Breaking
SecurityDeveloping Story

RUSI: EU Vendor Rules Face Definition Gap

RUSI warns the EU lacks a clear high-risk vendor definition, leaving members exposed to Chinese equipment risks.

··2 hours ago·7 min read
Communication tower with a worker against a cloudy sky
Photo by David Marquez on Unsplash

European countries treat the same foreign telecom vendors in radically different ways, and a UK-based think tank says the EU's current patchwork of tech policy is not built to handle that reality. On 1 October 2026, the Royal United Services Institute (RUSI) argued that the bloc needs a shared way of assessing risk — and stronger powers to act on it — without stepping on member states' rights to set their own national security policy.

The question is not theoretical. Equipment from Chinese suppliers sits in the 5G radio access networks of several EU members, and the rules meant to govern those choices have been voluntary, unevenly adopted, and — in RUSI's reading — easy to work around.

A voluntary toolbox, barely used

The EU's main telecom security instrument is the EU Toolbox for 5G Security, which launched in January 2020 as a framework of harmonized standards for mitigating 5G-related risk. Its central weakness, the report notes, is that it is voluntary.

According to RUSI, only 10 of 27 member states have fully implemented the Toolbox. That adoption gap is the backdrop for everything else in the debate: a framework that asks countries to harden their networks but cannot compel them to do so.

The European Commission has tried to close that gap. Earlier this year it proposed amendments to the Cyber Security Act (CSA) that would let it build a list of untrusted vendors, which member states would be required to exclude from the networks of 18 critical sectors. Equipment from a designated vendor would have to be ripped out and replaced within 36 months if the amendments pass.

The Commission has already signaled that it would propose listing Huawei and ZTE should those amendments become law.

Nobody has defined 'high risk'

Before the EU starts naming vendors, RUSI argues, it has to decide what a high-risk vendor actually is. There is still no official definition of the term, and it is not a legal category.

That absence matters because it gives countries room to interpret the label however suits them — buying the technology they want while sidestepping the scrutiny a formal designation would bring, should the CSA amendments take effect.

The think tank's researchers used Germany, Spain, and the UK as illustrations of three very different national approaches to the same vendors.

Three countries, three answers

Germany's most important trading partner is China, a relationship worth €251.8 billion ($284.4 billion) a year. Historically, the Bund has chosen to preserve those economic ties rather than reduce supply chain risk. Under Chancellor Friedrich Merz, that stance is shifting slowly, but RUSI does not expect a material change in Germany's 5G RAN composition in the near term. Chinese suppliers accounted for an estimated 59 percent of the country's 5G RAN in 2024.

Spain's exposure is smaller but still significant: Chinese equipment made up an estimated 32 percent of its 5G RAN in 2024, a share expected to shrink. The debate there intensified after a controversy in which Spain awarded Huawei a contract involving the storage of judicial wiretap recordings. RUSI describes Spanish procurement as often favoring the most cost-effective option, with a government that does not share the same national security concerns about China as the UK or US — or at least not to the same degree.

The UK, by contrast, is on track to remove Chinese technology from its telecoms network entirely by the end of next year, having yielded to sustained US pressure over Huawei.

The security case, in RUSI's words

RUSI does not treat concerns about Chinese IT vendors as speculative. It states that they "are well-founded," and that the Chinese government can empower authorities to exercise control over companies like Huawei.

Those mechanisms, per the report, include obliging firms to hand over data on demand, hosting Chinese Communist Party representatives inside companies, and requiring employees to report activity that signals a threat to national security.

RUSI also points to a separate law requiring tech companies to report vulnerabilities to the Chinese government within 48 hours of discovery — and to withhold that same disclosure from overseas counterparts, with the exception of the product vendor.

This converts China's private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities.

— Royal United Services Institute (RUSI)

The report adds that China has demonstrated both the willingness and the capability to launch cyberattacks against the critical national infrastructure of political adversaries.

