{"id":56433,"date":"2021-10-20T22:25:40","date_gmt":"2021-10-20T14:25:40","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/the-eu-faces-legal-changes-ahead-for-cybersecurity-in-space\/"},"modified":"2021-10-20T22:25:40","modified_gmt":"2021-10-20T14:25:40","slug":"the-eu-faces-legal-changes-ahead-for-cybersecurity-in-space","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/the-eu-faces-legal-changes-ahead-for-cybersecurity-in-space\/","title":{"rendered":"The EU Faces Legal Changes Ahead for Cybersecurity in Space"},"content":{"rendered":"<p>Cybersecurity remains one of the central topics when it comes to the space sector, not the least because of the role that satellite networks play in society, from satellite communications to Earth Observation (EO), to navigation. Nevertheless, few national space legislations have expressly addressed the need to meet cybersecurity requirements. <\/p>\n<p>One such case is the United Kingdom approach. The Space Industry Regulations 2021 contain a specific chapter on cybersecurity that requires a licensee to draw up and maintain a cybersecurity strategy for the network and information systems used in relation to spaceflight operations. The regulations also establish a duty to report incidents that have an adverse effect on the security of such systems and that may have a significant impact on future essential services. <\/p>\n<p>\t\t\t\t<img loading=\"lazy\" width=\"300\" height=\"225\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/PfxLKpF3SRSThDri0gEt_VS_110121_DGTL_Cover-300x225.jpg\" class=\"attachment-medium size-medium\" alt=\"\" style=\"width: 120px; height: auto;\" decoding=\"async\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/PfxLKpF3SRSThDri0gEt_VS_110121_DGTL_Cover-300x225.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/PfxLKpF3SRSThDri0gEt_VS_110121_DGTL_Cover-800x599.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/PfxLKpF3SRSThDri0gEt_VS_110121_DGTL_Cover-640x480.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/PfxLKpF3SRSThDri0gEt_VS_110121_DGTL_Cover.jpg 1280w\" sizes=\"(max-width: 300px) 100vw, 300px\">\t\t\t<\/p>\n<h3 class=\"fs-5 mt-0\">Explore the November 2021 Issue<\/h3>\n<p class=\"mb-0 fs-smaller text-balance\">Check out more from this issue and find your next story to read.<\/p>\n<p>\t\t\t<button class=\"btn btn-primary\" type=\"button\" data-bs-toggle=\"offcanvas\" data-bs-target=\"#offcanvasMENU\" aria-controls=\"offcanvasExample\" aria-label=\"button\" style=\"white-space: nowrap;\"><br \/>\n\t\t\t\tView More <i class=\"bi bi-arrow-right-circle\"><\/i><br \/>\n\t\t\t<\/button><\/p>\n<p>In the United States, Space Policy Directive-5 also establishes a set of cybersecurity principles for space systems, including the implementation of cybersecurity plans, noting that \u201cintegrating cybersecurity into all phases of development and ensuring full life-cycle cybersecurity are critical for space systems.\u201d<\/p>\n<p>In the European Union, there is no EU space law applicable to space activities, nor can the EU approve such a law. Under Article 189 of the Treaty on the Functioning of the European Union (TFEU), the EU cannot harmonize the laws and regulations of the member states when it comes to space activities. Indeed, though the recent EU Space Programme Regulation \u2013 Regulation (EU) 2021\/696 of 28 April 2021\u2014 does address cybersecurity, it does so with relation to the EU flagship programs Galileo, EGNOS, Copernicus, SST, and GovSatCom. Hence, lacking express cybersecurity requirements enshrined in national laws, it would seem that no cybersecurity obligations would directly apply to space actors.<\/p>\n<p>However, changes are coming to the EU cybersecurity regulatory framework with direct impact to the space sector.<\/p>\n<p><script>var AIAD_fcd45f981d570e35cee941b23edc69c7_6a6aec0a68a43;googletag.cmd.push(function(){var AIMAP_29b58f13885ebf8ea6b032f958eb0748 = googletag.sizeMapping().addSize([992, 100], [[970, 90], [970, 250]]).addSize([768, 100], [728, 90]).addSize([320, 100], [320, 50]).build();var AIMAP_737ce075cc05dd766c8f8ea08f3faa73 = googletag.sizeMapping().addSize([768, 100], [728, 90]).addSize([320, 100], [320, 50]).build();var AIMAP_21fe3bcfb86a8660aba4e721ee9338f3 = googletag.sizeMapping().addSize([1200, 100], [970, 250]).addSize([768, 100], [600, 300]).addSize([320, 100], [300, 250]).build();AIAD_fcd45f981d570e35cee941b23edc69c7_6a6aec0a68a43 = googletag.defineSlot('\/987\/satellitetoday.com\/via-satellite-digital-issue-ads', [ [600, 300], [300, 250], [970, 250] ], 'div-gpt-ad-1774631144891- 0-6a6aec0a68a45').defineSizeMapping(AIMAP_21fe3bcfb86a8660aba4e721ee9338f3).setCollapseEmptyDiv(true).addService(googletag.pubads());   });<\/script><script>googletag.cmd.push(function() { googletag.display('div-gpt-ad-1774631144891- 0-6a6aec0a68a45'); });<\/script><\/p>\n<p>There is a proposal for a directive on measures for a high common level of cybersecurity across the union (NIS 2 Directive), which will replace to current NIS Directive. Unlike the current NIS Directive, the future directive, as it is written at the moment, is going to apply to the space sector, to \u201coperators of ground-based infrastructure, owned, managed and operated by member states or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks.