Darmstadt: In the mission control rooms of this German city, engineers who steer Europe’s satellites are watching a legislative fight that could reshape how every spacecraft on the continent is built and defended. The European Union’s proposed Space Act has run into deep disagreement between the institutions meant to pass it, and the sticking point is cybersecurity.
The Commission unveiled the draft in June 2025 as the bloc’s first attempt to write common rules for a sector long governed by a patchwork of national laws. It rests on three pillars, safety, resilience and sustainability, and would oblige operators to manage the risk of collisions, guard against cyberattack and eventually clean up the debris their satellites leave in orbit.
The resilience chapter has become the battleground. As drafted, the Space Act would require new satellites to carry cybersecurity protections built in from launch, with operators running regular risk assessments across a spacecraft’s working life. Brussels argues that space infrastructure now underpins everything from banking to navigation, and that a single compromised satellite could ripple through the economy below.
Lawmakers disagree over how to deliver that protection. The European Parliament’s negotiators want to strip the resilience chapter out of the Space Act altogether and fold space systems into the existing NIS2 cybersecurity directive instead, arguing that two overlapping rulebooks would only confuse operators. The Council prefers to keep the obligations inside the new law, and the two sides entered talks far apart.
Legal doubts have deepened the stalemate. The Council’s own legal service questioned whether parts of the proposal fall within the Union’s authority, and delegations lodged scrutiny reservations across large sections of the text. Those objections give reluctant capitals cover to slow the file while they weigh the cost to their national space champions.
Industry is split. Larger operators accept that common standards could open a fragmented single market and spare them the expense of meeting twenty-seven different regimes. Smaller firms and start-ups fear that heavy compliance duties, especially on cybersecurity, will fall hardest on companies without the budgets of established players. Non-EU operators that sell services into Europe are watching just as closely, since the market-access rules would reach them too.
For now the Space Act remains stuck between ambition and objection. Supporters insist Europe cannot keep launching critical infrastructure with no shared rules on how to protect it. Sceptics warn that a rushed law could saddle a promising industry with red tape before it finds its feet. The trilogue negotiations ahead will decide which fear wins out.




