At the end of January 2026, the European Commission introduced a new cybersecurity package further to strengthen the EU’s cybersecurity resilience and capabilities.
The package includes a proposal for a revised Cybersecurity Act[1], which enhances the security of the EU’s Information and Communication Technologies (ICT) supply chains, and a proposal to amend the NIS2 Directive (Directive (EU) 2022/2555)[2].
While IWT is not explicitly mentioned in this package, it nevertheless falls within the scope of the EU’s critical sectors, which are defined under the NIS2 Directive. Transport, Digital Infrastructure and ICT Service Management (B2B), in accordance with the Directive, are sectors of critical importance for society and the economy, and those that therefore face stricter regulatory requirements.
A main objective of the package is to reduce risks in the EU’s ICT supply chain from third-country suppliers. For IWT developments, in case of third-country hardware or software (e.g., vessel tracking systems, port terminal operating systems, hydrographic survey and pilotage equipment and software, etc.), the new requirements will be introduced. In addition, the package introduces a renewed European Cybersecurity Certification Framework (ECCF) and harmonized security standards for digital products, services, and processes, enabling standardized certification valid across the EU.
With regards to the cybersecurity topic, it is important to mention that in 2023, CESNI[3], in cooperation with EFIP[4] published a good practice guide[5] on cybersecurity in inland navigation, focusing on ports. This guide provides an overview of cybersecurity risks, threats, and mitigation measures, primarily within the scope of inland navigation ports. This guide also gives an overview of good practices for the implementation of cybersecurity risk mitigation measures.
At the last meeting, in Budapest, in March 2026, CESNI TI discussed the European Cyber Resilience Act[6], its impact on inland navigation, especially on equipment manufacturers, and steps to be taken regarding its implementation within the CCNR. The CRA aims to introduce minimum cybersecurity requirements for all products with digital elements marketed in the EU and whose use involves connection to a device or network. Therefore, this means the CRA requirements apply to a wide range of connected products, including equipment used in inland navigation. The CRA was adopted on 23 October 2024 and will enter into full force on 11 December 2027. However, certain parts will enter into force earlier, on 11 June and 11 September 2026.


