Sources: Chinese authorities told domestic companies to stop using cybersecurity software made by ~12 US and Israeli companies due to national security concerns
Context & Ripple Effects
This extends China’s use of security rationales to reshape technology procurement. It previously warned key infrastructure operators against Micron after finding cybersecurity risks in its products, while government and security-related work was also steered away from less advanced US chips.
The scope has broadened beyond components: earlier orders restricted foreign devices in government agencies and state-backed firms, including foreign phones at work. Applying that logic to cybersecurity software reaches a layer that can sit directly in corporate networks and security operations.
First-order effects
- Domestic companies covered by the direction must stop using cybersecurity software supplied by roughly 12 US and Israeli vendors, forcing replacement, migration, or decommissioning work.
- The affected foreign vendors face an immediate loss of access to Chinese customers subject to the directive and reduced ability to support deployed products there.
Second-order effects
- Chinese cybersecurity suppliers are positioned to compete for replacement deployments, while affected customers face switching costs and potential disruption as they validate alternatives.
- Foreign security vendors may need to reassess China-specific product support and customer exposure as procurement restrictions extend from devices and chips into security software.
Third-order effects
- If applied consistently, this would make security-critical enterprise software another procurement layer governed by national-origin and security-policy tests, not only product performance.
- The pattern points toward more segmented technology stacks between China and foreign suppliers, although the eventual breadth of enforcement and available domestic substitutes remain uncertain.
The trend: China is increasingly treating control over security-sensitive technology inputs—from devices and chips to enterprise software—as a strategic procurement requirement.