eu-space-act

Art. 92(2)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (6)

Techniques referencing this article

  • DE-0012Component CollusionST0006
    addresses
    moderate
    inferred

    Art. 92(2)'s supply-chain-risk-strategy obligation is domain-relevant to colluding components, but the cited strategy mandate names no interdicting mechanism; component-provenance verification would be the interdiction.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    direct

    92(2)'s strategy-to-reduce-risks-in-the-supply-chain (with Annex VII point 6 measures) directly targets the supply-chain insertion paths IA-0001 enumerates.

  • Adversaries renting commercial ground-station-as-a-service is mostly outside the operator's control, but 92(2)'s supply-chain risk-reduction strategy includes governance over the operator's own commercial-GSaaS providers — preventing adversary misuse of the operator's contracted ground assets.

  • 92(2)'s strategy-to-reduce-risks-in-the-supply-chain obligation (with measures from Annex VII point 6) is directly aimed at the supply-chain attack surface that REC-0008 enumerates.

  • REC-0008.01Hardware ReconST0001
    addresses
    moderate
    inferred

    Art. 92(2)'s supply-chain risk-reduction strategy is domain-relevant to hardware-supplier reconnaissance, but names no mechanism interdicting the information-gathering.

  • REC-0008.02Software ReconST0001
    addresses
    moderate
    inferred

    Art. 92(2)'s supply-chain risk-reduction strategy is domain-relevant to software-factory reconnaissance, but names no mechanism interdicting the information-gathering.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.