Skip to Primary Navigation

EU Commission proposals on digital sovereignty and high-risk vendors

Playmobil Hacker dressed in dark clothing with torch about to steal information from mobile.
Photo: seewhatmitchsee/Getty Images

Regulation to push European businesses and third-country suppliers to consider potential exposure to government influence when assessing their technology vendor relationships.

In what the EU Commission identifies as an increasingly hostile threat landscape riddled with daily sophisticated state actor threats[1], it has issued a proposal for radical new supply chain requirements in the draft Cybersecurity Act 2 (the CSA2) that would push European enterprises to consider potential exposure to government

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience