The European Commission is pursuing revisions to the EU Cybersecurity Act to strengthen union-level supply-chain risk management for critical IT and telecom infrastructure, including the ability to impose targeted mitigations such as restrictions or bans on components from “high-risk suppliers.” Reporting indicates the proposal could effectively force member states to remove non-compliant equipment within a relatively short window—potentially as little as three years—as part of a broader effort to counter increasingly sophisticated hybrid threats to European infrastructure.
The initiative is widely viewed as an attempt to harmonize and accelerate national actions that have been uneven across the bloc, amid long-running concerns about reliance on vendors such as Huawei and ZTE in 5G and other network deployments. The Commission’s approach emphasizes coordinated risk assessments and common rules for supplier trust decisions, reflecting ongoing debate over whether certain third-country suppliers could be compelled—via domestic legal obligations—to support state espionage or disruption operations, despite vendor denials of wrongdoing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Huawei said excluding suppliers based on country of origin rather than technical evidence would violate EU legal principles and WTO obligations, and stated it would continue operating legally in Europe. The response came as the Commission's proposed reforms were reported publicly.
As part of the same review, the Commission proposed that member states could be required to remove non-compliant communications-network components within a maximum of 36 months after an EU high-risk supplier list is published. The measure is widely seen as targeting vendors such as Huawei and ZTE where some member states have been reluctant to impose restrictions.
The European Commission sought a revision of the EU Cybersecurity Act to address supply-chain and national security risks from IT and telecom equipment sourced from third countries. The proposal includes EU-level risk assessments, mitigation measures, and the possibility of banning components from suppliers designated as high risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.