What happened
On 1 October 2026 the Royal United Services Institute published a report arguing that the EU's current approach to high risk technology suppliers in critical infrastructure leaves members exposed. Its central recommendation is a risk assessment that applies across all member states, backed by stronger EU level powers, while leaving national security policy in national hands.
The gap RUSI points to is consistency. The only framework covering telecoms is the EU Toolbox for 5G Security, which is voluntary. Since it launched in January 2020, only 10 of 27 member states have fully implemented it. The European Commission has proposed amendments to the Cyber Security Act that would let it build a list of untrusted vendors that members must exclude from the networks of 18 critical sectors, with a 36 month replacement deadline for equipment already installed. Huawei and ZTE would be candidates. The difficulty, RUSI says, is that there is still no official definition of a high risk vendor and it is not a legal category, leaving room for members to buy what they want while appearing to comply.
The report uses Germany, Spain and the UK to show how differently three countries behave. Chinese suppliers accounted for an estimated 59 percent of German 5G radio access network equipment in 2024. In Spain the figure was around 32 percent, and the country awarded Huawei a contract involving the storage of judicial wiretap recordings. The UK is on course to remove Chinese technology from its telecoms networks by the end of next year. RUSI accepts that concerns about Chinese vendors are well founded. It cites laws that let the state compel data from companies, place party representatives inside them, and require flaws to be reported to authorities within 48 hours while withheld from overseas counterparts. It adds that the same arguments apply to US suppliers, with some European officials treating the Patriot Act as a comparable sovereignty concern.
Why this is a GRC story
Procurement is a control, and often the weakest one. RUSI's argument is that many governments still buy on price and treat supplier selection as an administrative step rather than a security decision. Its call for greater economic courage, and for treating procurement as a means to secure critical infrastructure rather than a compliance exercise, is a governance criticism as much as a technical one.
A ban is not a risk assessment. Blanket exclusions do not fix the weaknesses that make products attackable, and suppliers from trusted jurisdictions also ship exploitable software, as the Salt Typhoon intrusions into US telecoms networks showed. If a designation is to carry weight, someone has to define the criteria and defend each decision to include or exclude a company.
What to watch
Watch whether the Cyber Security Act amendments progress and what definition of a high risk vendor accompanies them. A list published without clear criteria invites both over exclusion and legal challenge.
The practical lesson travels beyond the EU. A supplier register recording where critical components come from, who controls the vendor, and what would happen if that supplier were designated, is cheaper to build before a designation lands than after. Most risk teams can ask the underlying question locally: can you show why each supplier in your stack is acceptable, and what you would do if that answer changed?
Attribution: Analysis based on The Register's reporting and RUSI's report on high risk ICT vendors and critical infrastructure. This article is original commentary, not a repost of the source material.
