What actually binds space operators in 2026
While the EU Space Act remains a proposal, operators still face NIS2, national space laws, export control, spectrum, and the Cyber Resilience Act. A map of what is law today versus what is still legislative text.
The EU Space Act (COM(2025) 335) is a European Commission proposal. It is not in force. What binds operators today includes NIS2, national space laws, dual-use and export-control rules, spectrum/ITU coordination, and — where a product is in scope — the EU Cyber Resilience Act.
Caelex is software for compliance workflows and legal research. This article is not legal advice and does not replace licensed counsel.
A lot of 2025 commentary treated COM(2025) 335 as if it had already replaced national space law. It has not. Preparing for the proposal is rational. Citing it as current authorization law is not.
What is law today
NIS2 (Directive (EU) 2022/2555). Space is in the NIS2 picture. Classification as essential or important, risk-management measures, supply-chain security, and incident reporting are live transposition questions for operators and their counsel — not a 2030 problem.
National space laws. Authorization, supervision, insurance, and registration still run through national competent authorities. France (LOS), Germany (including SatDSiG for satellite data), Luxembourg, Italy, and others did not pause because a Commission proposal exists. The UK Space Industry Act is a separate post-Brexit regime.
Export control. Dual-use (EU Dual-Use Regulation), national military lists, US ITAR/EAR for US-origin items, and destination screening are shipment-by-shipment legal acts. Software can classify and document. It cannot grant a licence.
Spectrum / ITU. Frequency assignments, coordination, and filing clocks do not wait for the Space Act. Missing an ITU milestone is an operational failure, not a “we’ll catch it at NCA authorization” item.
Cyber Resilience Act. Where a space product is in CRA scope, product-security obligations attach to placing products on the Union market. That is a different axis from operator authorization.
What the proposal would add
COM(2025) 335 would, if adopted as proposed, layer Union-level authorization and supervision categories (spacecraft operators, launch, in-space services, collision-avoidance providers, positional-data providers, third-country operators serving the Union). Debris, cyber, and environmental modules in the proposal are draft architecture, not present-tense duties.
Council (December 2025) and Parliament (March 2026) amendment tracks may still be open. Do not freeze a 2025 blog post as the final article numbering.
How to prepare without pretending
1. Inventory what you already need under NIS2, national authorization, insurance, and export control. 2. Map the proposal’s operator categories as a scenario, not as a licence you hold. 3. Keep evidence that will still matter under any likely final text: debris mitigation design, cyber risk management, incident logs, insurance certificates, registration filings. 4. Have counsel own legal determinations. Software can assemble the file.
Caelex is currently in pilot operation.
Start with a structured assessment if you want a machine-readable map of clusters — then have a lawyer read the result.
Next step
Run the structured assessment for a map of obligation clusters, or book a walkthrough. The result is a file to review with counsel — not a licence and not legal advice.