Breaking news

European Parliament Backs New Rules To Support Small Mid-Cap Companies

European lawmakers are setting the stage for a regulatory transformation aimed at bolstering the growth of small mid-cap enterprises across the continent. By endorsing proposals to expand regulatory exemptions, the European Parliament is creating a new category designed to bridge the gap between traditional SMEs and large multinationals.

Defining The Emerging Enterprise Segment

Under the proposed framework, companies with fewer than 1,000 employees and either up to €200 million in annual turnover or €172 million in total assets would qualify for the new category. These thresholds represent an expansion of the limits originally proposed by the European Commission. Earlier proposals set eligibility at 750 employees, €150 million in turnover and €129 million in total assets. Lawmakers adjusted the limits to better reflect companies that have outgrown the SME stage but still face constraints typical of mid-sized firms.

Targeted Relief From Regulatory Burdens

Members of the European Parliament have also proposed reviewing these thresholds every five years to ensure they remain aligned with economic conditions. The new framework seeks to address what policymakers describe as the “cliff-edge” effect. Under existing rules, companies that slightly exceed SME limits often face a sudden increase in regulatory obligations.

By extending certain exemptions, including simplified record-keeping obligations under the General Data Protection Regulation for lower-risk data processing, lawmakers aim to reduce compliance costs for growing businesses.

Access To Capital And Market Integration

Changes to financial market regulations are also part of the initiative. The new company category would be incorporated into the Markets in Financial Instruments Directive, allowing eligible firms to benefit from simplified prospectus disclosure requirements. Easier disclosure rules are expected to improve access to capital markets and help mid-sized companies raise funding more efficiently.

Environmental And Trade Policy Adjustments

Beyond financial and data privacy reforms, the proposals include streamlined measures for environmental compliance. Notably, updates to the Batteries Regulation and related due diligence requirements are scheduled to occur every five years rather than every three, reducing the compliance frequency for mid-sized players. Adjustments to the F-gases Regulation were also tabled, with registration requirements being capped at specific import or export volumes to avoid overburdening smaller market participants.

Strategic Implications And Future Negotiations

The reform package reflects recommendations outlined in the Draghi and Letta reports on European competitiveness and the future of the single market. Policymakers say the goal is to support growing businesses while preparing them to compete globally.

Following strong support from committees responsible for economic affairs, civil liberties and environmental policy, lawmakers have authorized the start of inter-institutional negotiations on the final legislative text. The initiative forms part of the EU’s broader “think small first” approach, which seeks to ensure that regulatory frameworks evolve alongside company growth and encourage a more competitive European business environment.

Iran-Linked Hackers Shut Down U.K. Power Plant For Four Days

A small U.K. power plant was taken offline for four days in July after a cyberattack reportedly linked to hackers tied to Iran, according to The Telegraph. The incident was not considered a threat to the wider U.K. energy system, according to the government.

U.K. Government Declines To Assign Blame

A government spokesperson declined to identify the facility or confirm who was behind the attack. The government said the incident affected a small-scale generator and did not threaten the wider energy system.

“The U.K. has a highly resilient energy system. We work closely with the energy sector to protect infrastructure and ensure the highest security standards,” the spokesperson told CNBC.

The Department for Energy Security and Net Zero said it had briefed energy executives and written to companies about further measures. The department is also updating cybersecurity regulations for the energy sector.

U.S. Agencies Warned Of Iranian Cyber Activity

The reported attack came as U.S. authorities warned that Iranian cyber actors were targeting critical infrastructure. The Cybersecurity and Infrastructure Security Agency, FBI, Environmental Protection Agency and other agencies said Iranian actors had targeted water facilities across at least seven U.S. states.

U.S. officials have also warned that Iranian cyber groups could target businesses and infrastructure in response to the conflict between the U.S., Israel and Iran.

On Aug. 18, the U.S. Department of Justice charged 17 Iranians over what it described as a “massive cyber theft campaign” carried out on behalf of the Islamic Revolutionary Guard Corps and other Iranian entities.

Iran Has Also Faced Cyberattacks

Iran has also been targeted by major cyberattacks. In June, blockchain analytics firm Elliptic said hackers stole more than $90 million from Nobitex, Iran’s largest cryptocurrency exchange.

According to Elliptic, the funds were moved from Nobitex wallets to addresses containing messages referencing the Islamic Revolutionary Guard Corps. The pro-Israel hacking group Gonjeshke Darande, also known as Predatory Sparrow, claimed responsibility for the attack.

The reported U.K. incident adds to a series of cyberattacks involving critical infrastructure and state-linked actors. Energy companies and other infrastructure operators are facing growing pressure to strengthen defenses as cyber operations become increasingly tied to geopolitical conflicts.

Aretilaw firm
eCredo
The Future Forbes Realty Global Properties
Uol

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter