Ukraine Ukraine wartime cyber resilience

Ukraine Joins the EU's Cyber Reserve While Its Own Cyber Forces Law Sits Unvoted

Brussels gave Kyiv emergency EU cyber responders in June 2026; Ukraine's own Cyber Forces Command bill has waited five months for a floor vote.

Two Tracks of Ukraine's Cyber Defense People of Internet Research · Ukraine 2nd 2nd non-EU Reserve member Ukraine follows Moldova (2024) as … €36M EU Reserve three-year budget ENISA's contracted budget to run t… 255 First-reading vote, Cyber Forces bill Lawmakers who backed the Cyber For… ~5 mo. Months stalled at second reading Time since committee finalized the… peopleofinternet.com
Two Tracks of Ukraine's Cyber Defense People of Internet Research · Ukraine 2nd 2nd non-EU Reserve member €36M EU Reserve three-year budget 255 First-reading vote, Cyber Forc… ~5 mo. Months stalled at second reading peopleofinternet.com

Key Takeaways

A backstop arrives from Brussels

On 15–16 June 2026, the Council of the European Union approved Ukraine's inclusion in the EU Cybersecurity Reserve, the emergency-response pool established under the EU's Cyber Solidarity Act and run by the European Union Agency for Cybersecurity (ENISA). The mechanism lets a covered state, when a cyberattack on government systems, power grids, or other critical infrastructure exceeds its own response capacity, call in vetted private-sector incident-response teams contracted by ENISA. Ukraine becomes only the second non-EU country admitted, after Moldova in 2024, according to the European Commission's digital-strategy announcement and a matching notice from the EU's delegation in Kyiv.

The Reserve itself is not large. ENISA operates it on a €36 million contribution from the Digital Europe Programme spread over three years — a modest sum against the scale of Russian cyber operations Ukraine has absorbed since 2022, but the money buys something more valuable than its size suggests: pre-vetted, pre-contracted responders who can deploy without Ukraine having to negotiate terms mid-crisis. As Natalia Tkachuk, head of Ukraine's National Cybersecurity Coordination Center, put it, Ukraine is "becoming part of the EU's collective cyber defense mechanism even before obtaining formal EU membership," a framing The Record reported alongside Kyiv's stated hope that Ukrainian firms will eventually qualify as trusted providers themselves.

The case for caution, stated fairly

It's worth taking seriously why Ukraine's own Cyber Forces Command legislation has moved slowly rather than assuming inertia or indifference. Standing up a new military command with offensive cyber authority is not a paperwork exercise: lawmakers have had to define chain of command, personnel status for civilians and reservists operating outside normal conscription, and the boundary between the new Cyber Forces and existing agencies — the SBU, the State Service of Special Communications, and military intelligence — that already run cyber operations. Militarnyi reported that MP Oleksandr Fediienko has argued the bill is needed precisely because these institutions currently "compete" rather than coordinate — which is also the strongest argument for getting the legislative details right rather than rushing a vote on a bill that reorganizes wartime command authority. A mid-war restructuring of military cyber command, done carelessly, could degrade the very coordination it's meant to fix.

But five months is not deliberation, it's drift

That caution has limits, and Ukraine has passed them. The Verkhovna Rada approved the Cyber Forces bill in first reading on 9 October 2025 with 255 votes in favor, per the Kyiv Independent. The relevant committee — working with the Ministry of Defense, the General Staff, and military intelligence — finalized the text for second reading by late February 2026, according to UNN. As of this writing, nearly five months later, no floor vote has been scheduled. The substantive drafting work — the part that justifies deliberation — is done. What remains is a scheduling decision.

That gap matters because the EU Cybersecurity Reserve and a domestic Cyber Forces Command are not substitutes; they solve different problems. The Reserve is triage: it surges outside incident responders after an attack has already landed on government or critical-infrastructure networks. It has no mandate for offensive operations, intelligence-driven pre-emption, or the kind of standing military cyber capability — trained, funded, and integrated with NATO partners — that the stalled bill would create. Kyiv can now call in European help to clean up after a major breach. It still lacks the legally chartered command structure to run its own cyber operations, recruit and retain specialists under clear service terms, or coordinate the agencies Fediienko says are currently working at cross-purposes.

The proportionate path

The EU's move is a template worth crediting on its own terms: a narrowly scoped, modestly funded mechanism that extends cross-border capacity through contracted private expertise rather than new bureaucracy, and that reached a wartime partner without waiting for EU accession. That is proportionate, evidence-based cooperation — the kind this publication generally wants to see more of, not less.

Ukraine's parliament should extend the same discipline to its own legislation: not by cutting corners on a bill that restructures military command, but by scheduling the vote its own committee has already recommended. A finalized bill sitting unvoted for five months isn't caution — it's an unforced gap in wartime cyber governance that Brussels' backstop, however welcome, cannot fill.

Sources & Citations

  1. European Commission: EU provides cyber support to Ukraine
  2. EEAS: EU cyber support to Ukraine notice
  3. ENISA: EU Cybersecurity Reserve funding
  4. Kyiv Independent: Cyber Forces bill first reading
  5. The Record: Ukraine gains EU Cybersecurity Reserve access
  6. UNN: Cyber Forces bill finalized for second reading
  7. Militarnyi: EU Reserve access as Cyber Forces law stalls