The Cybersecurity Act V2 (CSA V2), expected to be fully implemented by 2027, will fundamentally change how European organizations manage their ICT supply chains. For CISOs, this means mandatory vendor risk assessments must include ownership structure and country-of-origin analysis, not just technical security controls.
Starting in 2027, organizations classified as essential or important under NIS2 will be prohibited from using ICT components from designated high-risk suppliers in critical infrastructure. Mobile network operators have 36 months to replace affected equipment; other sectors will follow.
The immediate impact: procurement processes need updating, existing vendor relationships require auditing, and replacement roadmaps must be developed. Organizations with significant exposure to potentially affected suppliers (currently ~32% of 5G infrastructure in the EU) face substantial transition costs.
CISOs should act now: map your supply chain exposure, implement enhanced vendor due diligence incorporating non-technical risk factors, and align replacement cycles with the transition timeline. Early preparation minimizes disruption and positions your organization ahead of mandatory compliance deadlines.
Recommended advisory: PAC Leadership Session – Cybersecurity Compliance
SHARE :
This Excel document positions and ranks the leading AI (Artificial Intelligence) IT Services providers Worldwide.
Event Date : November 01, 2024
PAC has analyzed the IT services provider landscape in Europe and evaluated the leading providers’ approaches, offerings, strategies, and ...
Event Date : January 23, 2024
This Excel document delivers market figures broken down by vertical sectors. Figures cover a seven-year time frame (results from the past two years ...
Event Date : January 21, 2026
The UK public sector is entering a new transformation cycle under the Labour Government, prioritising data-centric modernization across health, ...
Event Date : January 28, 2026
This Excel document delivers market figures broken down by vertical sectors. Figures cover a seven-year time frame (results from the past two years ...
Event Date : January 28, 2026
AI (Artificial Intelligence) by Segments - Market Figures - MEA by countries
Datamart August 21, 2026
AI (Artificial Intelligence) by Segments - Market Figures - MEA consolidation
Datamart August 21, 2026
AI (Artificial Intelligence) by Segments - Market Figures - EMEA by countries
Datamart August 21, 2026
AI (Artificial Intelligence) by Segments - Market Figures - EMEA consolidation
Datamart August 21, 2026
AI (Artificial Intelligence) by Segments - Market Figures - Eastern Europe by countries
Datamart August 21, 2026
Atos: Cause for Optimism, Despite the Headlines
Blog Post February 05, 2024
Europe in Search of its Digital Sovereignty
Blog Post August 21, 2026
PAC RADAR: Digital Platforms & Service Providers for Industrial
Press Releases July 27, 2026
Farnborough Airshow 2026 and the increasing relevance of AI in manufacturing, aerospace and defence
Blog Post July 27, 2026
Beyond the Patch Cycle: How Third-Party Exposure and AI Are Reshaping Ransomware in Europe
Blog Post July 17, 2026
Adobe Summit London 2026 Takeaway
Blog Post July 15, 2026