A backstop arrives from Brussels
On 15–16 June 2026, the Council of the European Union approved Ukraine's inclusion in the EU Cybersecurity Reserve, the emergency-response pool established under the EU's Cyber Solidarity Act and run by the European Union Agency for Cybersecurity (ENISA). The mechanism lets a covered state, when a cyberattack on government systems, power grids, or other critical infrastructure exceeds its own response capacity, call in vetted private-sector incident-response teams contracted by ENISA. Ukraine becomes only the second non-EU country admitted, after Moldova in 2024, according to the European Commission's digital-strategy announcement and a matching notice from the EU's delegation in Kyiv.
The Reserve itself is not large. ENISA operates it on a €36 million contribution from the Digital Europe Programme spread over three years — a modest sum against the scale of Russian cyber operations Ukraine has absorbed since 2022, but the money buys something more valuable than its size suggests: pre-vetted, pre-contracted responders who can deploy without Ukraine having to negotiate terms mid-crisis. As Natalia Tkachuk, head of Ukraine's National Cybersecurity Coordination Center, put it, Ukraine is "becoming part of the EU's collective cyber defense mechanism even before obtaining formal EU membership," a framing The Record reported alongside Kyiv's stated hope that Ukrainian firms will eventually qualify as trusted providers themselves.
The case for caution, stated fairly
It's worth taking seriously why Ukraine's own Cyber Forces Command legislation has moved slowly rather than assuming inertia or indifference. Standing up a new military command with offensive cyber authority is not a paperwork exercise: lawmakers have had to define chain of command, personnel status for civilians and reservists operating outside normal conscription, and the boundary between the new Cyber Forces and existing agencies — the SBU, the State Service of Special Communications, and military intelligence — that already run cyber operations. Militarnyi reported that MP Oleksandr Fediienko has argued the bill is needed precisely because these institutions currently "compete" rather than coordinate — which is also the strongest argument for getting the legislative details right rather than rushing a vote on a bill that reorganizes wartime command authority. A mid-war restructuring of military cyber command, done carelessly, could degrade the very coordination it's meant to fix.
But five months is not deliberation, it's drift
That caution has limits, and Ukraine has passed them. The Verkhovna Rada approved the Cyber Forces bill in first reading on 9 October 2025 with 255 votes in favor, per the Kyiv Independent. The relevant committee — working with the Ministry of Defense, the General Staff, and military intelligence — finalized the text for second reading by late February 2026, according to UNN. As of this writing, nearly five months later, no floor vote has been scheduled. The substantive drafting work — the part that justifies deliberation — is done. What remains is a scheduling decision.
That gap matters because the EU Cybersecurity Reserve and a domestic Cyber Forces Command are not substitutes; they solve different problems. The Reserve is triage: it surges outside incident responders after an attack has already landed on government or critical-infrastructure networks. It has no mandate for offensive operations, intelligence-driven pre-emption, or the kind of standing military cyber capability — trained, funded, and integrated with NATO partners — that the stalled bill would create. Kyiv can now call in European help to clean up after a major breach. It still lacks the legally chartered command structure to run its own cyber operations, recruit and retain specialists under clear service terms, or coordinate the agencies Fediienko says are currently working at cross-purposes.
The proportionate path
The EU's move is a template worth crediting on its own terms: a narrowly scoped, modestly funded mechanism that extends cross-border capacity through contracted private expertise rather than new bureaucracy, and that reached a wartime partner without waiting for EU accession. That is proportionate, evidence-based cooperation — the kind this publication generally wants to see more of, not less.
Ukraine's parliament should extend the same discipline to its own legislation: not by cutting corners on a bill that restructures military command, but by scheduling the vote its own committee has already recommended. A finalized bill sitting unvoted for five months isn't caution — it's an unforced gap in wartime cyber governance that Brussels' backstop, however welcome, cannot fill.