EU tech sovereignty package extends cyber and supply chain resilience rules to critical infrastructure entities under NIS2-adjacent framework
The European Commission published a package of legislative and policy measures on 3 June 2026 under the banner of a tech sovereignty initiative, with detailed analysis of the package's scope emerging this week. The package addresses two broad categories: laws promoting cyber resilience to protect against malicious actors disrupting services and critical infrastructure, and laws aimed at building supply chain resilience by reducing dependencies on external actors and developing European industrial capacity in key technology sectors. The resilience obligations under the package apply to entities in sectors already covered by NIS2 (the EU's Network and Information Security Directive 2), provided they are also expressly designated by their Member State as critical entities. Those designated entities must implement measures ensuring resilience against a broad range of incident types, including cyber attacks, natural hazards such as extreme weather, physical threats such as vandalism or insider threats, and technical and operational failures. This goes beyond the purely cyber-focused obligations of NIS2 itself. A related legislative component is the Cloud and AI Development Act, one of the specific instruments within the broader package. The package reflects the Commission's drive to reduce European exposure to concentrated dependencies in cloud computing and semiconductor supply chains, with direct implications for technology procurement, data hosting arrangements, and supply chain due diligence obligations across the EU's critical sectors. UK-based operators with EU market exposure will need to assess whether their designated-entity status triggers compliance obligations under the new framework.
Why this matters
The tech sovereignty package creates a new layer of regulatory obligations that sits alongside NIS2 for the most sensitive critical infrastructure operators across the EU. For commercial lawyers, the key implication is that technology contracts (cloud hosting agreements, data processing arrangements, and software supply agreements) used by designated critical entities will need to be reviewed against the new resilience requirements, particularly clauses governing incident response, business continuity, and supply chain transparency. The dual focus on cyber resilience and supply chain diversification means that procurement lawyers and regulatory specialists will both be engaged. UK firms advising clients with EU operations or EU-facing digital infrastructure need to track whether the Commission's implementing measures, expected to flow from the package, create direct compliance obligations or trigger notification duties.
On the Ground
A trainee on a tech sovereignty compliance matter would assist with summarising the regulatory filing coordination requirements under the new framework, review technology transfer and cloud service agreements to flag provisions that may need updating, and draft a compliance gap analysis memo comparing the client's existing NIS2 obligations against the additional requirements imposed on designated critical entities.
Interview prep
Question you might get
“How does the EU tech sovereignty package interact with NIS2, and what does this mean for a technology company advising clients who operate critical infrastructure across the EU?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeMy notes
saved