FR
live

The EU Gives Operators 36 Months to Remove High-Risk Suppliers from Critical Networks

On 20 January 2026, the European Commission proposed a revamped Cybersecurity Act that mandates removing high-risk foreign suppliers from the EU’s telecom networks and ICT supply chains. Operators have three years to comply, with fines reaching 7% of global turnover.

L’Europe impose 36 mois pour éjecter les fournisseurs à risque de ses réseaux critiques — ETTAYEB illustration

20 January 2026. The European Commission drops its Cybersecurity Package — a two-pronged legislative overhaul that reshapes the EU’s cybersecurity regulatory architecture. At its heart sits the Cybersecurity Act 2 (CSA2), which for the first time mandates the compulsory removal of high-risk suppliers from the continent’s critical infrastructure.

36 months. That’s how long mobile network operators get to strip out equipment from designated high-risk suppliers once the Commission publishes its official list. Fixed-line and satellite networks will get their own deadlines through subsequent implementing acts, but the principle is identical: these are no longer recommendations. They’re obligations.

7% of global annual turnover. That’s the maximum fine for the most serious breaches of the prohibitions and mitigation measures the Commission will impose. The CSA2 slots itself straight into the same penalty bracket as the GDPR.

This isn’t a tactical surprise. It’s the endpoint of a decade of geopolitical friction over Chinese telecom equipment vendors — Huawei and ZTE most prominently —, years of US pressure on European allies, and a voluntary 5G Security Toolbox from 2020 that Brussels now considers too slow and too patchy. The CSA2 moves the needle from “you should” to “you must” — and it’s got real teeth.

A horizontal framework covering 18 critical sectors

The most structurally significant part of CSA2 isn’t just the telecom phase-out — it’s the introduction of the EU’s first horizontal ICT supply chain security framework. Until now, EU cybersecurity regulation operated through sectoral silos. The CSA2 creates a single mechanism spanning all 18 critical sectors covered by the NIS 2 Directive: energy, transport, healthcare, digital infrastructure, cloud services, data centres, drinking water, public administration, and the rest.

The mechanism works in three escalating tiers.

First, the Commission can adopt implementing acts identifying key ICT assets — the hardware, software, and services whose compromise would cause severe supply-chain disruption or large-scale data exfiltration. A component can be classified as “key” if it performs essential or sensitive functions, if supplier concentration creates dependency risks, or if EU-level risk assessments warrant it.

Second, the Commission can designate third countries and the entities they control as high-risk suppliers. The criteria include: national laws requiring vendors to report software or hardware vulnerabilities to that country’s authorities, the absence of effective judicial or democratic oversight, or credible evidence of malicious cyber activity originating from actors operating from that country. The classification is structural, not technical: it’s not the product that’s judged deficient — it’s the supplier’s legal and political environment that’s treated as a threat.

Third, once a country and its suppliers are classified, the Commission can prohibit specific categories of NIS 2 entities from using, installing, or integrating ICT components from those suppliers in key assets. It can also impose targeted mitigation measures: supplier-transparency obligations, restrictions on data transfers to third countries, third-party audited technical safeguards, mandatory diversification of supply.

Telecom: the special regime

Electronic communications networks — mobile, fixed, and satellite — operate under a separate, stricter, and faster-track regime embedded in Annex II of the regulation. For these networks, key ICT assets are pre-defined by law, with no waiting for implementing acts. And the rule is binary: components from high-risk suppliers must be removed, full stop.

For mobile networks, the maximum phase-out window is 36 months from the publication of the high-risk supplier list. Operators cannot install new components from those suppliers in the interim. Fixed and satellite networks will see their specific timelines negotiated through implementing acts, but the trajectory is the same.

The GSMA, the global mobile operators’ trade body, responded with caution. It supports the cybersecurity objective but warns that measures “must be strictly risk-based and operationally workable,” and that the proposed amendments “may ultimately undermine European operators’ ability to upgrade networks at pace.”

Huawei was more direct. The Chinese vendor called the proposal “a legislative move to limit or exclude non-EU suppliers based on country of origin, rather than factual evidence and technical standards,” arguing it violates “the EU’s basic legal principles of fairness, non-discrimination, and proportionality, as well as its WTO obligations.” The company says it reserves “all rights to safeguard its legitimate interests” — language that signals a potential WTO challenge.

Whether the WTO route succeeds is an open question. The UK, Australia, Canada, and New Zealand have already banned Huawei from their 5G networks following US pressure. The EU is now aligning with that bloc, but doing so through a regulation — directly applicable law — rather than the fragmented, voluntary approach that characterised the 2020 toolbox.

