Full Report
RUSI wants procurement rethink that could put US suppliers under scrutiny too
Analysis Summary
# Regulation/Compliance: Proposed Amendments to the EU Cybersecurity Act (CSA)
## Overview
This initiative seeks to address the fragmented approach across EU member states regarding high-risk ICT vendors in critical infrastructure. It aims to transition from the voluntary "EU Toolbox for 5G Security" to a mandatory, harmonized framework that allows the European Commission to designate "untrusted vendors" and compel member states to remove their equipment from critical networks.
## Key Details
- **Issuing Authority:** European Commission (EC)
- **Effective Date:** TBD (Currently in proposal phase)
- **Jurisdiction:** European Union (27 Member States)
- **Status:** Proposed (Based on recommendations by the Royal United Services Institute - RUSI)
## Requirements
### Mandatory Requirements
1. **Vendor Preclusion:** Member states must exclude designated "untrusted vendors" from the networks of 18 defined critical sectors.
2. **"Rip and Replace":** Mandatory removal and replacement of existing infrastructure provided by designated high-risk vendors.
3. **Mandatory Reporting:** (Under Chinese law cited in the context) Tech companies must report vulnerabilities to the Chinese government within 48 hours, a practice the EU seeks to mitigate through vendor exclusion.
### Recommended Practices (RUSI Recommendations)
1. **Harmonized Risk Framework:** Develop a unified risk assessment framework that applies to all members without infringing on national security autonomy.
2. **Sector-Specific Profiles:** Lawmakers should account for different risk profiles across different sectors (e.g., telecoms vs. energy).
3. **Strategic Decoupling:** Prioritize security over cost-effectiveness in procurement for critical national infrastructure (CNI).
## Affected Organizations
- **Industries:** 18 critical sectors (including Telecoms, Judicial systems, Energy, and Transport).
- **Organization Size:** All sizes operating within CNI; however, primary impact is on large-scale infrastructure providers.
- **Geographic Scope:** European Union member states and their international technology suppliers (specifically those from China and potentially the US).
## Compliance Timeline
- **January 2020:** EU Toolbox for 5G Security launched (Voluntary).
- **Early 2026 (Projected):** Proposed amendments to the CSA introduced.
- **TBD:** Passage of CSA amendments.
- **Implementation Deadline:** 36 months post-designation for "Rip and Replace" completion.
## Implementation Guidance
### Assessment Phase
- **Inventory Audit:** Identify all ICT equipment and software sourced from vendors likely to be designated as high-risk (e.g., Huawei, ZTE).
- **Dependency Mapping:** Evaluate the degree of reliance on non-EU technology in 5G RAN stacks and cloud services.
### Implementation Phase
- **Vendor Diversification:** Shift procurement to "trusted" vendors, even if costs are higher.
- **Policy Alignment:** Update internal procurement policies to prioritize "economic courage" and security over mere cost-effectiveness.
### Validation Phase
- **EU Commission Audit:** Verification by the EC that designated vendors have been removed from the 18 critical sectors.
## Technical Requirements
- **Supply Chain Integrity:** Verification that vendors do not have state-mandated pipelines for intelligence services to access exploitable vulnerabilities.
- **Vulnerability Disclosure:** Requirement for vendors to adhere to Western disclosure standards rather than state-controlled reporting (as seen in China).
- **5G RAN Security:** Specific technical controls to reduce the presence of high-risk components in Radio Access Networks.
## Penalties & Enforcement
- **Fines:** Structure TBD; likely aligned with existing EU cybersecurity and GDPR-level penalty frameworks.
- **Other Consequences:** Mandatory exclusion from the EU market for vendors; forced decommissioning of equipment for operators.
- **Enforcement:** The European Commission will be empowered to build and maintain the "Untrusted Vendor" list, moving away from member-state discretion.
## Related Standards
- **EU Toolbox for 5G Security:** The voluntary predecessor to this mandatory proposal.
- **NIS2 Directive:** Aligns with broader EU efforts to secure critical network and information systems.
- **National Intelligence Laws (China):** The regulatory trigger for high-risk designations.
## Resources
- **Official Documentation:** [rusi.org/explore-our-research/publications/research-papers/high-risk-ict-vendors-and-critical-infrastructure-european-approaches]
- **Guidance Documents:** EU 5G Security Toolbox (Current Framework).
## Practical Recommendations
- **Avoid Vendor Lock-in:** Organizations should avoid deep integration with vendors subject to foreign intelligence control (e.g., China’s National Intelligence Law).
- **Monitor US-EU Relations:** Be aware that "high-risk" designations could eventually extend to US vendors under legal instruments like the Patriot Act if EU sovereignty concerns increase.
- **Budget for Transition:** Prepare financial contingencies for the 36-month "rip and replace" cycle, which is significantly more expensive than standard maintenance cycles.