LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:cyber_sanctions

This is an old revision of the document!


EU cyber sanctions regime (2019)

As of 1 October 2026.

Full title EU restrictive measures against cyber-attacks threatening the Union or its Member States (Council Decision (CFSP) 2019/797 and Council Regulation (EU) 2019/796) and the Cyber Diplomacy Toolbox
Type EU Council decision (CFSP) and Council regulation; Council conclusions (toolbox)
Adopted by Council of the European Union
Adopted 17 May 2019 (sanctions framework); June 2017 (Cyber Diplomacy Toolbox)
Legal status Framework in force; renewed until 18 May 2028; individual listings renewed until 18 May 2027; binding (Regulation directly applicable; Decision binding on Member States)
Official text EUR-Lex (Decision (CFSP) 2019/797) · EUR-Lex (Regulation (EU) 2019/796)
Subject area Use of force, intervention and cyber operations

Overview

The regime is a horizontal EU sanctions framework allowing the Council to impose targeted restrictive measures – asset freezes, a prohibition on making funds available and, for natural persons, travel bans – on persons and entities responsible for, or involved in, cyber-attacks or attempted cyber-attacks with a significant effect that constitute an external threat to the Union or its Member States. Measures may also be applied in response to cyber-attacks against third States or international organisations where necessary to achieve CFSP objectives. The regime is one instrument of the “Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities” (Cyber Diplomacy Toolbox), established in June 2017, which comprises preventive, cooperative, stabilising and restrictive measures. Listings are adopted by unanimity and reviewed annually.

Provisions relevant to the cyber and information sphere

  • Decision (CFSP) 2019/797, Art. 1 – Scope: cyber-attacks with a potentially significant effect, including attempted attacks, involving access to or interference with information systems, data interference or data interception, originating or carried out from outside the Union or using infrastructure outside the Union, among other criteria.
  • Decision (CFSP) 2019/797, Arts. 4–5; Regulation (EU) 2019/796, Art. 3 – Travel bans and asset freezes against listed natural and legal persons, entities or bodies.
  • Regulation (EU) 2019/796, Annex I – List of designated persons and entities.

Application to cyber and information operations

Listing history according to the Council:

  • 2020-07-30: First listings – six individuals and three entities (the Council referred to the attempted attack against the OPCW, “WannaCry”, “NotPetya” and “Operation Cloud Hopper”).
  • 2020-10-22: Two individuals and one entity listed in connection with the 2015 cyber-attack on the German Bundestag.
  • 2024-06-24: Six individuals listed (the Council referred to the groups “Callisto”, “Armageddon” and “Wizard Spider”).
  • 2025-01-27: Three GRU officers listed in connection with cyber-attacks against Estonia.
  • 2026-03-16: Three entities and two individuals listed (entities based in China and Iran); according to the Council, the regime then applied to 19 individuals and 7 entities.
  • 2026-07-13: Eight individuals and four entities described by the Council as part of Russia's cyber ecosystem listed under the cyber regime (Council Decision (CFSP) 2026/1713, Implementing Regulation (EU) 2026/1714), together with one individual listed under the separate regime for Russia's destabilising activities (Council Decision (CFSP) 2026/1707).

Recent developments

  • 2025-05-12: Council extends the legal framework until 18 May 2028 (Council of the EU).
  • 2026-03-16: New listings (Council of the EU).
  • 2026-05-11: Council extends listings until 18 May 2027 (Council of the EU).
  • 2026-07-13: New listings (Council of the EU).

Sources

Change log

  • 2026-09-27: Entry created (draft).
  • 2026-09-30: Entry reviewed and finalised.
  • 2026-10-01: Link to the regime on Russia's destabilising activities added.
law/eu/cyber_sanctions.1790853678.txt.gz · Last modified: by lfpo