A Legal Door, Not a Standing Army
On 15 June 2026 the Council of the EU adopted Implementing Decision (EU) 2026/1354, authorising support from the EU Cybersecurity Reserve to Ukraine under Article 19(4) of Regulation (EU) 2025/38 — the Cyber Solidarity Act. The decision runs for one year, until 17 June 2027, and lets Kyiv activate ENISA-vetted private incident-response firms during "significant" or "large-scale" cyberattacks, the same trigger language used for EU member states themselves.
Executive Vice-President Henna Virkkunen framed it as solidarity: "By welcoming Ukraine into the EU Cybersecurity Reserve, we strengthen our collective defences and reaffirm the principle of solidarity that lies at the heart of Europe's digital future," the European Commission said. Ukraine is only the second non-member state admitted, after Moldova joined in 2024 — a sequencing that tracks the two countries' EU candidacy timelines as much as their threat exposure.
The Case For Treating This as Real Capacity
The steelman is straightforward. Ukraine has spent four years as the most heavily cyber-targeted state on earth, and its own CSIRT capacity, however battle-hardened, is finite. The Cyber Solidarity Act's Reserve model — pre-vetted managed security providers on call rather than ad hoc crisis contracting — is exactly the kind of standing mechanism that's useless if you have to build it while the fire is already burning. Folding Ukraine into the same activation framework used by member states also has a legal function beyond incident response: it treats Ukraine's cybersecurity posture as fungible with the EU's own, reinforcing the Digital Europe Programme association agreement that is itself a step toward accession. And unlike a grant or a donation, Reserve access comes with ENISA's ownership-control vetting on providers — a real assurance against a nominally private contractor with hidden foreign-state ties showing up inside Ukrainian critical infrastructure during a crisis.
Why the Number Undersells the Announcement
The catch is scale. ENISA's contribution agreement with the Commission funds the entire Reserve — covering all 27 member states, EU institutions, and now Moldova and Ukraine — at €36 million over three years. That is a shared, EU-wide incident-response pool, not a dedicated Ukraine fund, and it sits alongside ENISA's own €26.9 million annual operating budget — this is emergency surge capacity, not standing infrastructure spend. Set against the war, the mismatch is stark: Russian strikes have cut Ukraine's dispatchable power capacity from roughly 38 GW before the invasion to about 14 GW in 2026, and Ukrainian officials now describe cyber intrusions on energy infrastructure as reconnaissance for missile targeting rather than standalone disruption — Sandworm mapping facilities and repair-crew movements to calibrate strikes, according to Natalia Tkachuk of Ukraine's National Security and Defense Council. A pool sized for peacetime NIS2 incident response across dozens of countries was not built with that adversary in mind, and nothing in the June decision changes the pool's size — it only adds a claimant.
There's a second, more structural limit: activation still runs through the same Article 19 process used for member states, meaning Ukraine competes for the same finite roster of trusted providers during any period when multiple countries are hit simultaneously — a scenario Russian hybrid operations have shown a clear interest in engineering. The Reserve's own service catalogue treats unused incident-response allocations as convertible into "preparedness services," a sensible efficiency measure in calm years that becomes a rationing question in a year when Ukraine's grid is being hit as intelligence-gathering support for missile strikes on a near-daily cadence.
The Right Call, Undersized for the Moment
None of this argues against the decision — extending the same legal instrument the EU uses to protect its own members to a country absorbing the bulk of Europe's actual cyberwar exposure is proportionate, not indulgent, regulation. Providers still have to pass ownership-control vetting, activation still runs through ENISA rather than ad hoc bilateral deals, and the one-year renewal clock (expiring 17 June 2027) gives the Council a natural checkpoint to scale the mechanism rather than lock in an under-resourced status quo. But Brussels should be honest with itself about what it has actually built: a legal door Ukraine can now walk through, opening onto a room sized for ordinary member-state incidents. If the Council wants the Reserve to matter the next time Sandworm times a cyber intrusion to a missile barrage, the renewal in 2027 is the moment to fund it like the wartime tool it now formally is — not just the peacetime one it was designed as.