\u201d Despite this last wording, public electronic communications networks are still going to be subject to the NIS 2 Directive, as this future directive is going to apply also to \u201cproviders of public electronic communications networks and of electronic communications services that are publicly available\u201d (thus repealing the current cybersecurity provisions applicable to public telecom service and networks under the European Electronic Communications Code \u2013 EECC). <\/p>\n<p>The new NIS 2 Directive contains extremely demanding cybersecurity obligations that all public and private entities performing the above activities and providing services in a member state shall comply with. These measures include risk analysis, incident handling, supply chain security, testing and auditing procedures, use of cryptography and encryption, notification of cyber incidents. Breach of such obligations leads to substantial consequences, including administrative fines of a maximum of at least 10 million euro or up to 2 percent of the total worldwide annual turnover of the undertaking to which the entity belongs in the preceding financial year, whichever is higher. <\/p>\n<p>Other possible consequences of breach include: suspension of a certification or authorization; and a temporary ban against any person discharging managerial responsibilities at chief executive officer or legal representative level in the relevant entity, and of any other natural person held responsible for the breach, from exercising managerial functions in that entity.<\/p>\n<p>Another directive on the resilience of critical entities (CER Directive) is also being proposed, which will replace the current ECI (European Critical Infrastructures) Directive. The CER Directive aims to complement the NIS 2 Directive with relation to physical security. It will also apply to \u201coperators of ground-based infrastructure, owned, managed and operated by member states or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks,\u201d as well as to providers of public electronic communications networks and of electronic communications services that are publicly available. <\/p>\n<p>However, unlike the NIS 2 Directive, only entities in these sectors that have been identified as a \u201ccritical entity\u201d by a member state are subject to the obligations. These obligations are also quite demanding and include, for instance, adequate physical protection, risk and crisis management procedures, incident recovery, employee security management, incident notification, risks assessments.<\/p>\n<p>These two new proposed directives are going to thoroughly impact the space sector. Even though they do not apply throughout the whole space value chain, they apply to operators of ground-based infrastructure supporting the provision of space-based services, as well as to public telecom service and network providers (which include providers of satcom networks and services). What is more, the consequences of breach are considerable. <\/p>\n<p>Both directives raise however some questions that could be discussed and addressed in future versions, such as: their application to only certain stakeholders in the (non-satcom) space sector \u2013 ground segment operators; and the different treatment of (public\/publicly available) satcom vis-\u00e0-vis other space activities. Given the central role of satellites worldwide including for achieving the Sustainable Development Goals (SDGs) and the EU green and digital transition, there is growing need to protect space assets from cyber threats. This may require a more ambitious legal framework. States should as a result assess addressing cybersecurity for space activities in general and do so in their national laws (such as in their space laws), in a manner that is well coordinated with the future NIS 2 and CER Directives and that avoids duplicated burdens for space actors.<\/p>\n<p>In any case, even if national space laws do not address cybersecurity obligations, they often contain a set of obligations that require cyber resilience: for instance, most national space laws address the need to safeguard health, safety and the environment, with some of them expressly referring to space debris mitigation and remediation. What is more, cyber resilience is also an important instrument to avoid or mitigate potential liability that may arise from space activities.<\/p>\n<p>Nevertheless, the NIS 2 and CER Directives are going to bring substantial obligations to space stakeholders. Space actors should start preparing for the changes ahead. <strong class=\"Annotation -strong\">VS<\/strong><\/p>\n<p><em class=\"Annotation -emphasis\">Helena Correia Mendon\u00e7a is the principal consultant at the Information, Communication &amp; Technology practice at Vieira de Almeida &amp; Associados. Helena has been involved in various space sector projects, both in Europe and Africa. She further works on Emerging Technologies, especially on DLT\/Blockchain, AI, robotics, autonomous vehicles and Fintech related issues.<\/em><\/p>\n<p>,<\/p>\n<h2 class=\"widget-title\">In This Issue<\/h2>\n<p>\t\t\t\t\t<!-- post id 405574:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img loading=\"lazy\" width=\"300\" height=\"225\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/qtRE3pJTJKcoidUjhckA_VS_110121_DGTL_Cloud-300x225.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/qtRE3pJTJKcoidUjhckA_VS_110121_DGTL_Cloud-300x225.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/qtRE3pJTJKcoidUjhckA_VS_110121_DGTL_Cloud-800x599.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/qtRE3pJTJKcoidUjhckA_VS_110121_DGTL_Cloud-640x480.