Which infrastructure counts as critical for the EU? The European Parliament’s list
7 min read
Today, 5 August 2026, the Official Journal of the European Union publishes the European Parliament resolution of 22 January 2026 on European technological sovereignty and digital infrastructure (2025/2007(INI)), act P10_TA(2026)0022, C series, C/2026/3697. It is not a law, and we say so straight away because it matters more than anything else written below. But inside it there is a paragraph that anyone writing a specification can use from this morning: a list, put in writing by a European institution, of what counts as critical digital infrastructure. That is point 24, and it is the heart of this piece.
The list, item by item
The Parliament “recognises the strategic importance of critical digital infrastructure and the need to strengthen their security and resilience”, then lists it: “critical digital infrastructure includes, but is not limited to, cables (terrestrial and submarine), cellular network towers, satellite communication systems, spectrum and radio equipment, cloud servers that contain sensitive information and data centres that process sensitive information, as well as certain software elements, including security software that protects critical networks and data centres”.
Read it as a checklist, not a proclamation. Seven items, and each corresponds to something that genuinely appears in a supply contract: a fibre route, a mast, a VSAT terminal, radio equipment, a room that processes sensitive data, the software agent that protects access to it. If any of these items appears in your tender or your plant inventory, as far as the European Parliament is concerned it is part of the resilience conversation — not tomorrow, from today, now that the list is public. Recital H widens the frame: digital infrastructure is “composed of hardware elements related to connectivity, including fibre, 5G and 6G, submarine cables, satellites and spectrum, and computing, including semiconductors, data centres, HPC and quantum technologies”, plus software elements and “the intermediary layer”. Point 24 is therefore not a stand-alone list: it is the operational translation of a definition the Parliament had already set out a few pages earlier.
Jurisdiction, not geography
Point 25 adds the request, and it is the part with the most practical consequences: the Parliament “highlights the need to ensure that this infrastructure falls under EU jurisdiction, meaning that it fully adheres to EU law”. It does not ask where the cable or the server physically sits — it asks whose law governs whoever controls it. That is exactly the distinction the Data Act already requires providers to declare, under Article 28: the jurisdiction of the ICT infrastructure, not the data centre’s address. We wrote about that yesterday, on cloud providers — who has to declare it, and how to check it in ten minutes. Point 25 extends the same logic to the whole of the point 24 list, not just to cloud: cables, masts, satellites, data rooms.
The high-risk vendor legislation does not exist yet
The rest of point 25 is a request, not an accomplished fact: the Parliament “calls on the Commission … to introduce legislation to mitigate risks posed by high-risk vendors from non-EU countries, including risks posed by foreign-controlled energy resource providers”. The Commission has not tabled it yet. On the mobile-network segment, point 45 goes further and calls for “stricter measures to de-risk high-risk vendors in 5G and 6G networks”, alongside dense deployment of small cells and macro towers in areas with inconsistent coverage — of a comparable obligation, limited to mobile and following a different legislative route, we have already written here. But a binding, cross-cutting criterion for “high-risk vendor” — one that covers a cable, a mast, a data room — does not exist today. Whoever has to choose a supplier for a route or a cabinet has no binding list to lean on: the criterion has to be written into the specification by whoever writes it. That is the most operational point in this piece.
How much these infrastructures weigh, according to the Parliament
Three recitals give a sense of what is at stake — and they need to be read for what they are: statements by the Parliament, set out in the recitals that introduce the resolution, not independent measurements the article adopts as its own. Recital AF notes that “trusted capacity and availability of data storage is essential for European resilience and development”, and that “most data centres in Europe are not owned by European companies”. Recital AH states that “around 9 % of global electricity consumption results from data centres, cloud services and connectivity”: in the text we checked, this figure carries no source reference, unlike other passages of the same resolution that cite studies complete with a footnote; it should therefore be treated as a statement by the Parliament, not as a measured, independently verifiable figure. Recital AI, finally, echoes what we wrote on 19 July about the submarine cables severed in the Baltic and the Red Sea: “submarine cables are critical infrastructure for global connectivity, economic stability and security, carrying over 99 % of international communications through them, and they remain vulnerable to physical damage, cyberthreats and geopolitical risks”.
The limit: a resolution is not a law
This needs to be said with the same clarity as everything else. A European Parliament own-initiative resolution (INI) creates no obligations, amends no existing rule, and cannot be cited in a dispute as the source of a duty. Point 24 obliges no one to do anything. Its value lies elsewhere, and it is still a value: it is a public, dated, citable list of what a European institution considers critical digital infrastructure, and a reliable indication of where the legislation is heading in the coming years. Whoever puts it into a specification is adopting it as a chosen criterion, not submitting to it as a binding rule — a distinction worth stating explicitly in the document, not left implied.
There is a second fact worth stating precisely. The resolution was adopted on 22 January 2026 and is published in the Official Journal today, 5 August: six and a half months later. That is not an anomaly — Parliament resolutions follow their own publication timetable, independent of the pace at which regulations are drafted — but it is worth keeping in mind when reading it: a text published today describes the picture as it stood in January. In the meantime, to give one concrete example, the Data Act transparency obligation on jurisdiction we wrote about yesterday had already been in force for months, and remains so regardless of this resolution.
The point
The point 24 list is useful exactly to the extent that it is treated as a checklist for the perimeter, not as a label to cite out loud. For each of its items — cables, masts, satellite systems, radio equipment, servers and rooms that process sensitive data, security software — the specification question is always the same: who is the supplier, which jurisdiction do they answer to, what gets verified at acceptance testing, what documentation stays on file. It is the work we bring into every compliance specification we write for a data centre or a telecommunications network: routes, supplier contracts, declared jurisdictions and acceptance checks stop being files scattered across different folders and become a single map of the site and the network, on which an AI flags that a critical route today depends on a supplier whose corporate ownership has changed, or that a room processing sensitive information has never had a jurisdiction declared in writing — together with CSIDIA, the group’s other company. The AI runs within the client’s perimeter, not outside it: on autonomous on-premise machines that require no deep integration into the existing network, or on dedicated cloud with a data centre in Italy, with shared management and our own teams, without subcontracting, across multi-vendor installations.
Do you need to write a specification that accounts for the items on the Parliament’s list, or check which suppliers in your perimeter are already covered? Talk to an engineer: the site visit is free, and the list takes ten minutes to read, not until the next tender.