Design auctions involving control systems, SCADA, remote access systems or firewalls so that suppliers identified as 'high-risk' under the future Cyber Security Act instrument are excluded from supply, design, management or software-update processes.
Member States designing net-zero technology auctions must comply, and this is not law yet.
Why it matters
This is a Commission proposal: it is not law yet, and it can change before it is.
- It is Art. 34(5)(b) (amended Art. 26(1)(a)(iv) of Regulation (EU) 2024/1735), in the Industrial Accelerator Act. as of 2026-08-17
- The act gives its timing as: From entry into force. as of 2026-08-17
- It names 2 industries by name: Power and Clean tech. as of 2026-08-17
- Compliance is checked by competent authority, per auction. as of 2026-08-17
The rule
Auction includes control systems/SCADA/remote access systems/firewalls
Design auctions involving control systems, SCADA, remote access systems or firewalls so that suppliers identified as 'high-risk' under the future Cyber Security Act instrument are excluded from supply, design, management or software-update processes.
Who is affected
Burden drivers
Source text
iv) high-risk suppliers as defined in Article 2 point (39) of Regulation xxxx/xxxx [CSA2]: For auctions that include control systems, management control systems, supervisory control and data acquisition systems, remote access systems or firewalls, suppliers identified as high- risk suppliers in accordance with Regulation xxxx/xxxx [CSA2]shall not be involved in the following processes:
View source →Settled later in secondary legislation. References Regulation xxxx/xxxx [CSA2], which is not yet adopted/numbered.