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/qtRE3pJTJKcoidUjhckA_VS_110121_DGTL_Cloud.jpg 1280w\" sizes=\"(max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tEnabling the Edge: Cloud Capabilities Push Satellite Forward<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n<hr class=\"my-3 d-block d-md-none\">\n\t\t\t\t\t\t<!-- post id 405577:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img width=\"300\" height=\"225\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/y8FTELfCRkavj0FdfhD5_VS_110121_DGTL_5G-300x225.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/y8FTELfCRkavj0FdfhD5_VS_110121_DGTL_5G-300x225.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/y8FTELfCRkavj0FdfhD5_VS_110121_DGTL_5G-800x599.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/y8FTELfCRkavj0FdfhD5_VS_110121_DGTL_5G-640x480.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/y8FTELfCRkavj0FdfhD5_VS_110121_DGTL_5G.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tMassive Technical Leaps Push Satellite to the Fronthaul of 5G IoT<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n<hr class=\"my-3\">\n<p>\t\t\t\t\t<!-- post id 405571:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img width=\"300\" height=\"225\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/HMDwGE8QR9OaZOBOaSVr_VS_110121_DGTL_Ground_Station-300x225.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/HMDwGE8QR9OaZOBOaSVr_VS_110121_DGTL_Ground_Station-300x225.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/HMDwGE8QR9OaZOBOaSVr_VS_110121_DGTL_Ground_Station-800x599.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/HMDwGE8QR9OaZOBOaSVr_VS_110121_DGTL_Ground_Station-640x480.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/HMDwGE8QR9OaZOBOaSVr_VS_110121_DGTL_Ground_Station.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tRenting the Ground: The Growing Future of Ground Segment as a Service<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n<hr class=\"my-3 d-block d-md-none\">\n\t\t\t\t\t\t<!-- post id 405581:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img width=\"300\" height=\"300\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion-300x300.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion-300x300.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion-800x800.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion-150x150.jpg 150w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion-640x640.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/ydGVI94SmWTzrFvYVEog_Opinion.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tSpace Investment Has Moved Past Max-Q, Can it Continue to Ascend?<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n<hr class=\"my-3\">\n<p>\t\t\t\t\t<!-- post id 405566:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img width=\"300\" height=\"225\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/B7YvVc0bRiuB1pjNvCOr_YnHOFwQRQfeOfrAZ2iAA_VS_110121_DGTL_Steve-300x225.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/B7YvVc0bRiuB1pjNvCOr_YnHOFwQRQfeOfrAZ2iAA_VS_110121_DGTL_Steve-300x225.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/B7YvVc0bRiuB1pjNvCOr_YnHOFwQRQfeOfrAZ2iAA_VS_110121_DGTL_Steve-800x599.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/B7YvVc0bRiuB1pjNvCOr_YnHOFwQRQfeOfrAZ2iAA_VS_110121_DGTL_Steve-640x480.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/B7YvVc0bRiuB1pjNvCOr_YnHOFwQRQfeOfrAZ2iAA_VS_110121_DGTL_Steve.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tSteve Spengler Reflects on a Tumultuous Period for Intelsat<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n<hr class=\"my-3 d-block d-md-none\">\n\t\t\t\t\t\t<!-- post id 405587:  \/code\/wp-content\/themes\/ai-beehive\/template-parts\/content\/post-snippet.php --><\/p>\n<figure class=\"overflow-hidden w-100 me-3\">\n<p>\t<img width=\"300\" height=\"167\" src=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/0izsDkxOTXmxZxoADP7D_ED_Note-300x167.jpg\" class=\"img-responsive wp-post-image\" alt=\"\" style=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/0izsDkxOTXmxZxoADP7D_ED_Note-300x167.jpg 300w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/0izsDkxOTXmxZxoADP7D_ED_Note-800x446.jpg 800w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/0izsDkxOTXmxZxoADP7D_ED_Note-640x357.jpg 640w, https:\/\/www.satellitetoday.com\/wp-content\/uploads\/2026\/04\/0izsDkxOTXmxZxoADP7D_ED_Note.jpg 1280w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\">\t\t\t\t\t<\/figure>\n<h3 class=\"fs-4 w-100 line-clamp-3\">\n<p>\t\t\t\tTelco Deals Could Point to a Brighter Future<br \/>\n\t\t<\/h3>\n<p><!-- .post-snippet --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity remains one of the central topics when it comes to the space sector, not the least because of the role that satellite networks play in society, from satellite communications to Earth Observation (EO), to navigation. Nevertheless, few national space legislations have expressly addressed the need to meet cybersecurity requirements. One such case is the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":56434,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-56433","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/56433"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=56433"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/56433\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/56434"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=56433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=56433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=56433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}