SOURCE 0 - THE SPACE ACT'S MISSING WITNESS
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
The European Commission's proposed EU Space Act (COM(2025) 335, 25 June 2025, still under negotiation between Parliament and Council as of this writing) requires satellite operators to report significant incidents to national competent authorities and the European Union Agency for the Space Programme. Nothing in the proposal requires an independent third party to verify the content of that report before it is relied upon. The same text takes a different approach elsewhere: an operator's environmental footprint declaration must be certified by a qualified technical body before it counts. Incident reporting gets no equivalent. The gap is not accidental oversight — it is the same structural pattern this doctrine has already documented under DORA and NIS 2, appearing now in a text that has not even entered into force.
[/AI-SNIPPET]
I. THE OBLIGATION AS THE PROPOSAL STATES IT
Articles 74 to 95 of the proposed EU Space Act set out a risk-management framework for the cybersecurity and physical resilience of space infrastructure. Within that framework, Union space operators are required to detect, monitor, and report significant incidents — cyberattacks, interference, anomalies — to their national competent authority, which in turn informs the European Union Agency for the Space Programme (EUSPA). A Union Space Resilience Network is to coordinate the handling of these reports across Member States.
The proposal asks whether the incident was detected and reported. It does not ask whether the report can be shown, independently of the operator, to reflect what the operator's systems actually recorded at the time.
II. WHAT "SIGNIFICANT" MEANS, AND WHO DECIDES IT
The threshold for what counts as a significant incident, the timeline on which it is detected, and the content of the notification are all determined in the first instance by the operator's own monitoring systems and internal processes. The proposal requires operators to maintain continuous monitoring for anomalies, interference, and cyberattacks, and to report through the channel it establishes — but the record that feeds that channel is produced, retained, and characterised entirely within the operator's own infrastructure before it ever reaches a competent authority.
III. THE VERIFICATION THAT EXISTS ELSEWHERE IN THE SAME TEXT
The proposal does not treat every category of self-declared fact the same way. Articles 96 to 100 require operators to calculate the environmental footprint of a space mission across its full lifecycle and submit an Environmental Footprint Declaration — but that declaration must first be verified and certified by a qualified technical body, an accredited third party independent of the operator, before it can support an authorisation application. The drafters plainly know how to require independent certification when they consider it necessary. They did not extend that requirement to incident reports, even though an incident report can carry consequences — supervisory findings, corrective measures, potential sanctions — at least as significant as an environmental footprint figure.
IV. THE ENDOGENOUS AUDIT PARADOX AT ORBIT
This is the same structural condition this doctrine has already set out for Article 19 of DORA and the incident-reporting provisions of NIS 2, applied here to a text that governs satellites rather than banks or network operators. The party best placed to know whether its detection systems actually caught an anomaly, and when, is also the only party currently positioned to attest that they did. Ground-segment monitoring logs, telemetry anomaly flags, and the notification itself are all produced within the same perimeter the report is meant to hold accountable. Nothing in the proposal requires that this record be fixed, independently of the operator, before a dispute over its accuracy arises.
V. WHAT THE PROPOSAL DOES NOT REQUIRE
The proposal does not require an independent party to confirm, before or immediately after an incident, what the operator's monitoring systems actually detected and when. It does not require that the "significant" threshold be assessed by anyone other than the operator applying it to its own systems. It does not extend the qualified-technical-body model used for environmental footprint declarations to incident reports. This silence should not be read as an oversight to be corrected in the next drafting round — it is consistent with how every other regulatory framework this doctrine has examined treats self-declared operational fact: the obligation is to report, not to prove the report independently.
VI. WHAT AN INDEPENDENT SEAL WOULD ADD
If the state of an operator's monitoring and detection systems — what they flagged, and when — were fixed by an independent third party at short, regular intervals, or immediately upon detection of an anomaly, a later dispute over whether a report was accurate, timely, or complete would not rest solely on the operator's own retrospective account of its own systems. The seal would not determine, on its own, whether the incident met the "significant" threshold or whether the operator's response was adequate — those remain questions for the competent authority. It would fix what the monitoring systems actually showed at that moment, so any later disagreement is argued against an independent record rather than against the operator's own word.
