
EU Aims to Bar Chinese Equipment from Critical Networks
The European Commission is working on plans to bar equipment from Chinese suppliers, such as Huawei and ZTE, from critical networks within the EU, according to a … Read more
The European Commission is working on plans to bar equipment from Chinese suppliers, such as Huawei and ZTE, from critical networks within the EU, according to a Financial Times article. The reason for this is increasing concerns about cybersecurity, geopolitical dependencies, and digital sovereignty. What was initially primarily a discussion for telecom operators and governments is now increasingly affecting companies that rely on complex (digital) supply chains.
The question that arises more and more often is: do you actually know where your technology, products, and services come from? And perhaps even more importantly: do you know what risks are associated with them?
What is the European Commission's Intention?
The European Commission wants to oblige member states to exclude suppliers deemed 'high-risk' from critical infrastructure. In practice, this primarily concerns Chinese technology in, among others, telecom and 5G networks, vital IT systems, and other sectors crucial to society.
Until now, EU guidelines were mainly advisory. In the new plans, these will become legally binding, with clear deadlines for phasing out certain suppliers. This aligns with a broader strategy concerning cybersecurity, strategic autonomy, and reducing dependencies on non-EU countries.
Why This Isn't Just a Telecom Story
While the news primarily focuses on critical networks, the impact extends far beyond telecom and vital infrastructure. Virtually every company today relies on external hardware and software suppliers, cloud and IT service providers, and supply chain partners who, in turn, use other technologies. This creates a long and often opaque supply chain, where origin, dependencies, and risks are not always clearly visible.
Precisely in such a complex chain, risks can accumulate unnoticed. What is permitted today may fall under new legislation or policy measures tomorrow. Organizations that lack good insight into their suppliers and technology then run the risk of having to act reactively, resulting in high replacement costs, compliance issues, and potential reputational damage.
The EU's intention is therefore primarily a wake-up call: organizations must better understand where their digital and technological dependencies lie.
From 'Where do I procure?' to 'What risk am I procuring?'
On the one hand, this development demands a different kind of insight; on the other hand, it requires a different way of acting. The central question shifts from 'Where do I procure?' to 'What risk am I procuring?'. While suppliers were previously primarily assessed on price, quality, and continuity, today geopolitical and cybersecurity aspects play an increasingly significant role. Organizations must understand in which country a supplier operates, what laws and regulations that party is subject to, and what risks that entails.
Furthermore, it's not just about the direct supplier, but also what lies behind them. What incidents or vulnerabilities have occurred? And which shadow suppliers are part of the same chain? These questions cannot be answered with a one-time inventory. They require structural and up-to-date insight so that risks can be continuously monitored and factored into decisions about procurement, collaboration, and continuity.
Conclusion
The European Commission's intention to bar Chinese equipment from critical networks is more than geopolitical policy. It underscores a broader trend: companies are becoming increasingly responsible for the risks in their digital and technological supply chain.
Those who already have insight into origin, dependencies, and digital risks today can anticipate new rules, incidents, and strategic choices more quickly. With RiskStudio, organizations gain that insight. Continuous, scalable, and fact-based.