The European Commission (EC) has outlined proposals to phase out so-called high-risk suppliers after revealing its revised Cybersecurity Act this week.
In the proposals, the EC said the Act seeks to bolster the EU's cybersecurity resilience and capabilities.
As such, the EC said the Cybersecurity Act will "enable the mandatory derisking of European mobile telecommunications networks from high-risk third-country suppliers."
The proposals are expected to be a blow for Chinese network vendors Huawei and ZTE, with the two vendors increasingly phased out of European carriers' networks in recent years amid security concerns.
The EC's plans were finalized following an initial report from the Financial Times earlier this week, which pre-empted the EU's push to step up its tech sovereignty plans.
In the proposals, the EU said the Act will enhance the security of the EU's Information and Communication Technologies (ICT) supply chains, noting that it also "ensures that products reaching EU citizens are cyber-secure by design through a simpler certification process."
"The new Cybersecurity Act aims to reduce risks in the EU's ICT supply chain from third-country suppliers with cybersecurity concerns. It sets out a trusted ICT supply chain security framework based on a harmonized, proportionate, and risk-based approach. This will enable the EU and Member States to jointly identify and mitigate risks across the EU's 18 critical sectors, considering also economic impacts and market supply," said the EC this week in its announcement of the proposals.
According to the EC, the plans to clamp down on the high-risk vendors, often referenced as Huawei and ZTE, will build on work already carried out under the 5G security toolbox.
The EC introduced the 5G Security Toolbox in 2020, in a bid to reduce reliance on "high-risk" vendors for the buildout of future telecoms networks. Although it didn't directly address Chinese vendors Huawei and ZTE, it was seen to be a move to dial down on working with these vendors.
In a statement to DCD, Huawei said the proposals outlined this week don't change the company's plans to operate in Europe.
"A legislative proposal to limit or exclude non-EU suppliers based on country of origin, rather than factual evidence and technical standards, violates the EU’s basic legal principles of fairness, non-discrimination, and proportionality, as well as its WTO obligations," said a Huawei spokesperson.
"As a legally operating company in Europe, Huawei will continue to provide secure and trusted products and services. We will closely monitor the subsequent development of the legislative process and reserve all rights to safeguard our legitimate interests.”
Outside of the EU, many other countries have followed the US in imposing bans on Huawei equipment, notably the UK, Australia, Canada, and New Zealand.
Since 2019, the US government has restricted Huawei's access to American technology, alleging the vendor is a threat to its national security.
Europe has been under pressure from the US to impose bans on the so-called high-risk vendors.
In a statement, the GSM Association (GSMA) said that it supports the EC's aim of bolstering cybersecurity, but warned measures “must be strictly risk-based and operationally workable.”
“The proposed Cybersecurity Act revisions make this challenging and may ultimately undermine European operators’ ability to upgrade networks at pace and meet the continent’s connectivity ambitions," said the GSMA.
Comments