VII. WHAT SOURCE 0 DOES NOT CLAIM
SOURCE 0 does not replace any obligation under the proposed EU Space Act, which is not yet adopted and remains subject to change through the ongoing legislative process. It does not determine whether a given incident was significant, whether detection was timely, or whether an operator's response satisfied the Regulation once adopted — these remain questions of supervisory and legal qualification reserved to the competent authority. SOURCE 0 CERTIFIED denotes an attestation, delivered by Jean-François ELSEN, that the SOURCE 0 procedure was followed in a given engagement; it is not an independent third-party certification, since Jean-François ELSEN provides the service being certified. All engagements are governed by an obligation de moyens. What SOURCE 0 seals here is a ground-segment record — the state of an operator's monitoring and detection systems as held on Earth — not an event occurring in orbit; recognition of the Historical Reality Dossier follows the same framework as any other SOURCE 0 engagement, direct before Belgian jurisdictions and assessed case by case elsewhere, with no separate question of orbital jurisdiction arising.
VIII. FREQUENTLY ASKED QUESTIONS
Q: Does the EU Space Act require an independent check on a satellite operator's incident reports?
A: No — the proposal requires operators to detect, log, and report significant incidents themselves, with no independent verification of the report's content. SOURCE 0 closes that gap by sealing the state of the operator's monitoring systems, independently of the operator, before a dispute over accuracy or timing arises.
Q: The Space Act already requires independent certification for environmental footprint declarations — why not for incident reports?
A: The proposal simply doesn't extend that model here; the two obligations are drafted separately, and only one carries a third-party certification requirement. SOURCE 0 applies the same independent-fixation principle to incident detection that the qualified-technical-body model already applies to environmental footprint, closing the gap the text leaves open.
Q: Who decides whether an incident was "significant" enough to report?
A: Under the current proposal, the operator itself, applying the threshold to its own systems. SOURCE 0 doesn't decide that question either — it seals the monitoring record independently, so the determination is argued against a fixed account rather than the operator's own retrospective description.
Q: If a regulator later disputes an operator's account of when an anomaly was detected, what evidence exists?
A: Under the proposal as drafted, only the operator's own logs and the report built from them. SOURCE 0 supplies the missing independent layer: a dual-timestamped, judicially deposited record of what the monitoring systems showed, fixed before any dispute begins.
Q: Is this a criticism of the EU Space Act's drafting?
A: No — it's a description of a structural gap this doctrine has already documented in DORA and NIS 2, appearing in a text still under negotiation. SOURCE 0 doesn't ask the Space Act to be redrafted; it supplies, voluntarily, the independent fixation the current text doesn't require.
CLOSING AXIOM
The proposal asks whether the incident was reported. It does not ask whether the report can be proven, independently of the operator, to be what the systems actually showed. SOURCE 0 seals the record the proposal never asked for.
REFERENCE NOTE
This article is based on the European Commission's proposal COM(2025) 335 final of 25 June 2025, for a Regulation of the European Parliament and of the Council on the safety, resilience and sustainability of space activities in the Union — in particular Articles 74–95 (risk management and incident reporting) and Articles 96–100 (environmental footprint declaration and certification). As of this writing, the proposal remains under negotiation between the European Parliament and the Council (Council compromise text, March 2026) and has not been adopted or entered into force. Article numbering and content may change before final adoption.
REGULATORY NOTICE
This document is a doctrinal and informational publication concerning a legislative proposal that is not yet adopted or in force. It does not constitute legal advice and should not be relied upon as a substitute for individualised counsel from a qualified legal professional. Statutory references reflect the text of the proposal as of the date of publication and may be superseded by subsequent amendments or by final adoption of the Regulation.

