Key data
| Regulation | Corrigendum to Council Decision (CFSP) 2026/1713, which amends Decision (CFSP) 2019/797 |
|---|---|
| Publication | 30 July 2026 |
| Entry into force | 13 July 2026 (date of the original corrected Decision) |
| Affected parties | Entities obliged to comply with EU sanctions and persons or entities sanctioned for cyberattacks |
| Category | European Regulation — Common Foreign and Security Policy (CFSP) |
| Year | 2026 |
| Source regulation | Decision (CFSP) 2019/797 — EU sanctions regime against cyberattacks, in force since 2019 |
Companies with international sanctions compliance programs have a concrete task following the publication of this correction: confirm that the version of Decision (CFSP) 2026/1713 they handle internally is the corrected one, published on 30 July 2026 in the EU Official Journal. The correction does not introduce new sanctioned parties nor does it modify the substantive restrictive measures, but it does remedy formal errors in the text of the regulation that modified the European sanctions regime against cyberattacks originally established in 2019.
The EU's sanctions framework against cyberattacks, in force since Decision (CFSP) 2019/797, allows the Council to impose travel bans and asset freezes on natural and legal persons responsible for significant cyberattacks against the EU or its Member States. Decision (CFSP) 2026/1713, of 13 July 2026, amended that regime; this corrigendum remedies technical defects in that amendment without altering its content.
What does this regulation establish?
The corrigendum published on 30 July 2026 corrects Council Decision (CFSP) 2026/1713, adopted on 13 July 2026. That Decision, in turn, amended the European sanctions regime against cyberattacks contained in Decision (CFSP) 2019/797.
To understand the real scope, it is useful to distinguish the three regulatory levels:
- Decision (CFSP) 2019/797: base regulation establishing the EU's restrictive measures regime against significant cyberattacks. It defines what constitutes a sanctionable cyberattack, what measures can be applied (travel ban and asset freeze) and to whom.
- Decision (CFSP) 2026/1713 (13 July 2026): amendment to the base regulation, adopted by the Council. It introduces changes to the existing sanctions regime.
- Corrigendum (30 July 2026): remedies technical-formal errors detected in Decision 2026/1713. It does not alter the substantive content or scope of sanctions.
| Aspect | Situation after correction |
|---|---|
| Type of change | Technical-formal. No substantive modification |
| Existing restrictive measures | Travel ban and asset freeze (no changes) |
| Recipients of sanctions | Persons and entities responsible for significant cyberattacks against the EU or its Member States (no changes) |
| Affected base regulation | Decision (CFSP) 2019/797 (no substantive changes) |
| New sanctioned parties | None introduced by this correction |
Economic and operational impact
The direct economic impact of this correction is zero: no new economic obligations are created, sanctions lists are not expanded, and existing restrictive measures are not modified.
The operational impact is low but real for entities with international sanctions compliance programs. These organizations must:
- Update the internal regulatory reference to the corrected version of Decision (CFSP) 2026/1713.
- Confirm that their counterparty screening tools use the current and corrected version of EU sanctions lists.
- Document in their compliance file that they have reviewed the correction and that it does not imply operational changes.
Indirectly, this correction reinforces the political signal that the EU maintains an active and constantly reviewed sanctions framework in cybersecurity matters, which is relevant for companies operating in critical infrastructure sectors or managing relationships with counterparties in high-risk jurisdictions.
Who does it affect?
- Financial entities (banks, insurance companies, fund managers) with international sanctions compliance obligations and counterparty screening.
- Companies in any sector that maintain commercial relationships with international counterparties and are obliged to verify EU sanctions lists.
- Compliance and legal departments of business groups with exposure to European sanctions regulations.
- Public bodies that manage contracts or relationships with entities subject to the EU sanctions regime.
- Natural and legal persons already included in sanctions lists for cyberattacks under Decision (CFSP) 2019/797, who must be aware of the corrected text that affects them.
- Legal advisors and compliance consultants who advise clients on international sanctions matters.
Practical example
A medium-sized Spanish bank with an international sanctions compliance program conducts periodic controls of its counterparties against EU sanctions lists. Its compliance team receives an alert about the publication of the corrigendum to Decision (CFSP) 2026/1713 on 30 July 2026.
The process it must follow is as follows:
- Access the corrected text in the EU Official Journal and confirm that the correction is technical-formal, with no new sanctioned parties.
- Verify that its sanctions list provider (or its internal tool) already reflects the corrected version of the regulation.
- Document in the compliance file the review carried out, the date and the conclusion: no additional operational impact.
- It is not necessary to launch an extraordinary screening process, as there are no new persons or entities sanctioned.
This process, although simple, is mandatory to maintain traceability of the compliance program and avoid observations in internal or external audits.
What should companies do now?
- Review the correction published on 30 July 2026 in the EU Official Journal to confirm that it is technical-formal in nature and does not introduce substantive changes to existing sanctions.
- Update the internal regulatory reference: replace any reference to Decision (CFSP) 2026/1713 with the corrected version in compliance manuals, internal procedures and files.
- Verify with the sanctions list provider that the screening tool uses the current and corrected version. If lists are managed internally, ensure they are up to date.
- Document the review in the compliance file, with date and conclusion, to leave a trail for possible audits.
- No additional urgent action is necessary: as there are no substantive changes, there is no need to relaunch due diligence processes or notify counterparties.
Frequently asked questions
Does the corrigendum to Decision CFSP 2026/1713 add new sanctioned parties?
No. The corrigendum published on 30 July 2026 is technical-formal in nature and does not introduce new natural or legal persons to the sanctions lists. Nor does it modify the existing restrictive measures (travel ban and asset freeze) established under Decision (CFSP) 2019/797.
What restrictive measures does the EU sanctions regime against cyberattacks include?
The regime established by Decision (CFSP) 2019/797, and maintained without substantive changes following this correction, includes two types of measures: travel ban (sanctioned parties cannot enter or transit through EU territory) and asset freeze (immobilization of funds and economic resources of sanctioned parties in the EU). They apply to persons and entities responsible for significant cyberattacks against the EU or its Member States.
Which companies are obliged to verify EU sanctions lists for cyberattacks?
Mainly entities with international sanctions compliance programs: financial entities (banks, insurance companies, fund managers), companies with international commercial relationships and public bodies that contract with third parties. The obligation to verify EU sanctions lists derives from the European sanctions regime itself, which prohibits making funds or economic resources available to sanctioned parties.
When did Decision (CFSP) 2026/1713 that is being corrected enter into force?
Decision (CFSP) 2026/1713 was adopted on 13 July 2026, which is also its entry into force date. The corrigendum was published on 30 July 2026 and applies retroactively to that same original date, as it is a technical correction of the original text.
Where can I consult the updated list of persons and entities sanctioned for cyberattacks by the EU?
The official and updated list of persons and entities sanctioned under the regime of Decision (CFSP) 2019/797 is published in the EU Official Journal and in the EU Council's restrictive measures register. Specialized compliance tools (such as the consolidated lists of the EU Publications Office) also include these updates centrally.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202690642