanisms that allow for regular expert-level exchanges and meaningful industry feedback into the CSA2 framework, building on lessons learned from the past years. Such exchanges are essential, given industry’s role as a front-line defender against cyber threats. 

Now, as the file moves to the European Parliament and the Council of the EU, the co-legislators must ensure certification schemes under the CSA2 remain based on technical criteria. The EU’s cybersecurity needs should be a matter for sober, technical analysis. AmCham EU therefore supports the proposal's structural distinction between technical certification and non-technical supply chain risks. Maintaining this separation prevents restrictive requirements that limit choice, reduce competition and slow innovation. 

The same approach is necessary for the proposal’s provisions to secure critical infrastructure under the new ‘Trusted ICT Supply Chain Framework’ (Title IV). These measures must also be underpinned by an objective, evidence-based approach to ‘non-technical risks’. At the same time, measures involving restrictions on data transfers must be aligned with international agreements to avoid unintended disruptions to global operations. 

Ultimately, US companies share the EU’s commitment to securing the region’s digital resilience. AmCham EU members invest heavily in security and stand ready to support the delivery of a framework that keeps Europe open, secure and competitive. 

Related items

News
13 Mar 2026

Discussing digital policy priorities with MEPs in Strasbourg

From Monday, 9 to Wednesday, 11 March 2026, AmCham EU travelled to the European Parliament in Strasbourg for a series of meetings with policymakers to discuss ongoing EU digital policy initiatives. The delegation met with  members of the European Parliament, accredited parliamentary assistants and group policy advisers , to discuss priorities for the EU’s digital agenda. This includes exchanges on AI Omnibus, Digital Omnibus, Cybersecurity Act review, the Digital Networks Act and the upcoming Cloud and AI Development Act. Throughout the meetings, members emphasised the importance of urgent action to support the simplification of overlapping digital rules, strengthening cybersecurity while avoiding fragmentation in the Single Market and supporting innovation through proportionate, risk-based regulation.

Digital
Read more
Read more about Discussing digital policy priorities with MEPs in Strasbourg
Position Paper
11 Mar 2026

Advancing EU data and cybersecurity rules through the Digital Omnibus

Digital
Simplification
Read more
Read more about Advancing EU data and cybersecurity rules through the Digital Omnibus
Position Paper
11 Mar 2026

Supporting artificial intelligence uptake through the AI Omnibus

Digital
Simplification
Read more
Read more about Supporting artificial intelligence uptake through the AI Omnibus