30 September 2026

Few parts of the proposed Cybersecurity Act revision have drawn as much scrutiny as Title IV, which would let the Union designate high risk suppliers and require their equipment to be removed from critical networks. At its debate on 29 September, the European Internet Forum heard from those who would have to apply the rules: a network vendor, a Member State negotiator, a cloud and software provider and the telecom operators' association. Two questions ran throughout: what should make a vendor high risk, and what evidence and process should stand behind such a decision.

EU Cybersecurity Act 2 (CSA2)

Opening remarks

Markéta Gregorová MEP, who hosted and chaired the debate, explained that the aim was to hear from those who will live with the law rather than those who draft it. She noted that much of the proposal is uncontroversial, and that Title IV is the exception because it gives the Union power to declare a supplier too risky for critical infrastructure. She argued the power is needed, pointing to China's national intelligence law, which obliges companies to assist state intelligence work in secret, and to intrusion campaigns in European and American telecom networks known by names such as Typhoon. The 5G toolbox, she stressed, showed what happens when 27 capitals give 27 different answers on the same vendor. What remains open is how the power should be used: whether conduct, the law of a vendor's jurisdiction or the criticality of what it supplies defines high risk, and on what evidence, seen by whom and with what rights attached. She warned that a designation is closer to a sanction than to a product standard.

A Member State Perspective

Speaking from the Polish perspective, Katarzyna Prusak-Górniak of the Polish Representation to the EU described a file advancing under the Irish presidency, with trilogue preparations in view. Poland welcomes an EU level, risk based approach and supports starting the phase out with mobile networks, while seeing a need for further risk assessment before fixed and satellite networks are covered. She called for objective criteria that take account of ownership structure and third country influence, measures that are evidence based, proportionate and non discriminatory, and a stronger role for Member States. Coherence with the Cyber Resilience Act, a lighter administrative burden and a mechanism to prioritise what to protect first were further priorities. She added that ENISA needs a focused mandate rather than an ever growing one.

Industry Perspectives

Marc Vancoppenolle, Vice President at Nokia, argued that trust in networks is a real world issue, since telecom infrastructure underpins energy, transport, payments, defence and the data flows behind AI. He put the share of Europe's infrastructure relying on untrusted technologies at 30 to 35% and called for CSA2 to cover the full network, including optical transport, IP routing and fixed access, not mobile alone. The 5G toolbox, in his view, did not deliver because voluntary implementation left uneven progress. On cost, he distinguished total replacement cost from the incremental cost of accelerating a transition that would partly happen through routine modernisation, and said the latter is lower than some headline figures. He called for the transition to be completed before 6G arrives from 2030.

Rita Jonusaite, Government Affairs and Public Policy Manager at Google, welcomed the revision as a chance to reduce fragmentation, and first asked for security impact assessments of non-security legislation, citing data localisation requirements in the Cloud and AI Development Act (CADA) as an example. She argued that certification should stay technical and voluntary, noting the shortage of qualified conformity assessment bodies in Europe and the delays seen under the Medical Device Regulation. On the supply chain, she cautioned against rules that blacklist suppliers by country of origin and asked that any high risk designation rest on a case by case assessment of technical posture, governance and operational independence. She also pointed out that cloud providers now face three different foreign dependency tests across CADA, a recent procurement proposal and CSA2, and called for alignment and partnerships with allies.

Pinar Serdengecti, Senior Policy Director at Connect Europe, said telecom operators share the security objective but disagree with the Commission's approach, which places the burden disproportionately on one part of the ecosystem and risks higher prices, less supplier choice and weaker resilience. Operators proposed that restrictions match the evidence rather than extend automatically to fixed transport, satellite and radio access networks, and that decisions be targeted to a specific supplier and network function, with geopolitical analysis informing but not replacing risk assessment. Supplier designation, she argued, involves national security judgments that should remain with the Council and Member States, and phase out periods must follow investment cycles. Where lawfully acquired equipment must be replaced early, she called for fair compensation, warning that otherwise the cost would draw on a limited envelope needed for the 2030 fibre and 5G standalone targets.

Videos

  • Cybersecurity - Tech Masterclass
  • #EIFasks - MEP Beatrice Covassi on the impact of the Cyber Resilience Act
  • 2:04 We are EIF: a video tribute to our Members

Related content