Skip to main content
Skip to main content
Back to Glossary
Cybersecurity

Cybersecurity Assessment

A systematic evaluation of a space system's security posture against cyber threats; NIS2 requires risk-management measures for in-scope entities, and the EU Space Act proposal (COM(2025) 335) would require risk assessments for Union space operators (Art. 78).

Cybersecurity assessment evaluates the security of space systems against cyber threats. NIS2 requires in-scope entities to take risk-management measures, including policies on risk analysis (Art. 21(2)(a)); the EU Space Act proposal (COM(2025) 335, not in force) would require Union space operators to identify and assess risks throughout the mission life cycle (Art. 78).

Assessment Scope

  • Ground segment (mission control, data centers)
  • Space segment (spacecraft, payloads)
  • User segment (terminals, applications)
  • Link segment (communications)
  • Supply chain (components, software)

Framework Alignment Assessments typically align with:

  • NIS2 Article 21 measures
  • NIST Cybersecurity Framework
  • ISO 27001
  • ECSS-E-ST-80C (space-specific)

Key Evaluation Areas

  1. Risk management processes
  1. Incident detection and response
  1. Access control and authentication
  1. Encryption and key management
  1. Supply chain security
  1. Physical security
  1. Business continuity

Reporting Requirements

  • Self-assessment documentation
  • Third-party audit (for essential entities)
  • Continuous monitoring evidence
  • Incident history and lessons learned

Frequency

  • Initial assessment before authorization
  • Periodic reassessment (typically annual)
  • Triggered reassessment after significant changes

Cybersecurity Assessment - Definition | Space Compliance Glossary | Caelex — Regulatory OS for the orbital economy