Back to news

EU Space Act vs NIS2: Brussels' Fight Over Satellite Cyber Rules

Share:
EU Space Act vs NIS2: Brussels' Fight Over Satellite Cyber Rules

The European Commission's draft EU Space Act would force satellite operators serving European Union markets to report a major cyberattack within 12 hours of detection, twice as fast as the deadline set by the bloc's existing NIS2 cybersecurity directive. The bill, proposed on 25 June 2025 as COM(2025) 335, is now stuck in a three way argument between the Commission, the Council, and the European Parliament over which cybersecurity regime should actually govern Europe's satellites.

A reporting clock built for the Viasat scenario

Articles 75 through 95 of the proposal form a dedicated resilience chapter, and Article 93 sets the incident reporting timeline. Operators of Union owned space assets get 12 hours to file an early warning after detecting a significant cyberattack; everyone else gets 24 hours, matching NIS2's existing baseline. Both tracks then require a detailed follow up report within 72 hours and a final report within one month, layered on top of parallel duties to notify the EU Agency for the Space Programme and national authorities, on top of any separate report already owed to a NIS2 computer security incident response team.

EU officials have pointed to the 2022 Viasat KA-SAT hack as the scenario the faster clock is meant to catch sooner. Russian linked wiper malware disabled modems across Europe hours before Russia's invasion of Ukraine, cutting Ukrainian military communications and knocking out roughly 5,800 German wind turbines in the process.

Penetration testing before a satellite ever launches

Article 88 adds a second obligation: threat led penetration testing, built on the same TLPT framework the Digital Operational Resilience Act uses for banks. Operators must have their systems tested by an accredited assessor before launch, or before the first batch of a constellation goes up, and at least once every three years afterward. National accreditation bodies are meant to certify who qualifies as an assessor, a structure Hogan Lovells has compared directly to DORA's regime for financial institutions.

Nobody agrees on which law wins

The Commission's original text designates its own resilience chapter as lex specialis, meaning it would override NIS2's general obligations for any operator that already qualifies as an essential or important entity under that directive. The Council's presidency compromise, circulated on 5 December 2025, backs away from that framing. Instead of a full override, the Council draft says the Space Act applies without prejudice to NIS2, so operators already covered by NIS2 keep those obligations too, with national authorities expected to coordinate rather than one law replacing the other.

The European Parliament's industry committee, ITRE, has staked out a third position. Its March 2026 draft rejects a bespoke space cybersecurity regime altogether, proposing instead to amend NIS2 directly so it covers space activities, services, and EU owned assets within the existing directive. Academic reviewers have flagged the resulting overlap as a risk of duplicative compliance efforts, since it remains genuinely unclear today which of the two rulebooks a given satellite operator has to follow.

A cost smaller operators are already flagging

European industry groups have warned the cybersecurity chapter could hit startups hardest. The Commission's own impact assessment estimates authorisation requirements could cost around 100,000 euros per product line, on top of a manufacturing cost increase of up to 10 percent that analysts have attributed to the combined safety and resilience obligations. Critics note the rules were modeled on established primes like ArianeGroup and Thales Alenia Space, and apply much the same certification load to a two person startup building a single cubesat.

Reach beyond the EU, and a distant deadline

The cybersecurity chapter reaches well beyond EU borders. Any operator selling space based services into the EU falls under it regardless of where the company is headquartered, and non-EU operators must appoint a legal representative inside the Union and submit to compliance checks unless the Commission grants a derogation. Washington has objected specifically to the giga constellation thresholds, arguing they have a selective effect on a category the market fills almost entirely with American operators: SpaceX's Starlink, now flying more than 8,000 active satellites, and Amazon's Project Kuiper. Violations of the regulation's safety and security requirements carry fines of up to 2 percent of an operator's global annual turnover, enforced through the EU Agency for the Space Programme.

Full compliance is not due until 1 January 2030, and satellites already in orbit by then, including existing Starlink and Kuiper spacecraft, would be grandfathered under current rules. Trilogue talks between Parliament and Council are expected to open in the second half of 2026, but given how far apart the two institutions remain on the cybersecurity chapter alone, final adoption before late 2027 looks unlikely.

The stakes were underscored again in January 2026, when the European Space Agency confirmed that hackers had spent roughly a week inside a small number of external servers used for unclassified engineering projects, with a seller on the forum BreachForums offering 200 gigabytes of the resulting data for sale.

First mapped in detail by legal analysts at Hogan Lovells and Access Partnership following the European Commission's June 2025 proposal.