$ 45.05 € 50.48 zł 11.52
+17° Kyiv +18° Warsaw +19° Washington

European Commission proposes new rules for assessing ICT supplier risks — Cyprus Mail

UA.NEWS 23 September 2026 10:44
European Commission proposes new rules for assessing ICT supplier risks — Cyprus Mail

Cyprus-based Cyprus Mail writes that in January 2026, the European Commission presented a plan to update the EU Cybersecurity Act, known as CSA2. The proposal provides for a mechanism to assess and manage risks in information and communication technology supply chains in critical sectors at the EU level.

CSA2 is intended to modernize the voluntary cybersecurity certification system and strengthen the role of the EU Agency for Cybersecurity, ENISA. Under the new mechanism, the EU will be able to conduct coordinated risk assessments for specific ICT supply chains, identifying key ICT assets, threat actors, risks, vulnerabilities and possible response measures.

Assessment of countries and suppliers

If such an assessment indicates a serious and structural non-technical risk posed by a third country, the European Commission will be able to conduct a separate assessment of that country and designate it as a country of cybersecurity concern. The Commission will then be able to identify suppliers of ICT components linked to such a country through their place of establishment, control or ownership and include them on a list of high-risk suppliers.

For entities designated as essential or important under the NIS2 Directive, this may mean a ban on using, installing or integrating components from such suppliers into designated key ICT assets. A phased withdrawal of components already in use may also be envisaged. Separate restrictions may apply to cybersecurity certification, public procurement and EU funding.

More current news is available on the UA.News Telegram channel Telegram.

Rules for telecommunications

Stricter requirements are proposed for telecommunications networks. Components from suppliers recognized as high-risk must be phased out of key functions of mobile, fixed and satellite networks. According to the report, the deadline for such a phase-out is generally understood to be around three years from the time a supplier is added to the published list.

The authors note that risk assessments may take into account not only the technical characteristics of products, but also a company's place of establishment, ownership structure and control. Suppliers included on the high-risk list will not be able to obtain European cybersecurity certification, and existing certificates may be withdrawn without undue delay.

According to an estimate by the industry association GSMA, replacing equipment affected by the restrictions in Europe's mobile, fixed and transport networks could cost between €30 billion and €40 billion. GSMA also estimates a possible increase in equipment prices of around one quarter due to reduced competition among suppliers.

Read us on
Download our app