The Complete Guide to EU Space Act Compliance
Guide to the proposed EU Space Act (COM(2025) 335, not in force) for space operators: scope, operator categories, authorisation procedure, timelines, the NIS2 link and preparation steps.
The EU Space Act (COM(2025) 335) is a proposed EU regulation — published by the European Commission in 2025 and not yet in force. It would, for the first time, establish a comprehensive, harmonized framework for authorizing and supervising space activities across the Union. This guide explains what it would require and how to prepare — while noting that the obligations binding operators today are NIS2, the EU Cyber Resilience Act, EU dual-use / export control, and national space laws.
Executive Summary
As proposed, the EU Space Act would create one framework for authorising and supervising space activities across the Member States. It would apply to four groups of space services providers — space operators, collision avoidance space services providers, primary providers of space-based data and international organisations (Art. 2(1)) — and would set technical rules on safety, resilience and environmental footprint (Title IV). Nothing in it binds operators before it is adopted; as proposed it would apply from 1 January 2030 (Art. 119).
Key facts (as proposed):
- 119 articles in seven Titles, plus ten Annexes
- Four types of space operator: spacecraft operators, launch operators, launch site operators and ISOS providers (Art. 5(16))
- Authorisation before providing space services (Art. 6(1)), issued in the Member State of establishment and recognised by the other Member States as regards Title IV (Art. 6(2)–(3))
- No application to assets launched before 1 January 2030 (Art. 2(3)(d)); for authorisations of assets planned to be launched after 1 January 2030 whose critical design review ended by a date linked to entry into force, application only from 1 January 2032 (Art. 118(1))
- Cybersecurity rules in Title IV, Chapter II (Art. 75–95), which for NIS2 entities would count as a sector-specific act regarding NIS2 Art. 21 (Art. 75(1))
Part 1: Understanding the Regulatory Landscape
Why the EU Space Act?
Space activities in the Union are governed today by national space laws that differ from one Member State to another. The proposal lays down rules for the internal market of space-based data and space services (Art. 1(1)) and harmonised rules on authorisation, registration and supervision, on collision avoidance services, on governance and enforcement, and on a Union Space Label (Art. 1(2)).
Relationship with National Laws
- Authorisation would be issued by the competent authority of the Member State of establishment and, where different, of the Member State where the applicant intends to operate or launch (Art. 6(3)); the other Member States would recognise it as regards Title IV (Art. 6(2))
- Each Member State would designate a competent authority and lay down the penalties (Art. 28, 31)
- The proposal contains no rules on operator insurance or third-party liability; these stay with national law and the Liability Convention (see Part 6)
- Assets used exclusively for defence or national security, the authorisation or management of radio spectrum, and assets launched before 1 January 2030 are outside its scope (Art. 2(3))
Relationship with International Law
The international treaties continue to apply:
- Outer Space Treaty (1967): State responsibility for national activities (Art. VI)
- Liability Convention (1972): liability of the launching State for damage
- Registration Convention (1976): registration of space objects
- ITU Radio Regulations: spectrum coordination; radio spectrum is excluded from the proposal (Art. 2(3)(c))
Part 2: Operator Categories and Scope
Who would be covered
The proposal would apply to four groups of space services providers (Art. 2(1)):
- Space operators (Art. 5(16)), which carry out at least one of four services:
- Collision avoidance space services providers (Art. 5(24))
- Primary providers of space-based data (Art. 5(22)), which initiate the first processing of space-based data
- International organisations (Art. 5(23))
A Union space operator is established in the Union or controlled by a space services provider established in the Union (Art. 5(17)). A third country space operator is established outside the Union and provides space services to Union space operators or in relation to the assets defined in Art. 5(20)–(21), acts itself as a primary provider of space-based data, or provides services to such providers (Art. 5(19)).
Constellations
A constellation has at least 10 and at most 99 operational spacecraft, a mega-constellation 100 to 999 and a giga-constellation at least 1,000 (Art. 5(3)–(5)). Operators of constellations would, among other things, have to ensure that each spacecraft has a propulsion system (Art. 73(1)(a)). One authorisation could cover all satellites of a constellation launch if they are identical, perform the same tasks and are launched with the same vehicle from the same site (Art. 9(1)).
