Cybersecurity Act: high-risk vendors out of the network
6 min read
On 23 July 2026 seven European telecoms groups — including Deutsche Telekom, Vodafone and Orange, close to half the EU market by revenue — released a GSMA Intelligence study commissioned for one purpose: to put a precise number on an obligation Brussels has been preparing for months. The revision of the Cybersecurity Act, Regulation (EU) 2019/881, aims to make binding — no longer just recommended, as under the 2020 5G Toolbox — the exclusion of non-EU suppliers classed as “high-risk vendors”, in practice Huawei and ZTE, from next-generation mobile networks. For anyone writing a network tender, running a critical infrastructure, or planning multi-year investment in active equipment, the useful question is not whether the obligation is coming, but how much it will cost and where to start mapping the exposure.
What the revision actually proposes
The text, referred to in industry circles as CSA2, has not yet completed the legislative process: what has emerged from Brussels and trade press is a three-year window from entry into force to remove equipment from designated high-risk vendors from 5G core and RAN networks — the radio access layer and the mobile network’s control core. It is a shift in legal nature, not just in rigour: the January 2020 5G Toolbox left it to individual member states to decide whether and how to restrict these vendors in their own critical networks; a Cybersecurity Act revision that mandates exclusion turns it into a uniform, verifiable, enforceable obligation across the Union.
The figures, and the gap between two estimates
The GSMA Intelligence study estimates a direct cost of between €30 and 40 billion (central estimate around €35 billion), broken down as: €16-22 billion for mobile networks, €9-12 billion for transport networks (the backhaul and fibre links between sites), and up to €5 billion for fixed broadband network equipment. On top of this come expected price rises on replacement equipment — +24% for mobile, +19% for fixed, +10% for transport — which the study says would add a further €8.5 billion in costs between 2027 and 2030, with a projected additional €24 billion by 2035. The European Commission, for its part, has estimated the impact at €3.4-4.3 billion a year for three years — €10-13 billion in total — but limiting the count to mobile networks alone: a third of the industry figure, and over a narrower scope. The gap between the two estimates is not an accounting detail: it will decide how much transition time is actually granted, and whether the support fund operators are asking for ever reaches the table.
One side effect, less discussed but concrete for anyone writing tenders: with Huawei and ZTE out, some equipment segments would in effect be left with only one significant alternative supplier — Nokia is explicitly cited in the study as a dominant-position risk. A market with only one approved vendor is not just a continuity risk: it is a pricing risk worth writing into the contract, not discovering on the invoice.
Italy already has a similar mechanism, for entities inside the perimeter
Anyone working with public bodies, healthcare, or critical infrastructure operators already knows a national version of this same logic. Decree-Law No. 105 of 21 September 2019, converted with amendments by Law No. 133 of 18 November 2019, established the National Cybersecurity Perimeter (perimetro di sicurezza nazionale cibernetica): public and private entities within its scope must notify the acquisition of ICT goods, systems and services intended for networks, information systems and critical services, and await the outcome of the assessment — now carried out by the National Evaluation and Certification Centre under the National Cybersecurity Agency — before proceeding. It is the same principle the Cybersecurity Act revision aims to extend to the whole European telecommunications network, not just to entities already identified as critical: anyone writing a tender today for a body inside the perimeter is, in effect, already rehearsing an obligation that may soon apply to anyone buying network equipment.
What changes for those designing, procuring or running a network
The official count for now covers mobile only, but the exposure GSMA attributes to fixed networks — up to €5 billion — signals something that matters for FTTH and enterprise networks too: active equipment (OLTs, ONTs, switches, routers, transmission systems) has a vendor, and that vendor’s regulatory status can change without much notice. The same principle already set out for copper in the Digital Networks Act — map it before the operator’s letter arrives — applies just as much to the vendor inventory behind active equipment: knowing who is inside a network cabinet, not just which model, is the first defence against a deadline that arrives from outside. It also connects to the physical security of unsupervised splices and equipment we wrote about here: a network’s resilience rests as much on who controls it as on who can access it.
What to do
- Map active network equipment by vendor, not just by model: OLTs, ONTs, switches, routers, transmission systems. It is a day’s work today, not an emergency tender tomorrow.
- If you write or manage a tender for a body inside the National Cybersecurity Perimeter, check the notification steps to the National Evaluation and Certification Centre well in advance: they add more time to procurement than they appear to on paper.
- In new tenders for active equipment, write in vendor-substitutability and price-protection clauses: a single approved vendor in a segment is an economic risk, not just a technical one.
- Follow the progress of the Cybersecurity Act revision (CSA2): the gap between the Commission’s estimate and the industry’s will decide the real transition time operators are given.
- Do not confuse the incoming EU obligation with the one already in force in Italy since 2019: the national perimeter covers only entities identified as critical, not yet the whole network.
The bottom line.
The cost of this transition — however the negotiation settles, somewhere between €10 and 40 billion — will not fall only on the large operators who commissioned the study: it will fall, proportionally, on anyone writing a network tender in the coming years, because the pool of approved vendors is narrowing for everyone at once. Mapping today’s active equipment and the vendor behind each item — not only for bodies already inside the national perimeter — is the same preventive work we do for our clients in the telecommunications sector: an approach that starts from the network’s real inventory, not from whichever deadline arrives last.
Do you run a network with active equipment whose vendor status you are not certain of, or need to write a tender for a body subject to ICT notification? Get in touch: a first technical conversation helps clarify what to check before the rule becomes final.
Sources
- Corriere Comunicazioni — Cybersecurity Act, il conto per le telco europee può arrivare a 40 miliardi (23 July 2026)
- South China Morning Post — EU push to remove Huawei, other Chinese telecoms gear could cost US$46 billion: report (23 July 2026)
- Techzine Global — European Cybersecurity Act to cost telecom sector €40 billion
- Normattiva — Decreto-Legge 21 settembre 2019, n. 105, conv. Legge 18 novembre 2019, n. 133 (National Cybersecurity Perimeter)