Cheaper kit, harder choices

The risk is not only technical. RUSI notes that some Chinese vendors have developed more capable products than EU or US equivalents and sell them at more attractive prices, which makes it harder for countries to justify the extra expense of non-Chinese equipment.

That dynamic builds global reliance on Chinese products and can introduce what RUSI calls "unwelcome dependencies," cementing China as a dominant player in crucial supply chains. The report cites the heated 5G debate of 2019, when China threatened Germany with "consequences" over the two countries' economic ties.

A ban alone won't fix the problem

Part of RUSI's argument for a more considered assessment framework is that the Commission's current CSA amendments may not accomplish much on their own. Blanket bans on companies or countries do not directly address the underlying security issues that leave products vulnerable to attack.

Even with China excluded entirely from EU members' tech stacks, vendors from 'trusted' countries have shown they cannot deliver penetration-proof software — a point the report anchors to Salt Typhoon's high-profile attack on US telco networks in 2024.

US vendors could land on the list too

The designation mechanism cuts both ways. CSA-style listings could in principle apply to US companies, since some European countries view US vendors as similarly risky — for different reasons.

Merz's Germany is concerned about the state of the US-EU relationship, and RUSI notes that the same dependency worries directed at Chinese technology could easily be turned toward US suppliers if relations sour. In Spain, US cloud companies dominate the market, but anti-US sentiment is stronger than many outside observers realize, particularly around surveillance. Those concerns, combined with higher prices from some non-Chinese suppliers, have dampened Spain's appetite for ripping out equipment others consider high-risk.

RUSI relays one participant's account of how some officials frame the comparison:

One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China's National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient.

— Royal United Services Institute (RUSI)

What RUSI recommends

The think tank's central proposal is a new risk assessment framework applied consistently across all members, paired with stronger EU-level powers that stop short of overriding national security prerogatives. It has to reconcile two competing needs: securing the union, while preserving the flexibility for members to set domestic policy and for lawmakers to account for sector-specific risk profiles. Telecoms risks, RUSI notes, do not necessarily apply to other sectors the same way.

The report also frames procurement differently. If the EU wants policy to drive change, RUSI says it needs "greater economic courage" and a willingness to treat tech procurement as a means of securing critical infrastructure rather than "a compliance exercise."

  • 10 of 27 EU member states have fully implemented the voluntary EU Toolbox for 5G Security since its launch in January 2020.
  • Germany-China trade is worth €251.8 billion ($284.4 billion) annually; Chinese suppliers were an estimated 59 percent of Germany's 5G RAN in 2024.
  • Chinese equipment was an estimated 32 percent of Spain's 5G RAN in 2024.
  • Proposed CSA amendments would cover 18 critical sectors, with designated equipment to be removed within 36 months.
  • A Chinese law requires tech companies to report vulnerabilities to the government within 48 hours of discovery, while withholding disclosure from overseas counterparts.

Why this matters beyond Brussels

The practical effect of this debate lands on the networks that carry ordinary traffic — mobile, broadband, and the industrial systems layered on top. If the EU cannot settle on what makes a vendor high-risk, the CSA amendments could end up applying unevenly across the bloc, which leaves the members with the weakest assessment capacity as the softest targets in a shared market.

For operators and enterprise buyers, the near-term signal is uncertainty rather than clarity: a designation list that does not yet exist, a definition that has not been written, and a rip-and-replace clock that starts only if the rules pass. Companies with multi-country footprints may find their procurement decisions governed by whichever member state they operate in rather than by a single EU standard.

The more awkward inference is that any designation regime robust enough to name Chinese vendors is also robust enough to name US ones. RUSI's own examples suggest the mechanism's reach is a matter of politics, not architecture — which means the vendor risk conversation in Europe may end up being less about a specific country's laws and more about how much sovereignty each member is willing to trade for cost and capability.

#eu#5g security#huawei#zte#critical infrastructure#procurement

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories