The EC introduces draft revisions to the EU's Cybersecurity Act to phase out equipment from high-risk suppliers in critical sectors, a move criticized by Huawei
The EU plans to phase out components and equipment from high-risk suppliers in critical sectors, according to a draft proposal released …
Context & Ripple Effects
The Commission’s draft marks an escalation from the EU’s 2019 approach of asking member states to assess 5G risks rather than imposing a bloc-wide ban, and from its later consideration of mandatory restrictions on Huawei and other high-risk vendors.
The move also confirms reporting days earlier that the proposal was expected to target vendors including Huawei in critical infrastructure through a phase-out framework. It matters because the policy focus has broadened from telecom-network guidance toward equipment and components used across critical sectors.
First-order effects
- The draft puts operators in critical sectors on notice that equipment and components from suppliers designated high risk could face phase-out requirements if the revisions advance.
- Huawei becomes an immediate target of heightened EU policy scrutiny and has publicly criticized the proposed approach.
Second-order effects
- Affected operators will need to assess supplier exposure and potential replacement paths, creating procurement uncertainty before any final requirements are set.
- Rival equipment providers may gain access to replacement demand, while suppliers exposed to EU critical-sector deployments face greater pressure to demonstrate security acceptability.
Third-order effects
- If adopted, the revisions would shift EU cyber policy toward a more centralized, supplier-risk-based framework rather than relying chiefly on member-state risk management.
- The proposal could make supply-chain origin and vendor status more consequential in critical-infrastructure purchasing, though its eventual scope depends on the legislative process and implementation.
The trend: This is part of the EU’s shift from coordinating cybersecurity risk assessments to using market-access rules to reduce perceived strategic supplier exposure in critical infrastructure.