European cybersecurity policy continued to evolve during June as discussions intensified around updates to the Cybersecurity Act and NIS2 framework. The proposed changes focus on strengthening cybersecurity across critical sectors while reducing complexity in compliance activities. Supply-chain security emerged as one of the highest priorities.
The new proposals give greater attention to risks associated with ICT suppliers and technology dependencies. European regulators are seeking mechanisms that would allow organizations to assess and manage risks originating from critical vendors. This reflects growing concerns about the concentration of technology providers supporting essential services across Europe.
Another important development is the increased role of ENISA in threat coordination and cybersecurity support. Proposed changes would expand ENISA's responsibilities for threat awareness, vulnerability management, and assistance during major incidents. This reinforces the agency's position as a central cybersecurity coordinator across the European Union.
For security professionals, the message is clear: cybersecurity governance is moving closer to the boardroom. Organizations will need stronger visibility into supply chains, more mature risk management practices, and improved documentation of security controls. Practitioners should prepare for increased scrutiny of both operational security processes and third-party relationships.