The Council of the European Union (the Council) on May 17, 2021 agreed to prolong, for the second time, the sanctions framework concerning restrictive measures against cyber-attacks threatening the European Union (EU) or its Member States for another year, until May 18, 2022. The Council’s press release is available here.
Cyber sanctions are part of the EU cyber diplomacy toolbox and seek to prevent, discourage and respond to malicious cyber-attacks that have a significant impact on the EU. This framework was adopted in May 2019 under Council Decision (CFSP) 2019/797 and Council Regulation (EU) 2019/796, and is reviewed by the Council on a yearly basis. It allows the EU to sanction persons and entities deemed to be involved in major cyber-attacks threatening the EU or its Member States by imposing asset freezes or travel bans against those listed in the Council’s legal acts. The EU can also target those involved in attempted cyber-attacks with a potentially significant effect.