Skip to content

Dossier · Ordinary legislative procedure

European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)

Reference
2026/0011(COD) Ordinary legislative procedure
Where it stands
In committee: ITRE (Industry, Research and Energy) is preparing the report (draft published 18 September 2026).
Stage
First reading
Lead committee
Industry, Research and Energy ITRE
More facts (5)
Rapporteur
Markéta GREGOROVÁ
Shadow rapporteurs
7 members
Decisions in plenary
None yet
Versions
1 version
Opinions from
IMCO

Where it stands

The steps of this kind of dossier and how far it has come, from the procedure file.

  1. Referred to committee (done) 25 March 2026
  2. Committee work (current step) ITRE (Industry, Research and Energy) preparing the report
  3. Tabled for plenary (to come)
  4. Plenary vote (to come)
  5. Negotiations with the Council (to come)
  6. Published as law (to come)

A proposed EU law. Parliament and the Council must agree on the same text: Parliament adopts its position, then negotiates with the Council.

People

Committees and members responsible for the dossier, as the procedure file names them. Groups as recorded there.

Lead committee
Industry, Research and Energy ITRE
Opinion: IMCO
Internal Market and Consumer Protection · rapporteur Maria GUZENINA (S&D)

Decisions in plenary, 0

Every decision Parliament took on this dossier, newest first.

No plenary decision on this dossier is in the records yet.

Voting grid

Export

Every roll-call vote on the dossier, in date and voting order, with each group's line at the date of the vote.

No roll-call vote was recorded on this dossier.

Add members’ columns
The people on this dossier — pick up to 6. Each gets a column with their own position.

Versions, 1

The text of the dossier, version by version, newest first. Compare shows what changed between two consecutive versions.

  1. Committee draft18 Sept 2026

    Draft report (ITRE) ITRE-PR-792222

AI: Each version in short Written by AI from the official text — check the source
  • Draft report (ITRE): This is the rapporteur's draft report on the proposed Cybersecurity Act 2, which would replace Regulation (EU) 2019/881, broaden ENISA's mandate, reform European cybersecurity certification and set Union rules on ICT supply chain security.

Report a problem

What changed

Between consecutive versions of the text, newest pair first.

No overview of what changed between versions is available for this dossier — fewer than two versions of its text are linked in the open data.

Timeline, 2

Every recorded step, newest first, grouped by stage; the latest stage is open.

Committee stage 2 steps · 25 Mar 2026–18 Sept 2026
  1. 18 September 2026

    Draft report published

    The rapporteur’s first text in ITRE (Industry, Research and Energy). Members can table amendments before the committee votes.

    Draft report (ITRE)

  2. 25 March 2026

    Referred to the ITRE (Industry, Research and Energy) committee

    The lead committee prepares the report; IMCO (Internal Market and Consumer Protection) gives an opinion.

Connections

Texts, decisions, people and other dossiers related to this one.

No connections found for this item.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2026). “European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)”. Dossier. reference 2026/0011(COD). EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/dossiers/2026-0011 (retrieved 25 September 2026). Official source: Legislative Observatory (OEIL), 2026/0011(COD), https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2026%2F0011(COD). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-dossier-2026-0011,
  author = {{European Parliament}},
  title = {{European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)}},
  year = {2026},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/dossiers/2026-0011}},
  url = {https://news.eu-parl.st-solutions.dev/dossiers/2026-0011},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Dossier. reference 2026/0011(COD). Official source: https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2026\%2F0011(COD). Data: European Parliament Open Data (CC BY 4.0)}
}