Dossier · Ordinary legislative procedure
European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)
- Reference
- 2026/0011(COD) Ordinary legislative procedure
- Where it stands
- In committee: ITRE (Industry, Research and Energy) is preparing the report (draft published 18 September 2026).
- Stage
- First reading
- Lead committee
- Industry, Research and Energy ITRE
Where it stands
The steps of this kind of dossier and how far it has come, from the procedure file.
- Referred to committee (done) 25 March 2026
- Committee work (current step) ITRE (Industry, Research and Energy) preparing the report
- Tabled for plenary (to come)
- Plenary vote (to come)
- Negotiations with the Council (to come)
- Published as law (to come)
A proposed EU law. Parliament and the Council must agree on the same text: Parliament adopts its position, then negotiates with the Council.
People
Committees and members responsible for the dossier, as the procedure file names them. Groups as recorded there.
- Lead committee
- Industry, Research and Energy ITRE
- Rapporteur
- Markéta GREGOROVÁ (Greens)
- Shadow rapporteurs
- Tomas TOBÉ (EPP), Jens GEIER (S&D), Aleksandar NIKOLIC (Patriots), Diego SOLIER (ECR), Bart GROOTHUIS (Renew), Marc BOTENGA (The Left), Markus BUCHHEIT (ESN)
- Opinion: IMCO
- Internal Market and Consumer Protection · rapporteur Maria GUZENINA (S&D)
Decisions in plenary, 0
Every decision Parliament took on this dossier, newest first.
No plenary decision on this dossier is in the records yet.
Every roll-call vote on the dossier, in date and voting order, with each group's line at the date of the vote.
No roll-call vote was recorded on this dossier.
Add members’ columns
Versions, 1
The text of the dossier, version by version, newest first. Compare shows what changed between two consecutive versions.
Committee draft18 Sept 2026
Draft report (ITRE) ITRE-PR-792222
AI: Each version in short Written by AI from the official text — check the source
- Draft report (ITRE): This is the rapporteur's draft report on the proposed Cybersecurity Act 2, which would replace Regulation (EU) 2019/881, broaden ENISA's mandate, reform European cybersecurity certification and set Union rules on ICT supply chain security.
What changed
Between consecutive versions of the text, newest pair first.
No overview of what changed between versions is available for this dossier — fewer than two versions of its text are linked in the open data.
Timeline, 2
Every recorded step, newest first, grouped by stage; the latest stage is open.
Committee stage 2 steps · 25 Mar 2026–18 Sept 2026
18 September 2026
Draft report published
The rapporteur’s first text in ITRE (Industry, Research and Energy). Members can table amendments before the committee votes.
25 March 2026
Referred to the ITRE (Industry, Research and Energy) committee
The lead committee prepares the report; IMCO (Internal Market and Consumer Protection) gives an opinion.
Connections
Texts, decisions, people and other dossiers related to this one.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Official source
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2026). “European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)”. Dossier. reference 2026/0011(COD). EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/dossiers/2026-0011 (retrieved 25 September 2026). Official source: Legislative Observatory (OEIL), 2026/0011(COD), https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2026%2F0011(COD). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-dossier-2026-0011,
author = {{European Parliament}},
title = {{European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)}},
year = {2026},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/dossiers/2026-0011}},
url = {https://news.eu-parl.st-solutions.dev/dossiers/2026-0011},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Dossier. reference 2026/0011(COD). Official source: https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2026\%2F0011(COD). Data: European Parliament Open Data (CC BY 4.0)}
}