October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

EU Cybersecurity Act 2: Could It Ban High-Risk Suppliers?

The European Commission’s Cybersecurity Act 2 proposal could restrict high-risk suppliers in critical ICT assets, but no EU-wide ban is in force yet.
From TheFinanceBase Team8 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Not yet. On January 20, 2026, the European Commission proposed a revised Cybersecurity Act—often called Cybersecurity Act 2—that could let it restrict high-risk suppliers’ components in designated critical ICT assets. It is a pending proposal, not an EU-wide ban already in force. If adopted, the rules could affect telecom networks and certain entities covered by NIS2, but the restrictions would depend on later risk assessments and implementing acts.

What the proposal would do

The proposal, COM(2026) 11, would repeal and replace the existing EU Cybersecurity Act, Regulation (EU) 2019/881. Alongside changes to ENISA and the EU cybersecurity-certification framework, it would establish a mechanism for assessing ICT supply-chain risks and imposing targeted measures. The Commission’s proposed regulation sets out the relevant supply-chain provisions in Articles 98–109, with additional provisions for electronic communications in Articles 110–111.

The proposal does not itself name suppliers, ban products from a particular country, or prohibit every EU company from buying foreign technology. It would create a process through which the Commission could identify high-risk suppliers and specify restrictions for particular entities and assets.

How a supplier could become high-risk

The proposed process is conditional, and its details could change as Parliament and the Council negotiate the text. In broad terms, it would involve:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Assessing risk: EU-level work would identify ICT supply chains presenting significant cybersecurity concerns.
  2. Defining the assets at issue: The Commission could identify “key ICT assets” whose compromise could affect essential or sensitive functions, disrupt the internal market, enable data exfiltration, or create systemic exposure.
  3. Considering third-country concerns: The framework would allow a third country to be designated as posing cybersecurity concerns.
  4. Mapping and assessing suppliers: The Commission would consider factors including where a supplier is established and its ownership and control, drawing on information from suppliers, competent authorities, risk assessments, and other relevant input.
  5. Adopting implementing acts: The Commission could establish a high-risk-supplier list and specify which restrictions apply to which entities and assets.

Article 104 would allow the Commission to update supplier listings and provide for reassessment when relevant circumstances, such as ownership, control, or establishment, change. The proposed framework therefore points toward ongoing supplier monitoring rather than a one-time purchasing check. The Commission’s proposal contains the legal framework; a breakdown of Article 104 describes its supplier-assessment factors.

What “high risk” means—and does not mean

Risk is not limited to a proven software vulnerability. The proposal addresses non-technical supply-chain concerns as well, including foreign interference, ownership, control, legal exposure in a third country, and strategic dependency. A supplier could therefore face scrutiny even if no publicly demonstrated exploitable flaw is tied to a particular product. The Commission describes the broader policy context on its Cybersecurity Act policy page.

That is not the same as an automatic nationality-based ban. The proposal does not name China, Huawei, ZTE, or any other country or company as already designated. A supplier’s place of establishment alone may not settle the question, since ownership and control are also relevant. Any claim that a particular company is covered would require an official designation or applicable implementing act.

Which organizations and systems could be affected?

The proposed restrictions could apply to specified entities covered by Annexes I and II of the NIS2 Directive, which include essential and important entities across sectors such as energy, transport, banking, health, water, digital infrastructure, public administration, space, manufacturing of critical products, digital services, and research. NIS2’s sector and entity framework is broad, but this proposal would not automatically impose the same supplier restriction on every entity in scope. Implementing acts could limit measures by sector, asset type, entity category, or company size.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

“Key ICT assets” would be selected rather than assumed to mean a supplier’s entire catalogue. Illustrative examples might include network-core equipment, radio-access-network components, network-management systems, or sensitive operational technology—but these are examples, not assets already designated by the Commission.

For electronic communications, the proposal specifically addresses mobile, fixed, and satellite networks. The potential reach is therefore broader than 5G alone, while the particular equipment, suppliers, operators, and conditions would depend on the final law and later acts.

What restrictions could be imposed?

Under proposed Article 103, implementing acts could prohibit specified entities from using, installing, or integrating components from listed high-risk suppliers in designated key ICT assets. The provision also reaches components that contain ICT components. The Commission could instead or additionally require mitigation measures such as:

  • Supply-chain transparency and disclosure.
  • Limits on data transfers to, or remote data processing from, third countries.
  • Network segmentation, monitoring, or disabling remote or physical access.
  • Disabling non-essential features.
  • Hardware and software testing.
  • Restrictions on outsourcing functions to managed-service providers.

So a future measure need not always mean immediate physical removal of every product. Depending on the implementing act, it could involve operational controls, restrictions on access or data handling, or limits on new use as well as replacement requirements.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens to equipment already in service?

The European Parliament’s legislative briefing says the proposal would require affected components to be phased out of electronic-communications networks within 36 months after publication of the high-risk-supplier list. That is a proposed transition period, not a current compliance deadline. The clock would not necessarily begin when the regulation takes effect; it would depend on the final text, relevant implementing acts, publication of a supplier list, and the assets and networks covered. See the European Parliament’s legislative file.

Operators would need to determine whether affected components are present, whether they must be replaced or can be addressed through other measures, and how to manage a transition without compromising service. Limited alternative suppliers, interoperability, certification, spare parts, support contracts, and migration time could all affect the practical plan. The proposal’s exact treatment of existing equipment versus new purchases remains subject to the final text and implementing acts.

