Europe’s telecommunications industry is confronting a stark question at the heart of the European Union’s proposed supply-chain security overhaul: who pays to remove and replace high-risk network equipment at continental scale? A new GSMA Intelligence assessment, reported by The Register, places the direct cost of removing designated high-risk vendor equipment from EU mobile, fixed, and transport networks at €30 billion to €40 billion—before accounting for higher future equipment prices, operational disruption, or delayed network investment.
That is not simply a procurement problem for Huawei, ZTE, Ericsson, Nokia, or Europe’s mobile operators. It is a test of whether Europe can pursue strategic autonomy and stronger cybersecurity without weakening the affordability, coverage, and upgrade pace of the digital infrastructure on which its wider economy depends.
The numbers should be treated seriously, but not uncritically. They come from an industry-backed analysis based on operator data, not from a completed regulatory impact assessment or a final implementation plan. Yet the underlying policy direction is real: the European Commission has proposed a revised Cybersecurity Act 2, or CSA2, that could allow EU-wide restrictions on designated high-risk suppliers in critical ICT supply chains. The proposed regime would be far more consequential than the earlier voluntary 5G security toolbox because it creates a mechanism for enforceable phase-outs, supplier designations, and restrictions on key network assets. European Commission
The immediate controversy concerns a proposed three-year removal timetable for high-risk suppliers in mobile 5G networks. Under the Commission’s proposal, operators would need to adjust vendor strategies, network planning, and investment roadmaps to comply with a mandatory EU-wide framework rather than a patchwork of national restrictions. European Commission
The policy has obvious geopolitical implications. In practical terms, public debate has centered on Chinese suppliers, particularly Huawei and ZTE. The Commission previously said restrictions or exclusions involving those companies were justified under the EU’s 5G security toolbox, describing them as presenting materially higher risks than other 5G suppliers. European Commission
But the draft law is designed more broadly than a simple company blacklist. Its language focuses on high-risk suppliers, third countries posing cybersecurity concerns, and key ICT assets. That distinction matters because the regulatory model is meant to be reusable across sectors and technologies, not restricted forever to the radio access network equipment installed at 5G mast sites.
The central tension is therefore straightforward:
CSA2 would change the center of gravity. The Commission’s proposal would create an EU-level mechanism for identifying high-risk suppliers, identifying the ICT assets considered critical, and imposing mitigations ranging from transparency obligations to outright prohibitions on using specified components. EUR-Lex
Crucially, the proposal is not yet the same thing as an immediate Europe-wide Huawei ban. The legislative text gives the Commission powers that would be exercised through subsequent implementing acts. Those acts would need to define the relevant supplier categories, affected entities, critical assets, restrictions, and appropriate transition periods. EUR-Lex
That procedural detail is easy to miss, but it is important for network operators. The final financial impact will depend on choices still to be made:
That is a strength of the framework. It recognizes that cybersecurity risk is not always binary. In some cases, segmentation, controlled access, audited operations, or tighter maintenance procedures may reduce risk without requiring immediate replacement of every device in the field.
However, the same proposal also permits prohibitions on using, installing, or integrating components from designated high-risk suppliers in key assets. It therefore reserves the option of a much harder outcome where policymakers believe mitigation is insufficient. EUR-Lex
For European telcos, the uncertainty is not academic. A network operator can plan around a clear long-term rule. It is much harder to efficiently budget for a regime where scope, asset definitions, supplier designations, and replacement timetables may emerge in stages.
According to the assessment reported by The Register, the estimated €30 billion to €40 billion direct cost spans three broad categories:
The largest risk is not necessarily that a network fails outright. Operators are experienced at staged migration. The more realistic concern is that capital expenditure, skilled engineering capacity, and executive attention are diverted from expansion and innovation to regulatory compliance.
That distinction has consequences for Europe’s digital ambitions. A network can remain operational while still being delayed in deploying advanced 5G features, edge computing support, standalone 5G cores, private-network capabilities, fiber extensions, or eventual 6G preparations.