Third-country operators
Third-country space operators would not be authorised but registered by the Agency in the Union Register of Space Objects (URSO), on the basis of a Commission decision (Art. 14, 17, 24), and would receive an e-certificate (Art. 25(1)). They would designate a legal representative in the Union (Art. 23) and meet the requirements listed in Art. 15.
Determining your category
Many operators fall into more than one category, for example a company that operates satellites and also provides in-space services. Map each activity to the definitions in Art. 5(16) and check the exclusions in Art. 2(3).
Part 3: Authorisation (as proposed)
Procedure
- Application to the competent authority (Art. 7(1)) with a technical file showing compliance with Title IV, Chapters I to V, as applicable (Art. 7(2))
- Technical assessment by a qualified technical body, an international organisation or the Agency, as the Member State decides (Art. 8(1)); a qualified technical body issues its opinion within 6 months of receiving the technical file (Art. 7(5))
- Decision within 12 months of receipt of the application; the deadline is suspended while information requested by the authority is missing (Art. 7(6))
- Registration: the competent authority informs the Agency for registration in URSO (Art. 7(7)); the Agency issues an e-certificate (Art. 25(1))
Which authority
The competent authority of the Member State in which the applicant is established and, where different, of the Member State in which it intends to operate or launch (Art. 6(3)).
Light regimes
Article 10 adapts the conditions for three cases: research or education institutions and research missions (Art. 10(2), with Art. 62); entities applying a simplified risk management (Art. 10(3)); and IOD/IOV missions of small enterprises or of research or education institutions, which would be exempted from the environmental footprint obligation of Art. 96(2) (Art. 10(4)). The proposal sets no thresholds by mass, mission duration or altitude.
Part 4: Safety and Sustainability (Title IV, Chapter I)
Space debris mitigation
- Spacecraft operators would have to limit debris generation and the risk of fragmentation, complete end-of-life disposal and draw up a debris control plan, an end-of-life disposal plan and a failure response plan (Art. 70(1)–(2), Annex V); launch operators have parallel rules (Art. 61, Annex II)
- LEO: the maximum orbital lifetime after the end of the mission would be set by an implementing act (Annex V point 3.4.2); controlled re-entry comes first in the order of preference for removal (Annex V point 3.3)
- GEO: removal to an orbit not interfering with protected regions and valuable orbits within 100 years after end of life (Annex V point 3.7)
- Re-entry: design for demise as one step to minimise casualty risk (Annex V point 3.5.1); the maximum probability of casualties would be specified in an implementing act (Annex V point 3.5.4)
Collision avoidance and trackability
- Spacecraft would need technical means allowing trackability and precise orbit determination (Art. 63)
- Spacecraft operators would subscribe to the collision avoidance services of the Union CA space services provider for all mission phases except re-entry (Art. 64(1)–(2)) and inform it of planned and unplanned changes (Art. 64(3))
- Spacecraft in orbits with an apogee above 400 km would need manoeuvrability (Art. 66(1))
Part 5: Cybersecurity
Relationship with NIS2
For Union space operators that are essential or important entities under NIS2 Art. 3, the proposal would count as a sector-specific Union legal act regarding NIS2 Art. 21 (Art. 75(1)). NIS2 itself is in force; its space sector covers operators of ground-based infrastructure that support the provision of space-based services, excluding providers of public electronic communications networks (NIS2 Annex I, point 11).
NIS2 obligations that apply today
Fines (NIS2 Art. 34): for infringements of Art. 21 or 23, maximum fines of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher, for essential entities (Art. 34(4)); at least EUR 7 million or 1.4% for important entities (Art. 34(5)).
Supervision: essential entities can be subject to on-site inspections, off-site supervision and regular and targeted security audits (Art. 32(2)); important entities are supervised ex post, when there is evidence of non-compliance (Art. 33(1)).
Risk-management measures (NIS2 Art. 21(2))
- Policies on risk analysis and information system security
- Incident handling
- Business continuity, such as backup management and disaster recovery, and crisis management
- Supply chain security
- Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of the measures
- Basic cyber hygiene practices and cybersecurity training
- Cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- Multi-factor or continuous authentication, secured voice, video and text communications and secured emergency communication systems, where appropriate
Incident Reporting (NIS2 Art. 23(4))
For significant incidents:
- 24 hours after becoming aware: early warning
- 72 hours after becoming aware: incident notification
- One month after the incident notification: final report
Under the proposal, Union space operators would report significant incidents through the NIS2 channels where they are NIS2 entities (Art. 93(3)).
