• The proposed Cybersecurity Act 2 would require designated high-risk components to leave key mobile-network assets within 36 months
  • Connect Europe and GSMA Europe want the supply-chain provisions removed, citing cost and operational pressure

The fact

The European Commission proposed a revised Cybersecurity Act in January that would turn parts of the EU's approach to high-risk telecom suppliers into binding rules. The proposal is still being negotiated and has not become law. Under Title IV, equipment from suppliers designated as high risk could have to be removed from key mobile, fixed and satellite network assets. For mobile networks, the proposed deadline is no more than 36 months after the relevant supplier list is published.

The proposal does not name Huawei or ZTE. The Commission has separately said that member-state restrictions on the two companies are justified under the 5G Toolbox. Connect Europe and GSMA Europe want Title IV removed, arguing that mandatory replacement would create heavy financial and operational costs.

Germany already has its own timetable. Critical 5G core components are due to be removed by the end of 2026, while critical management systems in access and transport networks must be replaced by the end of 2029. That does not mean every piece of access and transport equipment must be removed by 2029.

The assessment

How difficult this becomes depends on what equipment the final EU rules cover. Replacing core systems is concentrated in a relatively small number of locations. If the rules reach further into radio and transport networks, operators face work across many more sites, with equipment swaps, testing, integration and maintenance windows.

The 36-month deadline could therefore affect operators very differently. Some already have replacement programmes under way; others may have equipment scheduled to remain in service for years. A common deadline could force those upgrades forward.

For BTW readers, the important detail is which network assets fall under the final rules. If the requirement reaches deep into access and transport networks, compliance becomes a large field-engineering programme rather than a concentrated core-network migration.

What to watch

Watch how Parliament and the Council amend Title IV, particularly the definition of key ICT assets, the process for designating high-risk suppliers and when the 36-month clock starts. Germany's 2029 access-and-transport management-system deadline provides a useful comparison. Funding or compensation provisions would also affect how much replacement spending operators must absorb themselves.