Article content
In briefShow moreShow lessThe proposal sought more agile certification schemes and a stronger role for ENISA.
- The proposal sought more agile certification schemes and a stronger role for ENISA.
- It also covered ICT supply-chain risk and simplification of existing cybersecurity compliance.
- This was a Commission proposal, not adopted EU law.
The European Commission presented a proposal to revise the Cybersecurity Act. Its stated direction was to strengthen the EU’s resilience and capacity against digital threats while making existing mechanisms easier to use. The proposal therefore combined a strategic security objective with a practical compliance objective.
A central element was more agile cybersecurity certification. The Commission proposed mechanisms that could adapt more readily as technology, threat conditions and market needs change. Certification would remain a way to document security properties; it would not automatically prove that every other legal requirement had been satisfied.
The proposal would also strengthen ENISA’s role. The agency’s functions were intended to support a more coordinated European approach to certification, capability and implementation. The proposed role still depended on the legislative process, because the Commission’s announcement did not itself amend ENISA’s mandate.
ICT supply chains were another major focus. Risk can enter through software, hardware, cloud services, updates and subcontractors even when an organisation’s own systems are well protected. Organisations should therefore maintain visibility over critical dependencies, update paths, geographic exposure and realistic options for changing suppliers.
The Commission also linked the proposal to simplifying existing cybersecurity compliance. The aim was to reduce unnecessary duplication and clarify how different schemes interact. There was no basis, however, for treating the announcement as an immediate exemption mechanism or as a new, consolidated set of binding duties.
For Norwegian organisations, the status and timing were especially important. The proposal did not directly change Norwegian law. Any eventual Norwegian effect would depend on EU adoption, an assessment of EEA relevance and subsequent Norwegian implementation where required.
Organisations with EU exposure could still treat the proposal as a strategic signal. They could use it to test certification strategies, supplier mapping and security-documentation practices, but should not describe or apply the Commission proposal as binding law before the legislative process was complete.
Sources
European Commission: “Commission strengthens EU cybersecurity resilience,” 20 January 2026.
European Commission: “Proposal for a Regulation for the EU Cybersecurity Act,” 20 January 2026.
For discussion
Which supply-chain dependencies and certification needs should the organisation map if the proposal is eventually adopted?