The analysis reported by The Register estimates that reduced supplier competition could raise equipment prices by roughly:
A smaller viable supplier pool can bring real risks:
That outcome is avoidable, but it requires the Commission and member states to make supplier diversity a measurable implementation objective rather than a rhetorical aspiration.
Yet industrial policy should not obscure the customer side of the equation. A supplier market with fewer credible competitors can improve the strategic position of surviving vendors while worsening purchase terms for operators. Europe should not assume that strengthening domestic champions automatically produces lower costs, faster innovation, or better service outcomes for users.
The policy has to do both: protect the supply chain and preserve genuine competition.
The Commission’s draft legislation cites strategic threats including ransomware and wiper attacks, supply-chain attacks, network intrusions, and distributed denial-of-service attacks in its discussion of the cybersecurity and resilience risks facing Europe’s communications infrastructure. EUR-Lex
The policy logic is not necessarily that every component from a designated supplier contains a proven backdoor. Rather, the framework is concerned with systemic risk: ownership and control structures, legal exposure to a third country, the prospect of undue interference, operational access, concentration, and the consequences of compromise in critical infrastructure.
This is a more sophisticated argument than a narrow debate over whether a particular device has a detected vulnerability. Security decisions in essential infrastructure often account for the risk of coercion, denial of support, compromised update processes, intelligence collection, or strategic disruption during a crisis.
The Commission’s proposal even allows suppliers to seek exemptions if they can provide clear evidence that effective measures address non-technical risk and prevent undue interference by a third country. EUR-Lex
That provision is notable. It suggests the EU is attempting—at least in legislative design—to preserve a due-process mechanism rather than rely solely on country-of-origin assumptions.
The UK later retained the 2027 deadline in legal notices issued to operators, while recognizing the practical complexity of compliance. UK Government
A government-backed independent report on telecom supply-chain diversification estimated that removing Huawei would cost UK industry approximately £2 billion across network generations and technologies. It also noted that, unlike the United States, the UK did not create an equivalent public funding scheme to reimburse operators for those removal costs. UK Government
Europe should be cautious about making simplistic comparisons between the UK and the EU. The EU has far more operators, more national regulatory systems, different levels of vendor exposure, and vastly larger combined fixed, mobile, and transport infrastructure. Still, the British case demonstrates three key realities.
That is not an argument against removal. It is an argument for technically credible timelines. A deadline that forces hurried work can increase outage risk, strain engineering teams, and lead to wasteful duplication where operators replace equipment before the end of its useful lifecycle.
That is particularly important in Europe, where telecom operators often face lower returns and more fragmented market conditions than their counterparts in some other large regions. A security mandate may be justified, but policymakers should be honest that it has an opportunity cost unless accompanied by financing, tax incentives, spectrum-policy reform, or targeted support.
Europe should draw the same conclusion. A secure network ecosystem needs more than approved vendors; it needs interoperable architectures, robust testing, skilled engineering, competitive procurement, long-term support, and credible alternatives.
That should lead to a risk-ranked migration plan, not a one-size-fits-all demolition timetable. The most sensitive systems should receive the earliest attention. Less critical equipment should be replaced through planned modernization cycles where possible, unless a specific security assessment justifies faster action.
Possible approaches include:
That principle should translate into practical policy:
But the existence of a substantial cost does not settle the question against action. Critical infrastructure is often expensive precisely because failure has consequences that ordinary market calculations do not capture. The relevant policy comparison is not “€40 billion versus zero.” It is the cost of managed replacement and stronger resilience versus the potential economic and strategic cost of maintaining unacceptable dependency in essential networks.