Space-Specific Considerations
Space systems face unique cybersecurity challenges:
- Command link security
- Telemetry protection
- Ground station security
- Software update integrity
- Supply chain attacks
Part 6: Insurance and Liability
The proposal contains no insurance or third-party liability duty for space operators. In its articles, the word "insurance" appears only in Art. 88(3), which requires external testers carrying out threat-led penetration testing to hold professional indemnity insurance; in the Annexes, Annex IX point 1.11 requires qualified technical bodies to hold liability insurance for their assessment activities.
Operator insurance and liability therefore come from national law and the Liability Convention. Examples:
| Jurisdiction | Insurance or financial guarantee | Source |
|---|---|
| France | Insurance or approved financial guarantee up to the amount fixed in the authorisation, within EUR 50–70 million; State guarantee above that amount under the conditions of LOS Art. 15 |
Check the national rules that govern your authorisation.
Part 7: Supervision and Enforcement (as proposed)
Competent authorities
Each Member State would designate or establish a competent authority for authorisation and supervision (Art. 28(1)). Its tasks would include controlling the application of the Regulation, investigations and audits (Art. 29(1)); its powers would include requiring documents, access to premises and on-site and off-site inspections (Art. 30(3)). For the cybersecurity chapter it would coordinate with the NIS2 authorities (Art. 30(2)).
Penalties
Member States would lay down the penalties for infringements (Art. 31(1)). For third-country space operators, international organisations and operators of Union-owned assets supervised at Union level (Art. 48(1)), the Commission could impose fines on a proposal from the Agency, up to twice the profits gained or losses avoided or, where these cannot be determined, 2% of worldwide annual turnover (Art. 56(1), (3)).
The Agency
The EU Agency for the Space Programme established under Regulation (EU) 2021/696 ("the Agency", Art. 5(73)) would carry out technical assessments for Commission decisions, register third-country operators and international organisations, set up and manage URSO and issue e-certificates (Art. 40(1)(a)–(f)).
Part 8: Preparation Roadmap
The phases below are planning assumptions, not legal deadlines.
Phase 1: Assessment (Months 1-3)
- Map your activities to Art. 2 and Art. 5(16)
- Identify the competent authority (Art. 6(3))
- Map current status against the Title IV requirements
- Identify compliance gaps
- Estimate resource needs
Phase 2: Planning (Months 4-6)
- Develop a compliance timeline
- Assign responsibilities
- Budget for implementation
- Follow the legislative process — the text may still change
- Check the insurance rules of the national law that governs your authorisation
Phase 3: Implementation (Months 7-18)
- Implement technical measures
- Develop documentation
- Deploy cybersecurity controls
- Establish reporting systems
- Train personnel
Phase 4: Authorisation
- Prepare the technical file (Art. 7(2))
- Choose the qualified technical bodies (Art. 7(3))
- Respond to questions from the authority
- Arrange insurance where national law requires it
- Receive the authorisation
Phase 5: Operations (Ongoing)
- Maintain compliance
- Submit required reports
- Update documentation
- Respond to changes
- Prepare for audits
Key Takeaways
- It is a proposal: nothing applies before adoption; as proposed, from 1 January 2030 (Art. 119)
- Know your category: Art. 2(1) and Art. 5(16) determine which obligations would apply
- Plan for the procedure: 6 months for the technical assessment and 12 months for the decision (Art. 7(5)–(6))
- Address cybersecurity now: NIS2 already applies to operators of ground-based space infrastructure (Annex I, point 11)
- Plan for debris: the maximum LEO lifetime would be set by an implementing act (Annex V point 3.4.2)
- Insurance is national: amounts and forms come from national law
- Document everything: the technical file has to evidence compliance (Art. 7(2))
How Caelex Helps
Caelex supports preparation for the EU Space Act proposal and the national laws:
- Assessment: Determine your category and gaps
- Compliance Tracking: Track requirements of the proposal and of national law
- Document Generation: Draft authorisation documents
- Deadline Management: Track regulatory milestones
- Expert Guidance: AI-assisted answers to compliance questions
Start your free assessment today. Software is not legal advice.
Next step
Run the structured assessment for a map of obligation clusters. Software is not legal advice. EU Space Act remains proposal COM(2025) 335.