The European Union’s draft Space Act would force satellite operators selling services into EU markets, regardless of where the company is headquartered, to report a significant cyberattack within 12 hours of detecting it. The timeline is tighter than the 24-hour standard imposed on power grids and hospitals under the NIS2 directive.
The resilience chapter, spanning Articles 75 through 95, is designated as lex specialis, meaning it takes precedence over NIS2 for space operators rather than stacking on top of it. Article 88 introduces mandatory threat-led penetration testing, requiring operators to have systems tested by accredited assessors before launch and at least once every three years afterward.
Article 93 sets the incident-reporting clock and layers it on top of parallel duties to notify the EU Agency for the Space Programme and national authorities.
EU officials point to the 2022 Viasat KA-SAT hack as the driving case behind the reporting rules. Russian-linked wiper malware knocked out modem connectivity across Europe hours before the invasion of Ukraine, disrupting military communications and knocking roughly 5,800 German wind turbines offline.
The market-access standard has drawn criticism from Washington. The State Department submitted formal comments in November 2025 calling the draft discriminatory and warning it could complicate cooperation with ESA and EUMETSAT on weather data and spaceflight safety.
The regulation remains under debate ahead of a Council vote, with industry pushing back on the 12-hour timeline as too aggressive for the complexity of space incident response.