The EU Space Act is meant to give Europe its first common rulebook for activity in orbit, and the argument that now decides its shape is a technical one about cybersecurity. The Commission published the proposal, COM(2025) 335, on 25 June 2025. Since then the Council and Parliament have each tabled changes that disagree on whether satellite operators should follow a dedicated space regime or fall under the existing NIS2 Directive.
The Commission’s EU Space Act text treats space as critical infrastructure and builds a specific framework around it. Operators would face lifecycle risk management duties, threat-led penetration testing before launch, supply-chain controls and incident reporting within deadlines of 12 to 72 hours depending on severity. Operators from outside the Union that serve European customers would have to register with the EU Agency for the Space Programme, although an equivalence mechanism could recognise comparable foreign rules.
The Council took a different line in its presidency compromise text of December 2025. Ministers had debated the file at the Competitiveness Council on 9 December and stressed the need for simplification. Under the Council approach, a space operator that already counts as an essential or important entity under NIS2 would follow NIS2 instead, and the space-specific rules would apply mainly to smaller operators and third-country entities. The text also removes international organisations from direct scope and leaves collision avoidance providers outside the regulation.
Parliament went further on the EU Space Act when it published its proposed revisions in March 2026. Rapporteur Elena Donazzan of the ECR group leads the work in the Industry, Research and Energy Committee, and the Parliament position rejects the idea of a separate lex specialis for space cybersecurity. It would fold space activities into NIS2 and replace mandatory certification of environmental footprints with a duty to provide an estimate. Legal analysts at Hogan Lovells noted in May 2026 that realistic adoption looks like 2028, with entry into force around 2030 or 2031.
Timing is another fault line for the EU Space Act. The Commission proposed that it apply from 1 January 2030, with 1 January 2032 for certain planned assets. Council and Parliament both prefer a period of 36 months after entry into force. Enforcement is also contested, because the Commission’s draft caps fines at 2 percent of worldwide annual turnover, while the Council would remove the proposed role of the space agency and keep enforcement with the Commission itself.
For industry the practical question about the EU Space Act is which compliance programme to build. A launch provider or constellation owner cannot design security architecture around three different texts, and each month without a settled position raises costs for planning. Non-EU operators have an extra concern, since Washington criticised the draft in late 2025 as potentially discriminatory, even though negotiators insist the standards apply equally to every operator.
Commissioner Andrius Kubilius has argued that fragmented national rules are bad for business, competitiveness and Europe’s future in space. No final agreement has been reported, and the NIS2 question will probably decide how burdensome the final EU Space Act proves to be for the companies that build and fly Europe’s satellites.





