EU Implements New Cybersecurity Package Affecting Companies

EU Implements New Cybersecurity Package Affecting Companies

First seen 10 Feb 2026, 03:11 UTC LexologyJdsupra 20.3

Article Content

Browse articles
ThreatCluster

On February 9, 2026, the European Union proposed a new cybersecurity package that elevates cybersecurity certification to a compliance and risk-management instrument. Companies operating in the EU will be required to disclose sensitive information, including ransom payments, only upon request from the Computer Security Incident Response Team or relevant authorities. These reforms aim to enhance cybersecurity measures across the region.

Timeline

2026-02-09
EU proposed new cybersecurity package
2026-02-09
Cybersecurity certification elevated to compliance instrument
2026-02-09
Disclosure of ransom payments regulated