Vendors & EquipmentHuaweiZteEuropean CommissionCybersecurity Act
EU Governments Push Back on Three-Year High-Risk Vendor Phase-Out
EU member states want a flexible, criteria-based phase-out of high-risk vendor kit instead of the EC's fixed three-year deadline, as operators face a €30bn-€40bn bill.
Why it matters
- EC proposed a three-year phase-out of high-risk supplier equipment under the revised Cybersecurity Act in January.
- GSMA Intelligence estimates replacement costs at €30 billion to €40 billion for European operators.
- Member states want the timeline determined by risk levels, equipment lifespan, compatibility and alternative availability.
- The rules are expected to hit Chinese vendors Huawei and ZTE hardest.
- Member states must discuss changes with politicians before enacting the Cybersecurity Act.
The story
European operators could get more time to rip out equipment from high-risk suppliers after EU governments asked the European Commission to scrap its fixed three-year phase-out deadline in favour of a criteria-based timeline.
A document seen by Reuters shows member states requested amendments to the EC proposal, arguing the phase-out period should be determined by multiple factors rather than a set date.
The factors governments want weighed include:
- risk levels attached to individual deployments
- the usable lifespan of installed equipment
- compatibility requirements with existing networks
- "the availability of suitable alternatives"
The request lands as the industry faces a bill of €30 billion to €40 billion to replace the equipment involved, according to GSMA Intelligence estimates.
What does the governments' request change?
The EC proposed revisions to the Cybersecurity Act in January to address what it called increased risks to the bloc's ICT supply chain from third-party suppliers. The Commission argued the overhaul would remove dangers posed to regional mobile networks.
The move targets Chinese vendors Huawei and ZTE in practice, though neither company is named as such in the framing of high-risk suppliers.
Under the revised procedure Reuters described, member states would need to discuss the planned changes with politicians before enacting the Cybersecurity Act, which contains the equipment overhaul requirement.
Governments' push for flexibility could stretch replacement timelines well beyond the Commission's three-year window, easing the immediate capex burden on operators but delaying the de-risking the EC set out to achieve.
How have vendors responded?
Huawei did not accept the Commission's rationale when it first outlined the plan. The vendor told Mobile World Live the move would violate basic EU legal principles and said it would continue to provide "secure and trusted products and services".
ZTE has not commented publicly in the same terms, but both Chinese suppliers stand to lose significant European RAN market share if the rules take effect across the bloc.
What happens next?
The timeline now depends on negotiations between member states and EU politicians over the final text of the Cybersecurity Act. If governments prevail, operators gain a criteria-driven schedule shaped by equipment lifecycles and the availability of alternative vendors — a process that could unfold over several years rather than a single three-year deadline.
Also reported
Source: Mobile World Live
More from Daniel Okafor
Show full bio
Senior reporter covering marketplaces and e-commerce at Telecom Gazette.
166 articles