A new report from the Royal United Services Institute (RUSI) argues that the EU needs a common framework for assessing the risks of Chinese technology vendors in critical infrastructure. The think tank warns that the current patchwork of national policies leaves individual members exposed, and that Brussels should strengthen its own powers without overriding members' control over national security.
The EU's existing 5G security toolbox is voluntary, and only 10 of 27 member states have fully implemented it since it launched in 2020. The European Commission has proposed amendments to the Cyber Security Act that would let it compile a list of untrusted vendors, with Huawei and ZTE likely candidates. Countries using designated equipment would have 36 months to rip and replace it, but there is still no official definition of what makes a vendor "high-risk."
RUSI highlights how differently member states treat Chinese suppliers. Germany, whose largest trading partner is China, relied on Chinese vendors for an estimated 59 percent of its 5G radio access network in 2024. Spain accounted for 32 percent, and has shown less concern about national security implications. The UK, by contrast, plans to remove Chinese technology from its telecoms network entirely by the end of next year.
The report says concerns about Chinese vendors are "well-founded," citing legal obligations that give Beijing privileged access to vulnerabilities and data. It also notes economic risks, as Chinese products are often more capable and cheaper, creating dependencies that can be exploited politically. RUSI calls for a risk assessment framework that applies across the bloc while allowing sector-specific flexibility. The source is a single article from The Register, so no contrasting sources{