On 12 May 2026, E.DSO submitted its feedback to the European Commission on the proposed Cybersecurity Act 2 (CSA2), following a dedicated knowledge-sharing and coordination process carried out within E.DSO Task Force 4 on Cybersecurity. The contribution reflects the views of distribution system operators (DSOs) across Europe on the practical implications of the proposal for critical electricity infrastructure.
In a nutshell, the feedback welcomes the overall objectives of CSA2, particularly efforts to strengthen European cybersecurity coordination, reduce fragmentation, and improve ICT supply chain resilience.
Nevertheless, E.DSO stresses that implementation must remain operationally feasible and aligned with the realities of electricity distribution networks.
- A key focus of the contribution is the strengthened role of European Union Agency for Cybersecurity (ENISA) under Title II of the proposal. E.DSO supports ENISA’s enhanced coordination and capacity-building role, while underlining the need for an implementation of a single entry point for cybersecurity reporting. Members also call for stronger involvement of operators in ENISA governance and advisory structures to ensure that future guidance reflects operational realities faced by DSOs.
- Regarding the European Cybersecurity Certification Framework (Title III), E.DSO raises concerns about the risk of duplicating existing standards and creating additional administrative burden without sufficient added value. The feedback highlights that certification schemes must recognise equivalent existing frameworks, remain proportionate, and avoid slowing down innovation and grid digitalisation efforts through lengthy or rigid procedures.
- On ICT Supply Chain Security (Title IV), E.DSO supports a coordinated European approach but stresses that risk assessments and mitigation measures must remain evidence-based, proportionate, and context-specific. The feedback emphasises the importance of service continuity, phased implementation, lifecycle considerations, and transparency in supplier risk assessments, particularly given the long operational lifetimes of electricity infrastructure assets.

The contribution was developed through a structured consultation process within the E.DSO Cybersecurity Task Force, including article-by-article analysis and a dedicated online knowledge-sharing session involving cybersecurity experts and member companies.
You can now explore the full E.DSO Feedback on CSA2.