As of 1 October 2026. Information only, not legal advice – see the disclaimer.
| Full title | EU restrictive measures against cyber-attacks threatening the Union or its Member States (Council Decision (CFSP) 2019/797 and Council Regulation (EU) 2019/796) and the Cyber Diplomacy Toolbox |
|---|---|
| Type | EU Council decision (CFSP) and Council regulation; Council conclusions (toolbox) |
| Adopted by | Council of the European Union |
| Adopted | 17 May 2019 (sanctions framework); June 2017 (Cyber Diplomacy Toolbox) |
| Legal status | Framework in force; renewed until 18 May 2028; individual listings renewed until 18 May 2027; binding (Regulation directly applicable; Decision binding on Member States) |
| Official text | EUR-Lex (Decision (CFSP) 2019/797) · EUR-Lex (Regulation (EU) 2019/796) |
| Subject area | Use of force, intervention and cyber operations |
The regime is a horizontal EU sanctions framework allowing the Council to impose targeted restrictive measures – asset freezes, a prohibition on making funds available and, for natural persons, travel bans – on persons and entities responsible for, or involved in, cyber-attacks or attempted cyber-attacks with a significant effect that constitute an external threat to the Union or its Member States. Measures may also be applied in response to cyber-attacks against third States or international organisations where necessary to achieve CFSP objectives. The regime is one instrument of the “Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities” (Cyber Diplomacy Toolbox), established in June 2017, which comprises preventive, cooperative, stabilising and restrictive measures. Listings are adopted by unanimity and reviewed annually.
Listing history according to the Council: