×

CENTR publishes a comment on the EU Cybersecurity Act 2

News 15-06-2026

CENTR has published a comment on the proposal for the revised EU Cybersecurity Act 2 (CSA2), which was put forward by the European Commission in January 2026. The proposal aims to strengthen the EU's cybersecurity governance and introduces a new "trusted ICT supply chain framework" that would apply to essential and important entities under the NIS 2 Directive, including ccTLD registries.

CENTR members welcome the ambition behind the proposal to strengthen the EU’s cybersecurity governance and its reconfirmation of ENISA's mandate to support essential infrastructure. However, they raise a series of concerns about provisions that could impose disproportionate obligations on European ccTLDs and the broader internet infrastructure ecosystem.

In the context of the trusted ICT supply chain framework, CENTR members would like to stress that:

  • EU policymakers must refrain from duplicating obligations or imposing unnecessary additional burdens on ccTLDs in the area of cybersecurity.
  • Any risk assessments that prohibit high-risk suppliers must be based on tangible, evidence-based security risks, grounded in a clear framework that considers the nature of critical infrastructure and sector-specific security concerns.
  • A well-informed impact assessment must precede any binding decision to exclude key suppliers, and affected essential entities must be able to object and meaningfully participate in derogation procedures.
  • An adequate transitional phase-out period must be provided to all affected entities, with financial compensation available where viable alternatives are absent.
  • The ICT supply chain definition must be revised to limit its scope to suppliers with a direct contractual relationship with the affected entity, avoiding general statements regarding key internet infrastructure protocols such as DNS.

Lastly, CENTR members welcome ENISA’s expanded role in supporting high-criticality sectors, including ccTLD registries, but stress that ccTLDs must maintain their autonomy in setting their own governance policies.

You can read the full CENTR comment here.

Published By Polina Malaja
Polina Malaja is the Policy Director at CENTR, leading its policy work and liaising with governments, institutions and other organisations in the internet ecosystem.