Exemptions, procurement, and recourse

The proposal includes provisions on exemptions, rights of defense, confidentiality, and supplier reassessment. It does not describe affected suppliers or entities as having no recourse. However, the final eligibility rules, evidence requirements, deadlines, monitoring conditions, and grounds for withdrawing an exemption would depend on the enacted regulation and its implementing measures. The proposal’s structure for Articles 98–111 is summarized in this document overview.

Procurement is also conditional rather than a universal exclusion. The proposal’s explanatory text says that entities established in or controlled by third-country entities posing cybersecurity concerns may seek permission to provide components for key ICT assets and participate in related public procurement. At the same time, high-risk suppliers could face restrictions on participation in certain EU funding programs and instruments for relevant components. Buyers should not treat either outcome as automatic without checking the applicable act and procurement rules.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How this differs from existing EU cybersecurity rules

Framework What it does How it relates to the proposal
5G Cybersecurity Toolbox Provides coordinated guidance, including supplier restrictions, diversification, and dependency reduction. The proposed Act would add a mechanism for binding EU-level restrictions through implementing acts. See the Toolbox announcement.
NIS2 Directive Requires covered entities to manage cybersecurity risks and report incidents, including attention to supply-chain risk. The proposal would add a possible supplier-restriction mechanism; it would not replace existing NIS2 duties.
Cyber Resilience Act Sets cybersecurity obligations for manufacturers, importers, and distributors of products with digital elements. It addresses product cybersecurity obligations, while the proposal would address supply-chain security and potential restrictions on high-risk suppliers.
Cybersecurity Act 2 proposal Would revise EU certification and introduce an ICT supply-chain security framework. It remains under legislative consideration; its restrictions are not yet generally applicable.

The European Parliament has discussed the relationship between NIS2 and the Cyber Resilience Act in an answer on the two instruments. A European cybersecurity certificate would not necessarily resolve ownership or foreign-control concerns: the proposal contemplates certificate withdrawal where a supplier is classified as high-risk.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affected organizations can do now

The following are prudent preparations under the proposal’s approach, not new duties already imposed by Cybersecurity Act 2. They can also support existing supply-chain risk management.

  1. Inventory ICT dependencies: Record hardware, embedded components, network-management systems, cloud and hosted services, managed-service providers, remote-access tools, maintenance, and support.
  2. Map ownership and control: Document parent companies, subsidiaries, beneficial ownership, control rights, relevant government ties, data-processing locations, and remote-administration locations.
  3. Classify assets by criticality: Identify systems supporting essential services, processing sensitive data, creating cross-border disruption risk, or relying on a narrow supplier base.
  4. Test replacement feasibility: Assess alternative vendors, interoperability, certification, migration time, spare parts, firmware support, contract exit rights, and the cost of transition.
  5. Strengthen supplier contracts: Consider ownership-change notices, supply-chain disclosures, audit rights, remote-access limits, data-location terms, security-update commitments, and exit assistance.
  6. Keep evidence ready: Maintain supplier assessments, architecture diagrams, hardware and software inventories, risk decisions, monitoring and segmentation controls, and contingency plans.

A smaller supplier may not itself fall within NIS2’s direct scope but can still face due-diligence requests or substitution pressure from an in-scope customer. External supplier ratings and GRC tools can help organize evidence, but they cannot determine the Commission’s future legal classification or replace legal and engineering review.

Costs and operational trade-offs

The cost of a possible transition cannot be reduced to the price of replacement equipment. Depending on the affected asset and timetable, organizations may also need engineering work, parallel operations, interoperability tests, certification, staff training, site visits, service planning, and contract changes. The proposal does not establish a universal cost figure; actual exposure would depend on the equipment, network, available alternatives, and final requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Security versus cost: Replacement and migration can be expensive, while retaining a component may require compensating controls or be disallowed by a future act.
  • Supplier diversity versus complexity: Multiple suppliers can reduce dependency, but increase integration work and the number of interfaces that must be secured. The Commission’s ICT supply-chain toolbox addresses diversification and resilience.
  • Reduced dependency versus competition: Restrictions may reduce strategic exposure but also narrow the supplier pool, raise costs, or concentrate demand among a few approved providers.
  • Certification versus broader risk: Technical certification may not resolve questions about ownership, control, or foreign interference.
  • EU consistency versus timing uncertainty: A common mechanism could reduce uneven national approaches, but businesses may not know which assets or suppliers are covered until later decisions are made.

Where the proposal stands and what comes next

The Commission proposed Cybersecurity Act 2 on January 20, 2026. The European Parliament’s legislative file records committee work and a rapporteur, and indicates that Parliament and the Council still need to negotiate and agree on the final text. The EESC adopted an opinion on April 29, 2026, and the file records a feedback period ending May 12, 2026. As of August 18, 2026, the measure remains a proposal under consideration, not a completed supplier ban. Follow the Parliament legislative file and the Commission’s January 20 announcement for status updates.

If the regulation is adopted, the practical sequence would still include the relevant risk assessments and implementing acts, supplier and asset determinations, any exemptions or mitigation requirements, and applicable transition periods. The final law may differ from the Commission proposal. Until official designations and measures exist, no supplier should be described as banned under this proposal.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.