Space Act negotiations are heading for a fight over cybersecurity that has little to do with satellites and a great deal to do with legislative housekeeping. Members of the Parliament industry committee want the dedicated cyber provisions pulled out of the regulation entirely, on the argument that the Union already has a law for this.
The Commission proposed the Space Act in June 2025 as a single rulebook covering authorisation, debris mitigation, resilience and market access for operators serving European customers. The Council circulated a presidency compromise in December 2025 and a further text in May 2026. The industry committee adopted its draft report in March 2026, and the gap between those documents is now the substance of the coming trilogue.
On cybersecurity the committee proposes deleting the provisions on threat led penetration testing, cryptography requirements and supply chain obligations. Its reasoning is that the NIS 2 directive already governs these duties for essential and important entities, and that writing a parallel regime into the Space Act would force operators to satisfy two authorities applying two vocabularies to one network. Lawyers advising ground segment providers have made the same complaint since the proposal appeared.
The Commission resists the deletion for a reason that is easy to state and hard to dismiss. NIS 2 was drafted around terrestrial infrastructure, and its incident reporting timelines assume an operator can inspect and patch the affected system. A spacecraft in orbit offers neither option. Uplink authentication, command encryption and the integrity of telemetry sit outside what a general directive contemplates, so stripping the Space Act back to a cross reference risks leaving the orbital layer governed by rules written for data centres.
Both positions contain a real problem. The committee is right that duplicated obligations cost money and produce compliance theatre rather than security. The Commission is right that a cross reference only works if the referenced law actually covers the risk. The trilogue will probably land somewhere in between, keeping a short set of space specific requirements and deleting everything NIS 2 already handles, which is the pattern recent sectoral files have followed.
Market access carries the same tension. Operators based outside the Union that sell services into it face authorisation duties under the Space Act, and American firms have spent months calculating what the Council draft would require of them. Some argue the regime amounts to a licensing barrier dressed as safety regulation. Others note that any state permitting launches sets conditions, and that a single Union standard beats twenty seven national ones. The second argument is stronger, though it only holds if the final text really does displace national licensing rather than sitting on top of it.
Timing shapes everything. Trilogues are expected to open late in 2026, and observers tracking the file through the legislative train see adoption slipping toward 2027. Every month of delay matters commercially, because constellation operators placing hardware orders now must guess which rules will bind the satellites they launch in 2029.
The wider point is that the Space Act has become a test of how the Union writes sectoral legislation after a decade of horizontal digital laws. If every new file rebuilds cybersecurity from scratch, compliance departments drown. If every file simply points at NIS 2, genuinely different risks fall through the gap. Lawmakers have not yet found a stable answer, and satellites are an awkward place to look for one.





