Threat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 01.08.2026 10:21 CET72 dossiersMITRE ATT&CK mapping

Editorial explainer · official EUR-Lex sourcemedium

What Europe does when the attack is too big for one state: inside the Cyber Solidarity Act

Regulation (EU) 2025/38 — the Cyber Solidarity Act — answers a question no directive on corporate obligations addresses: what happens when an attack exceeds a single Member State's capacity to respond. It builds three things: a European cybersecurity alert system made of interconnected hubs that share what they see, a cybersecurity emergency mechanism, and an EU Cybersecurity Reserve, that is, incident response services contracted in advance and activated on request. It imposes no duties on companies: it organises solidarity before it is needed. And it is deliberately limited to the initial phase of recovery.

The question the other rules do not ask

European cybersecurity legislation of recent years shares one trait: it tells someone what to do. NIS2 tells essential and important entities which measures to adopt and what to notify. DORA tells the financial sector. The Cyber Resilience Act tells product manufacturers. CER tells critical entities.

All of them assume one thing: that whoever is hit is able to react. There is a scenario in which that assumption breaks, and none of the earlier rules address it: a large-scale incident that exceeds a Member State's capacity to respond.

Regulation (EU) 2025/38 — adopted on 19 December 2024 and published in the Official Journal on 15 January 2025 — is the answer to that question. It lays down measures to strengthen solidarity and the Union's capacities to detect cyber threats and incidents, and to prepare for and respond to them, and it amends Regulation (EU) 2021/694 on the Digital Europe Programme.

The three things it builds

  1. 01
    European alert system
    a pan-European network of hubs detecting and sharing
  2. 02
    Emergency mechanism
    rapid mobilisation of assistance in defined circumstances
  3. 03
    EU Cybersecurity Reserve
    response services contracted in advance, activated on request

The European cybersecurity alert system is a pan-European network of hubs working on coordinated detection and information sharing about the situation. Translated into practice, the idea is that the same campaign should not be discovered twenty-seven separate times. If infrastructure in one Member State sees an indicator, that data should reach the others before the attack does — which is, ultimately, the only structural advantage defence can hold over an attacker replaying the same technique.

The cybersecurity emergency mechanism is the delicate part. It must allow rapid and effective mobilisation of assistance in defined circumstances and under specific conditions, while also allowing accurate monitoring and evaluation of how resources are used. Those two needs pull in opposite directions — speed and control — which is precisely why the conditions are written down rather than left to the moment.

The EU Cybersecurity Reserve is the most concrete part. These are incident response services from trusted providers, contracted in advance, activated when a Member State or eligible entity requests them. The principle is banal and frequently ignored in crisis management: you do not go looking for teams at the moment you need them, you keep them ready beforehand.

The limit written into the rule, and why it matters

There is a clarification in the regulation that deserves more attention than it gets: support from the EU Cybersecurity Reserve should be limited to the initial phase of the recovery process, the one leading to the restoration of basic system functionalities.

On first reading that looks restrictive; in fact it is why the mechanism can work at all. A reserve committed to completing every recovery would be consumed by the first large incident. Limiting it to getting essential functions back up keeps it available for the second — and the history of large-scale incidents suggests the second often arrives while the first is not over.

The regulation is equally explicit about the responsibility architecture: primary responsibility for preventing incidents and crises, and for preparing and responding, remains with the Member States. The emergency mechanism promotes solidarity; it does not substitute for national capacity. Reading this regulation as a European rescue service is reading it wrong: it is a safety net, and safety nets are strung beneath someone who is walking anyway.

Where it touches those who are not a Member State

An Italian SME has no direct obligations under this regulation, and that is the first thing to say to head off compliance anxiety. It adds no lines to your checklist.

It does, however, shape the context that SME operates in, in two ways worth understanding.

First: activatable assistance runs through national structures. A country's ability to benefit from these instruments depends on its national CSIRT knowing what is happening, and that depends on the notifications it receives. The reports that feel like paperwork — the ones NIS2 requires, the ones to the CSIRT — are the input to the very system that, in the severe scenario, decides whether and how to request assistance. Not notifying is not merely a breach: it removes a data point from the mechanism.

Second: the Commission cooperates with the High Representative on requests received and on the implementation of support granted to third countries associated with the Digital Europe Programme. That signals that the perimeter of this solidarity does not map exactly onto the Union's, and that cybersecurity is also being handled as foreign policy.

What to take away

The Cyber Solidarity Act does not change what you must do tomorrow. It changes the frame in which the rest should be read: NIS2 says what the entity must do, this regulation says what happens when the entity, or the state, cannot manage alone. They are two sides of the same policy, and it is useful to know the second side exists — especially for whoever, in a crisis, has to decide who to call.

A note on sources and limits: this explainer is based on the text of Regulation (EU) 2025/38 as published on EUR-Lex. It does not go into individual articles, financial envelopes and implementing acts, which should be read in the source: we preferred to describe the architecture as it stands, without attributing to the regulation figures or mechanisms we did not verify directly in the text.

More dossiers