Decoding the world of cybersecurity

·

EU states loosen telecom supplier phase-out timetable

EU governments have removed a proposed fixed three-year deadline for telecom operators to phase out high-risk suppliers, adding flexibility to one of the bloc’s most consequential supply chain security measures.

EU states loosen telecom supplier phase-out timetable
Summary
  • EU governments have removed the Commission’s proposed fixed phase-out deadline from their negotiating position.
  • Replacement schedules would instead reflect risk, equipment lifecycles, interoperability, and available alternatives.
  • The change leaves the security objective intact while reopening questions over cost, implementation, and dependency on high-risk suppliers.

European Union governments have removed a proposed fixed deadline for mobile operators to replace equipment from suppliers judged to present a high cybersecurity risk, opening the way for a more flexible implementation of one of the bloc’s most consequential telecom security measures.

The European Commission proposed in January that high-risk suppliers should be phased out of critical telecommunications infrastructure, including a three-year transition period for mobile operators. A Council document dated 22 September, however, removes that fixed timetable and would instead make replacement periods dependent on factors including the assessed level of risk, infrastructure and product lifecycles, equipment replacement cycles, interoperability requirements, and the availability of alternatives.

The change does not amount to a reversal of the EU’s effort to reduce security dependencies in critical communications infrastructure. The Commission’s revised Cybersecurity Act proposal would establish a broader framework for addressing risks from third-country suppliers across information and communications technology supply chains, moving beyond the voluntary and uneven approach that has characterised the bloc’s treatment of high-risk 5G vendors.

Huawei, whose equipment would be among the technology most affected by stronger restrictions, has consistently denied that its products present a security risk. The legislation remains under negotiation, and the Council’s position will still have to be reconciled with the European Parliament and Commission before the revised Cybersecurity Act can become law.

The dispute over timing reflects an increasingly difficult collision between security policy and infrastructure economics. European telecom operators have spent years building networks around equipment from a relatively small number of large suppliers. Replacing installed infrastructure is not simply a procurement decision: operators have to account for network compatibility, existing investment cycles, engineering capacity, testing, and the availability of technically viable alternatives.

Industry opposition has focused heavily on the cost. A joint letter from Deutsche Telekom chief executive Timotheus Höttges and 16 other industry executives warned that replacing affected equipment could cost as much as €40 billion, potentially diverting capital from fibre deployment and the development of 5G and 6G networks. That estimate is an industry claim rather than an EU assessment, but it illustrates the scale of the commercial argument now shaping the legislative negotiations.

The revised approach also puts more weight on how individual governments translate a common European risk framework into actual infrastructure decisions. A flexible timetable can allow replacement to coincide with planned network upgrades and reduce stranded investment, but it also creates more room for different national interpretations of what constitutes an acceptable transition period.

That tension has followed European telecom security policy since concerns about high-risk suppliers first became central to 5G planning. The EU has increasingly sought to move from voluntary guidance towards a more harmonised system, while operators have argued that security requirements need to recognise the practical constraints of running large, long-lived networks.

The September Council text is not the final position. What emerges from negotiations will determine not only how quickly individual suppliers disappear from European networks, but how much discretion operators and national authorities retain when security policy meets infrastructure reality.

×