The Commission’s proposed framework contains the bones of a balanced approach: risk assessments, critical-asset identification, transition periods, proportionality considerations, economic and societal impact assessments, and the availability of alternatives are all explicitly contemplated in the legal text. EUR-Lex
The danger lies in implementation. If Europe turns CSA2 into a blunt deadline with little funding, vague technical scope, and insufficient attention to vendor concentration, it could achieve formal compliance while making networks more expensive and slowing upgrades that businesses and citizens need.
If, instead, the EU pairs targeted restrictions with transparent risk criteria, credible transition periods, operator investment support, and an active competition strategy, it can pursue a more durable result: telecom networks that are not merely free of designated high-risk equipment, but are also more secure, more diverse, more affordable, and better prepared for the next generation of connectivity.
That is not simply a procurement problem for Huawei, ZTE, Ericsson, Nokia, or Europe’s mobile operators. It is a test of whether Europe can pursue strategic autonomy and stronger cybersecurity without weakening the affordability, coverage, and upgrade pace of the digital infrastructure on which its wider economy depends.
The numbers should be treated seriously, but not uncritically. They come from an industry-backed analysis based on operator data, not from a completed regulatory impact assessment or a final implementation plan. Yet the underlying policy direction is real: the European Commission has proposed a revised Cybersecurity Act 2, or CSA2, that could allow EU-wide restrictions on designated high-risk suppliers in critical ICT supply chains. The proposed regime would be far more consequential than the earlier voluntary 5G security toolbox because it creates a mechanism for enforceable phase-outs, supplier designations, and restrictions on key network assets. European Commission
Overview: a cybersecurity proposal with infrastructure-scale consequences
The immediate controversy concerns a proposed three-year removal timetable for high-risk suppliers in mobile 5G networks. Under the Commission’s proposal, operators would need to adjust vendor strategies, network planning, and investment roadmaps to comply with a mandatory EU-wide framework rather than a patchwork of national restrictions. European CommissionThe policy has obvious geopolitical implications. In practical terms, public debate has centered on Chinese suppliers, particularly Huawei and ZTE. The Commission previously said restrictions or exclusions involving those companies were justified under the EU’s 5G security toolbox, describing them as presenting materially higher risks than other 5G suppliers. European Commission
But the draft law is designed more broadly than a simple company blacklist. Its language focuses on high-risk suppliers, third countries posing cybersecurity concerns, and key ICT assets. That distinction matters because the regulatory model is meant to be reusable across sectors and technologies, not restricted forever to the radio access network equipment installed at 5G mast sites.
The central tension is therefore straightforward:
- Security policymakers want the power to reduce dependencies that could create national-security, espionage, sabotage, coercion, or supply-chain risks.
- Telecom operators warn that forced removal will consume capital that could otherwise expand 5G coverage, modernize fixed networks, improve resilience, and begin the long transition toward 6G.
- Consumers and businesses may eventually bear a portion of the cost through higher prices, slower upgrades, or less ambitious rural and enterprise connectivity investment.
- European equipment vendors could gain a stronger home-market position, but a reduced supplier pool could also make network equipment more expensive and procurement less flexible.
What CSA2 would actually do
More than a voluntary 5G toolbox
The EU’s original 5G cybersecurity toolbox established a common framework for member states to assess supplier risks, protect critical and sensitive network functions, and diversify vendors. It was important, but its implementation was uneven because national governments retained discretion over how aggressively to apply restrictions. ENISACSA2 would change the center of gravity. The Commission’s proposal would create an EU-level mechanism for identifying high-risk suppliers, identifying the ICT assets considered critical, and imposing mitigations ranging from transparency obligations to outright prohibitions on using specified components. EUR-Lex
Crucially, the proposal is not yet the same thing as an immediate Europe-wide Huawei ban. The legislative text gives the Commission powers that would be exercised through subsequent implementing acts. Those acts would need to define the relevant supplier categories, affected entities, critical assets, restrictions, and appropriate transition periods. EUR-Lex
That procedural detail is easy to miss, but it is important for network operators. The final financial impact will depend on choices still to be made:
- Which suppliers are designated.
- Which parts of a network count as key ICT assets.
