Prague: The EU Space Act has been published in the Official Journal, completing more than three years of negotiation and bringing the Union’s first horizontal legislative framework on space activities into force. From early 2027, operators of space objects launched from or registered in the Union must comply with binding rules on collision avoidance, end-of-life disposal, cybersecurity and operational reporting.
Regulation (EU) 2026/0145 covers the full range of orbital activities, from launch services and satellite operation to in-orbit servicing and end-of-life de-orbiting. Until now, space activities in the Union were governed by a patchwork of fifteen national laws applying different licensing thresholds, technical standards and liability frameworks. The fragmentation had become a source of regulatory arbitrage and a barrier to a single market in space services.
The European Union Agency for the Space Programme, headquartered in this city, has been designated as the technical authority for the new framework. Its responsibilities include the maintenance of a Union-wide space surveillance and tracking infrastructure, the development of harmonised technical standards in cooperation with the European Space Agency, and the certification of space situational awareness service providers. The Agency’s existing role under the Galileo and EGNOS programmes provides a foundation that is now substantially expanded.
The most demanding new obligations relate to orbital debris. Operators must demonstrate a high probability of successful end-of-life de-orbiting at the licensing stage, with default values requiring the natural decay of low earth orbit objects within five years of mission completion. The previous benchmark, drawn from non-binding international guidelines, was twenty-five years. The shorter horizon reflects the rapid increase in orbital traffic and the consequent rise in collision risk, especially in the low earth orbit shells where megaconstellations now operate. Operators may apply for derogations on technical grounds, but the burden of proof rests on the applicant.
A second obligation concerns collision avoidance. All space objects in the Union register must be capable of executing avoidance manoeuvres when the probability of conjunction exceeds a defined threshold. Operators must establish twenty-four-hour conjunction monitoring and have agreements in place with the Agency or recognised commercial service providers for the receipt and verification of conjunction warnings. Cubesats and small satellites are not exempted from the requirement, though simplified compliance modules apply to those below defined mass thresholds.
A third strand of the regulation addresses cybersecurity. Space objects are increasingly part of critical infrastructure, and the loss of command-and-control over an active satellite has both operational and physical consequences. The regulation imposes security-by-design obligations, vulnerability handling duties and reporting requirements that align with the Cyber Resilience Act but adapt them to the particularities of space operations.
The transitional arrangements are critical. Existing satellites enjoy grandfathering for collision avoidance but not for the cybersecurity requirements, which apply from 2028 to all command-and-control infrastructure regardless of when the underlying satellite was launched. The Agency is preparing technical specifications and a notified body framework that should make compliance assessment feasible within commercial timeframes.
For the Union’s nascent commercial space sector, the regulation marks a maturation. For operators based outside the Union but offering services to European customers, the rules raise compliance considerations that will need to be factored into commercial pricing. The next twenty months will determine whether the framework becomes a model for other jurisdictions or a source of competitive disadvantage. Industry voices are watching closely.