ENISA becomes operational

The CSA2 transforms the European Union Agency for Cybersecurity (ENISA) from an advisory body into a genuine operational arm. Its budget increases by more than 75%, each Member State designates two permanent liaison officers, and the agency inherits critical new missions:

  • Operational coordination of cross-border incident response, working alongside EU-CyCLONe (the European Cyber Crisis Liaison Organisation Network).
  • Early threat alerts sent directly to Member States, with the authority to issue warnings on major or cross-border threats.
  • Single incident reporting platform, introduced by the Digital Omnibus package, replacing the current fragmented notification landscape.
  • Ransomware helpdesk, supporting essential and important entities in partnership with Europol and national CSIRTs — roughly analogous to CISA’s incident response coordination in the US.
  • EU Cybersecurity Reserve, a standby pool of incident-response providers deployable at a Member State’s request.
  • Cybersecurity Skills Academy, with EU-wide skills attestation schemes.
  • Development of technical specifications for future certification schemes, with a hard deadline of 12 months per scheme.

ENISA also becomes manager of the European Vulnerability Database established under Article 12 of NIS 2 and takes charge of developing European cybersecurity certification schemes — a project that had stalled since 2019.

Certification: breaking the logjam

The European Cybersecurity Certification Framework (ECCF), created in 2019, produced exactly one adopted scheme in five years: EUCC, based on Common Criteria. Two more are under development — for digital identity wallets (EUID) and managed security services (EUMSS) — but work on cloud certification (EUCS) and 5G certification (EU5G) was blocked by political deadlock over sovereignty clauses.

The CSA2 breaks the impasse through several levers:

  • It extends certification scope beyond products and services to an organisation’s overall cyber posture — its governance maturity, processes, and readiness. This posture certificate will provide presumptive compliance with NIS 2 and other sectoral legislation.
  • It imposes a legal timeline: 12 months for ENISA to develop a candidate scheme after a Commission request.
  • It clarifies that the certification mechanism is distinct from the ICT supply-chain security mechanism: certification remains voluntary, but becomes de facto mandatory through procurement rules, market expectations, and national requirements.

The cloud scheme (EUCS) is explicitly relaunched, anchored to the forthcoming Cloud and AI Development Act (CADA), which will impose sovereignty requirements on the most critical cloud and AI services used by the public sector.

NIS 2: simplification for 28,700 companies

The second leg of the Cybersecurity Package is a set of targeted amendments to the NIS 2 Directive, informed by experience gained during national transposition. These fixes reduce administrative burden without weakening the security perimeter:

  • 28,700 companies exit the scope through definitional clarifications, including 6,200 micro and small enterprises.
  • A new small mid-cap enterprise category reduces compliance costs for an additional 22,500 companies.
  • Submarine data cables are explicitly brought within the directive’s scope, closing a regulatory blind spot as these infrastructures become strategic targets — a concern shared by NATO and national defence agencies.
  • Cross-border entity supervision procedures are simplified, with ENISA playing a strengthened coordination role.

The geopolitics that lit the fuse

The CSA2 wasn’t born from bureaucratic whim. It’s a direct response to a rapidly deteriorating threat landscape that the Commission describes bluntly in its explanatory memorandum: increasingly sophisticated cyberattacks against critical infrastructure, state-actor involvement in destabilisation campaigns, and strategic technological dependencies on third countries perceived as hostile.

Russia’s war in Ukraine served as the catalyst. Russian cyberattacks on Ukrainian energy grids and communications infrastructure — and, by spillover, European targets — demonstrated that an ICT supply chain isn’t a technical problem. It’s a strategic lever. A network component whose firmware can be remotely instrumented by a third country isn’t a “potential” risk. It’s a prepositioned offensive capability.

US-China tensions provided the second engine. Since 2019, Washington has pushed allies to ban Huawei and ZTE from their networks. The UK, Australia, Canada, and New Zealand complied. Europe remained divided: some Member States banned Chinese vendors, others temporised, others signed contracts. The CSA2 forces a common position, and it does so at the regulation level — directly applicable law that leaves no room for national horse-trading during transposition.

The verdict

The CSA2 is not symbolic legislation. It’s an instrument of economic and diplomatic coercion that transforms European technological sovereignty from a slogan into an enforceable legal mechanism. The question for telecom operators and cloud service providers is no longer whether they’ll have to audit their supply chains — it’s when, and how much it will cost.

For security teams, three concrete actions to start now, without waiting for the final text — expected later in 2026 after negotiations in the European Parliament and Council:

  • Map your supplier dependencies across critical ICT assets. If you operate in any of the 18 NIS 2 sectors, you’re in scope — even if you don’t touch telecom. Identify components whose replacement would force an architectural overhaul.
  • Prepare for cyber-posture certification. The forthcoming organisational certification scheme will be a competitive advantage, not an imposed burden. Start documenting your security policies, incident-response processes, and governance maturity now.
  • Review your supplier contracts. Infrastructure vendor agreements need reversibility, substitution, and subcontracting-transparency clauses immediately. A supplier that’s acceptable today can be classified as high-risk tomorrow.

The CSA2 marks a doctrinal break: the security of an ICT product is no longer judged solely on its code, but on the jurisdiction that controls its manufacturer.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

← Back to the feed

Type at least two characters.

navigate open esc dismiss