- Whether restrictions cover only future procurement or installed equipment too.
- How quickly phase-out periods run.
- Whether fixed, mobile, satellite, cloud-managed, and transport layers receive different deadlines.
- Whether exemptions are available in narrowly defined cases.
A more risk-based framework than a blanket technical ban
The proposed regulation contains a broader set of potential mitigation measures than just removal. These include supplier transparency requirements, restrictions on data transfers or remote processing from third countries, third-party-audited technical measures, network segmentation, disabling non-essential functions, operational monitoring, hardware and software testing, and vendor diversification requirements. EUR-LexThat is a strength of the framework. It recognizes that cybersecurity risk is not always binary. In some cases, segmentation, controlled access, audited operations, or tighter maintenance procedures may reduce risk without requiring immediate replacement of every device in the field.
However, the same proposal also permits prohibitions on using, installing, or integrating components from designated high-risk suppliers in key assets. It therefore reserves the option of a much harder outcome where policymakers believe mitigation is insufficient. EUR-Lex
For European telcos, the uncertainty is not academic. A network operator can plan around a clear long-term rule. It is much harder to efficiently budget for a regime where scope, asset definitions, supplier designations, and replacement timetables may emerge in stages.
The €40 billion estimate: what the telco industry is warning about
GSMA Intelligence says it conducted research on the cost of removing critical high-risk-vendor components from European telecom networks using information supplied by European operator groups. The research organization describes the potential measures as one of the most significant structural interventions in the European telecoms sector in decades. GSMA IntelligenceAccording to the assessment reported by The Register, the estimated €30 billion to €40 billion direct cost spans three broad categories:
- Mobile networks, including radio access network equipment and associated systems.
- Fixed networks, where vendor equipment may be embedded across broadband access and core infrastructure.
- Transport networks, including the optical and transmission systems that carry traffic between network locations and across borders.
- €19 billion to mobile network replacement;
- €5 billion to fixed infrastructure; and
- €11 billion to transport networks.
The hidden work behind “rip and replace”
Replacing installed network gear can require operators to:- Redesign radio and transport architecture.
- Re-engineer interoperability across multi-vendor environments.
- Reconfigure network-management platforms.
- Retest security, performance, and reliability.
- Arrange tower access, field engineering, and local permitting.
- Train operational teams on new systems.
- Replace spares, maintenance tooling, and support processes.
- Rework contracts and service-level agreements.
- Manage service continuity during cutovers.
The largest risk is not necessarily that a network fails outright. Operators are experienced at staged migration. The more realistic concern is that capital expenditure, skilled engineering capacity, and executive attention are diverted from expansion and innovation to regulatory compliance.
That distinction has consequences for Europe’s digital ambitions. A network can remain operational while still being delayed in deploying advanced 5G features, edge computing support, standalone 5G cores, private-network capabilities, fiber extensions, or eventual 6G preparations.
The second bill: less competition means higher prices
The headline replacement cost is only the first layer of the GSMA Intelligence warning. The more persistent concern is the effect on the economics of the telecom equipment market after high-risk suppliers are excluded.The analysis reported by The Register estimates that reduced supplier competition could raise equipment prices by roughly:
- 24% for mobile network equipment;
- up to 19% for fixed-network equipment; and
- around 10% for transport equipment.
Why vendor concentration matters
Telecom infrastructure is not a consumer electronics market. Equipment has long support cycles, extensive interoperability requirements, custom integration work, and mission-critical reliability expectations. Operators cannot treat a national radio network like a laptop fleet and simply move procurement to the cheapest available alternative.A smaller viable supplier pool can bring real risks:
- Less price pressure in tenders.
- Fewer alternatives when a vendor’s product roadmap disappoints.
- Greater dependency on individual suppliers.
- More difficult negotiations over maintenance, upgrades, and intellectual-property terms.
- Reduced resilience if a single vendor faces production, software, security, or geopolitical problems.
