Kourou: Launch operators working out of Europe’s spaceport want to know which rulebook will govern their satellites, and the Space Act still cannot tell them. The regulation the Commission proposed in June 2025 has reached the stage where the Parliament and the Council disagree openly about who should write cybersecurity rules for orbit, and that disagreement now shapes the timetable for the whole file.
The Commission designed the Space Act around three pillars. It would force operators to track their objects, mitigate debris and dispose of satellites safely. It would impose cybersecurity duties on space infrastructure. And it would make operators calculate the environmental footprint of a mission across its full lifecycle. Crucially, the rules would apply to non-EU operators selling services into the single market, which is why American and Japanese constellation owners have followed the drafting closely. The Commission set out its reasoning when it published the proposal.
The cybersecurity chapter has become the fault line. The Commission text, and the Council presidency compromise that followed, require operators to run threat-led penetration testing before launch, or before the first batch of a constellation goes up, and to repeat it at least every three years. That is a demanding obligation borrowed from financial-sector supervision, and it would bite hardest on smaller European manufacturers without in-house red teams.
Parliament’s industry committee took a different view. Rapporteur Elena Donazzan published her draft report in March 2026, and the committee line proposes deleting the dedicated penetration testing, cryptography and supply chain provisions altogether. Their argument is structural rather than permissive: the NIS 2 directive already governs cybersecurity for critical entities, and duplicating it inside a sectoral space regulation invites conflicting obligations and two sets of supervisors.
Member states are not aligned either. The Council working party circulated a revised text in March 2026, and capitals with national space laws already on the books, France, Austria and Denmark among them, want the Space Act to accommodate their existing authorisation regimes rather than override them. Countries without such laws prefer a single European framework precisely because it spares them the drafting.
The substantive question underneath the procedural one is whether space is different enough to deserve its own cyber regime. Defenders of the Commission approach point out that a compromised satellite cannot be patched by sending an engineer, that ground segments and space segments face different threat models, and that horizontal legislation written for hospitals and energy grids will not capture either. Sceptics reply that NIS 2 is deliberately flexible, that sectoral carve-outs multiply once one is granted, and that Europe’s space firms already carry more compliance weight than their competitors.
There is a competitiveness argument on both sides that neither institution has fully answered. Heavy obligations could push European start-ups toward jurisdictions with lighter rules. Weak ones could leave European infrastructure exposed while the bloc builds out IRIS2 and expands military reliance on commercial constellations. The debris and light pollution provisions, meanwhile, have drawn far less controversy, which suggests the environmental core of the Space Act will survive largely intact.
Trilogue negotiations will settle it, and they have not yet begun in earnest. The file needs a Parliament plenary mandate and a Council general approach before the three institutions can bargain, and neither is locked. Operators planning launches for 2028 and beyond should watch the autumn ITRE vote closely, because the Space Act text that emerges from it will define the negotiating floor for everything that follows.




