EU Cyber Solidarity Act (Regulation (EU) 2025/38)
The EU Cyber Solidarity Act establishes a framework for EU-wide cybersecurity preparedness, detection, and response. It creates the European Cybersecurity Shield (network of national and cross-border Security Operations Centres), a Cybersecurity Emergency Mechanism for mutual assistance, and a European Cybersecurity Incident Review Mechanism. Entered into force February 2025.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (19)
Coordination
| Code | Title |
|---|---|
| CSA-COO-01 | ENISA and EU-CyCLONe Coordination |
Cyber Emergency Mechanism
| Code | Title |
|---|---|
| Art. 10 | Data and Data Governance |
| Art. 11 | Technical Documentation |
| Art. 12 | Record-Keeping |
| Art. 13 | Transparency and Provision of Information to Deployers |
| Art. 14 | Human Oversight |
| Art. 15 | Accuracy, Robustness and Cybersecurity |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 9 | Risk Management System |
Cyber Shield
| Code | Title |
|---|---|
| CSA-SOC-01 | Cross-Border SOC Participation |
| CSA-SOC-02 | National SOC Designation |
| CSA-SOC-03 | Detection and Analysis Tools |
Cybersecurity Emergency Mechanism
| Code | Title |
|---|---|
| CSA-EM-01 | Cybersecurity Emergency Mechanism Activation |
| CSA-EM-02 | Preparedness Actions |
| CSA-EM-03 | Incident Response Support |
Cybersecurity Incident Review
| Code | Title |
|---|---|
| Art. 18 | Documentation Keeping |
Cybersecurity Reserve
| Code | Title |
|---|---|
| CSA-RES-01 | Cybersecurity Reserve Onboarding |
| CSA-RES-02 | Reserve Service Levels |
| CSA-RES-03 | Trusted Provider Vetting |
European Cyber Shield
| Code | Title |
|---|---|
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
Evaluation
| Code | Title |
|---|---|
| CSA-EVA-01 | Evaluation and Review |
Final Provisions
| Code | Title |
|---|---|
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
General Objectives and Definitions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
Information Security
| Code | Title |
|---|---|
| CSA-CON-01 | Confidentiality and Classification |
Information Sharing
| Code | Title |
|---|---|
| CSA-INF-01 | Information Sharing Agreements |
International
| Code | Title |
|---|---|
| CSA-INT-01 | International Cooperation |
Mutual Assistance
| Code | Title |
|---|---|
| CSA-EM-04 | Mutual Technical Assistance |
Oversight
| Code | Title |
|---|---|
| CSA-OVS-01 | Oversight by Commission |
Performance
| Code | Title |
|---|---|
| CSA-SLA-01 | Service Level Reporting |
Preparedness
| Code | Title |
|---|---|
| CSA-EXE-01 | Cybersecurity Exercises |
Procurement
| Code | Title |
|---|---|
| CSA-PRO-01 | Procurement and Funding |
Review
| Code | Title |
|---|---|
| CSA-REV-01 | Incident Review Mechanism |
Your Compliance Coverage
If you comply with EU Cyber Solidarity Act (Regulation (EU) 2025/38), you already cover:
Australia Consumer Data Right — Banking (CDR)
29%
12 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
29%
12 controls mapped
Compare →Turkey Personal Data Protection Law (KVKK — Law No. 6698)
29%
12 controls mapped
Compare →+ 639 more: EU Digital Markets Act (29%), EU AI Act (29%)
See all 642 mapped frameworks ↓Maps to 642 other frameworks
Frequently Asked Questions
What is EU Cyber Solidarity Act (Regulation (EU) 2025/38)?
EU Cyber Solidarity Act (Regulation (EU) 2025/38) is a compliance framework from European Union with 19 domains and 42 controls. The EU Cyber Solidarity Act establishes a framework for EU-wide cybersecurity preparedness, detection, and response. It creates the European Cybersecurity Shield (network of national and cross-border Security Operations Centres), a Cybersecurity Emergency Mechanism for mutual assistance, and a European Cybersecurity Incident Review Mechanism. Entered into force February 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does EU Cyber Solidarity Act (Regulation (EU) 2025/38) have?
EU Cyber Solidarity Act (Regulation (EU) 2025/38) has 42 controls organised across 19 domains. The largest domains are Cyber Emergency Mechanism (9 controls), European Cyber Shield (6 controls), Final Provisions (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does EU Cyber Solidarity Act (Regulation (EU) 2025/38) map to?
EU Cyber Solidarity Act (Regulation (EU) 2025/38) maps to 642 other compliance frameworks. The top mapping partners are Australia Consumer Data Right — Banking (CDR) (29% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (29% coverage), Turkey Personal Data Protection Law (KVKK — Law No. 6698) (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with EU Cyber Solidarity Act (Regulation (EU) 2025/38) compliance?
Start your EU Cyber Solidarity Act (Regulation (EU) 2025/38) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU Cyber Solidarity Act (Regulation (EU) 2025/38) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.
Get Started Free →Free forever — no credit card required