That outcome is avoidable, but it requires the Commission and member states to make supplier diversity a measurable implementation objective rather than a rhetorical aspiration.
The case for European suppliers is real—but not cost-free
Nokia and Ericsson are strategically significant European network-equipment suppliers, and a policy that favors trusted, locally aligned supply chains could strengthen their market position. That may appeal to policymakers seeking technological sovereignty, manufacturing capability, research investment, and a stronger European telecom industrial base.Yet industrial policy should not obscure the customer side of the equation. A supplier market with fewer credible competitors can improve the strategic position of surviving vendors while worsening purchase terms for operators. Europe should not assume that strengthening domestic champions automatically produces lower costs, faster innovation, or better service outcomes for users.
The policy has to do both: protect the supply chain and preserve genuine competition.
Security is a legitimate objective, not a side issue
It would be a mistake to dismiss the policy as mere protectionism or assume that the debate is only about equipment pricing. Telecommunications networks are foundational infrastructure. They carry emergency communications, financial traffic, industrial data, government services, cloud workloads, and consumer connectivity.The Commission’s draft legislation cites strategic threats including ransomware and wiper attacks, supply-chain attacks, network intrusions, and distributed denial-of-service attacks in its discussion of the cybersecurity and resilience risks facing Europe’s communications infrastructure. EUR-Lex
The policy logic is not necessarily that every component from a designated supplier contains a proven backdoor. Rather, the framework is concerned with systemic risk: ownership and control structures, legal exposure to a third country, the prospect of undue interference, operational access, concentration, and the consequences of compromise in critical infrastructure.
This is a more sophisticated argument than a narrow debate over whether a particular device has a detected vulnerability. Security decisions in essential infrastructure often account for the risk of coercion, denial of support, compromised update processes, intelligence collection, or strategic disruption during a crisis.
The Commission’s proposal even allows suppliers to seek exemptions if they can provide clear evidence that effective measures address non-technical risk and prevent undue interference by a third country. EUR-Lex
That provision is notable. It suggests the EU is attempting—at least in legislative design—to preserve a due-process mechanism rather than rely solely on country-of-origin assumptions.
What the United Kingdom’s experience can teach Europe
The United Kingdom provides a useful, if imperfect, real-world comparison. The UK required Huawei equipment to be removed from public 5G networks by the end of 2027, following a policy shift linked to updated security advice concerning the impact of US sanctions on Huawei’s supply chain. UK GovernmentThe UK later retained the 2027 deadline in legal notices issued to operators, while recognizing the practical complexity of compliance. UK Government
A government-backed independent report on telecom supply-chain diversification estimated that removing Huawei would cost UK industry approximately £2 billion across network generations and technologies. It also noted that, unlike the United States, the UK did not create an equivalent public funding scheme to reimburse operators for those removal costs. UK Government
Europe should be cautious about making simplistic comparisons between the UK and the EU. The EU has far more operators, more national regulatory systems, different levels of vendor exposure, and vastly larger combined fixed, mobile, and transport infrastructure. Still, the British case demonstrates three key realities.
First, deadlines must reflect operational constraints
The UK government acknowledged that bringing certain requirements forward could increase the risk of consumer disruption and impose substantial costs. UK GovernmentThat is not an argument against removal. It is an argument for technically credible timelines. A deadline that forces hurried work can increase outage risk, strain engineering teams, and lead to wasteful duplication where operators replace equipment before the end of its useful lifecycle.
Second, funding policy shapes deployment outcomes
If governments mandate removal while leaving operators to absorb every cost, the financial burden will likely surface elsewhere. It can appear in retail pricing, slower rollout plans, lower returns for investors, or reduced capital available for remote-area coverage.That is particularly important in Europe, where telecom operators often face lower returns and more fragmented market conditions than their counterparts in some other large regions. A security mandate may be justified, but policymakers should be honest that it has an opportunity cost unless accompanied by financing, tax incentives, spectrum-policy reform, or targeted support.
Third, supplier diversity requires more than exclusions
Removing one supplier does not automatically build a resilient market. The UK has explicitly framed telecom supply-chain diversification as a policy challenge in its own right. UK GovernmentEurope should draw the same conclusion. A secure network ecosystem needs more than approved vendors; it needs interoperable architectures, robust testing, skilled engineering, competitive procurement, long-term support, and credible alternatives.
A better implementation model for Europe
The strongest version of CSA2 would not be one that simply mandates the fastest possible removal of Chinese telecom equipment. It would be one that measurably improves resilience while minimizing disruption to Europe’s connectivity investment.Create a transparent asset-risk hierarchy
Not all network equipment carries the same strategic significance. A sensible framework should distinguish among:- Core-network functions.
- Network management and orchestration systems.
- Remote-access and maintenance systems.
- Radio access networks.
- Optical transport and backbone equipment.
- Fixed broadband access infrastructure.
- Subsea cable and satellite-related systems.
- Legacy equipment approaching scheduled retirement.
That should lead to a risk-ranked migration plan, not a one-size-fits-all demolition timetable. The most sensitive systems should receive the earliest attention. Less critical equipment should be replaced through planned modernization cycles where possible, unless a specific security assessment justifies faster action.
Pair mandates with funding mechanisms
If direct replacement costs genuinely approach €40 billion, EU policymakers need to decide whether it is reasonable to place the entire burden on operators and, ultimately, customers.Possible approaches include:
- Targeted grants for high-risk, high-cost replacements.
- Low-interest infrastructure financing.
- Tax treatment that supports accelerated depreciation.
- State-aid-compatible support for rural and hard-to-replace infrastructure.
- Spectrum-policy reforms that reduce operators’ capital burden.
- EU procurement and research programs that expand the alternative supplier ecosystem.
Make competition a measurable security outcome
Vendor diversity should be included in national and EU implementation metrics. The Commission’s own proposal lists diversification of ICT-component supply as a possible mitigation measure. EUR-LexThat principle should translate into practical policy:
- Require multi-vendor resilience plans for critical functions.
- Encourage interoperable interfaces and open standards where they are mature enough for production deployment.
- Support testing and certification capacity for newer vendors.
- Prevent one approved supplier from becoming unavoidable in a particular network layer.
- Monitor pricing, delivery lead times, and support quality after restrictions take effect.
The cost of inaction versus the cost of haste
The GSMA’s €30 billion-to-€40 billion estimate is a warning that the EU cannot treat high-risk vendor removal as a cheap or administrative exercise. The policy will consume money, engineering resources, and time. It may increase the cost of future infrastructure investment and complicate network operations for years.But the existence of a substantial cost does not settle the question against action. Critical infrastructure is often expensive precisely because failure has consequences that ordinary market calculations do not capture. The relevant policy comparison is not “€40 billion versus zero.” It is the cost of managed replacement and stronger resilience versus the potential economic and strategic cost of maintaining unacceptable dependency in essential networks.
The Commission’s proposed framework contains the bones of a balanced approach: risk assessments, critical-asset identification, transition periods, proportionality considerations, economic and societal impact assessments, and the availability of alternatives are all explicitly contemplated in the legal text. EUR-Lex
The danger lies in implementation. If Europe turns CSA2 into a blunt deadline with little funding, vague technical scope, and insufficient attention to vendor concentration, it could achieve formal compliance while making networks more expensive and slowing upgrades that businesses and citizens need.
If, instead, the EU pairs targeted restrictions with transparent risk criteria, credible transition periods, operator investment support, and an active competition strategy, it can pursue a more durable result: telecom networks that are not merely free of designated high-risk equipment, but are also more secure, more diverse, more affordable, and better prepared for the next generation of connectivity.
References
- Primary source: The Register
Published: 2026-07-24T10:45:00+00:00
Loading…
www.theregister.com