Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Not yet. On January 20, 2026, the European Commission proposed a revised Cybersecurity Act—often called Cybersecurity Act 2—that could let it restrict high-risk suppliers’ components in designated critical ICT assets. It is a pending proposal, not an EU-wide ban already in force. If adopted, the rules could affect telecom networks and certain entities covered by NIS2, but the restrictions would depend on later risk assessments and implementing acts.
What the proposal would do
The proposal, COM(2026) 11, would repeal and replace the existing EU Cybersecurity Act, Regulation (EU) 2019/881. Alongside changes to ENISA and the EU cybersecurity-certification framework, it would establish a mechanism for assessing ICT supply-chain risks and imposing targeted measures. The Commission’s proposed regulation sets out the relevant supply-chain provisions in Articles 98–109, with additional provisions for electronic communications in Articles 110–111.
The proposal does not itself name suppliers, ban products from a particular country, or prohibit every EU company from buying foreign technology. It would create a process through which the Commission could identify high-risk suppliers and specify restrictions for particular entities and assets.
How a supplier could become high-risk
The proposed process is conditional, and its details could change as Parliament and the Council negotiate the text. In broad terms, it would involve:
Recommended Free Tools
#1 Best Overall
- Assessing risk: EU-level work would identify ICT supply chains presenting significant cybersecurity concerns.
- Defining the assets at issue: The Commission could identify “key ICT assets” whose compromise could affect essential or sensitive functions, disrupt the internal market, enable data exfiltration, or create systemic exposure.
- Considering third-country concerns: The framework would allow a third country to be designated as posing cybersecurity concerns.
- Mapping and assessing suppliers: The Commission would consider factors including where a supplier is established and its ownership and control, drawing on information from suppliers, competent authorities, risk assessments, and other relevant input.
- Adopting implementing acts: The Commission could establish a high-risk-supplier list and specify which restrictions apply to which entities and assets.
Article 104 would allow the Commission to update supplier listings and provide for reassessment when relevant circumstances, such as ownership, control, or establishment, change. The proposed framework therefore points toward ongoing supplier monitoring rather than a one-time purchasing check. The Commission’s proposal contains the legal framework; a breakdown of Article 104 describes its supplier-assessment factors.
What “high risk” means—and does not mean
Risk is not limited to a proven software vulnerability. The proposal addresses non-technical supply-chain concerns as well, including foreign interference, ownership, control, legal exposure in a third country, and strategic dependency. A supplier could therefore face scrutiny even if no publicly demonstrated exploitable flaw is tied to a particular product. The Commission describes the broader policy context on its Cybersecurity Act policy page.
That is not the same as an automatic nationality-based ban. The proposal does not name China, Huawei, ZTE, or any other country or company as already designated. A supplier’s place of establishment alone may not settle the question, since ownership and control are also relevant. Any claim that a particular company is covered would require an official designation or applicable implementing act.
Which organizations and systems could be affected?
The proposed restrictions could apply to specified entities covered by Annexes I and II of the NIS2 Directive, which include essential and important entities across sectors such as energy, transport, banking, health, water, digital infrastructure, public administration, space, manufacturing of critical products, digital services, and research. NIS2’s sector and entity framework is broad, but this proposal would not automatically impose the same supplier restriction on every entity in scope. Implementing acts could limit measures by sector, asset type, entity category, or company size.
“Key ICT assets” would be selected rather than assumed to mean a supplier’s entire catalogue. Illustrative examples might include network-core equipment, radio-access-network components, network-management systems, or sensitive operational technology—but these are examples, not assets already designated by the Commission.
For electronic communications, the proposal specifically addresses mobile, fixed, and satellite networks. The potential reach is therefore broader than 5G alone, while the particular equipment, suppliers, operators, and conditions would depend on the final law and later acts.
Rank #3
What restrictions could be imposed?
Under proposed Article 103, implementing acts could prohibit specified entities from using, installing, or integrating components from listed high-risk suppliers in designated key ICT assets. The provision also reaches components that contain ICT components. The Commission could instead or additionally require mitigation measures such as:
- Supply-chain transparency and disclosure.
- Limits on data transfers to, or remote data processing from, third countries.
- Network segmentation, monitoring, or disabling remote or physical access.
- Disabling non-essential features.
- Hardware and software testing.
- Restrictions on outsourcing functions to managed-service providers.
So a future measure need not always mean immediate physical removal of every product. Depending on the implementing act, it could involve operational controls, restrictions on access or data handling, or limits on new use as well as replacement requirements.
Free tools Windows power users keep installed
One-click scans. No signup required.
What happens to equipment already in service?
The European Parliament’s legislative briefing says the proposal would require affected components to be phased out of electronic-communications networks within 36 months after publication of the high-risk-supplier list. That is a proposed transition period, not a current compliance deadline. The clock would not necessarily begin when the regulation takes effect; it would depend on the final text, relevant implementing acts, publication of a supplier list, and the assets and networks covered. See the European Parliament’s legislative file.
Rank #4
Operators would need to determine whether affected components are present, whether they must be replaced or can be addressed through other measures, and how to manage a transition without compromising service. Limited alternative suppliers, interoperability, certification, spare parts, support contracts, and migration time could all affect the practical plan. The proposal’s exact treatment of existing equipment versus new purchases remains subject to the final text and implementing acts.
Exemptions, procurement, and recourse
The proposal includes provisions on exemptions, rights of defense, confidentiality, and supplier reassessment. It does not describe affected suppliers or entities as having no recourse. However, the final eligibility rules, evidence requirements, deadlines, monitoring conditions, and grounds for withdrawing an exemption would depend on the enacted regulation and its implementing measures. The proposal’s structure for Articles 98–111 is summarized in this document overview.
Procurement is also conditional rather than a universal exclusion. The proposal’s explanatory text says that entities established in or controlled by third-country entities posing cybersecurity concerns may seek permission to provide components for key ICT assets and participate in related public procurement. At the same time, high-risk suppliers could face restrictions on participation in certain EU funding programs and instruments for relevant components. Buyers should not treat either outcome as automatic without checking the applicable act and procurement rules.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
How this differs from existing EU cybersecurity rules
| Framework | What it does | How it relates to the proposal |
|---|---|---|
| 5G Cybersecurity Toolbox | Provides coordinated guidance, including supplier restrictions, diversification, and dependency reduction. | The proposed Act would add a mechanism for binding EU-level restrictions through implementing acts. See the Toolbox announcement. |
| NIS2 Directive | Requires covered entities to manage cybersecurity risks and report incidents, including attention to supply-chain risk. | The proposal would add a possible supplier-restriction mechanism; it would not replace existing NIS2 duties. |
| Cyber Resilience Act | Sets cybersecurity obligations for manufacturers, importers, and distributors of products with digital elements. | It addresses product cybersecurity obligations, while the proposal would address supply-chain security and potential restrictions on high-risk suppliers. |
| Cybersecurity Act 2 proposal | Would revise EU certification and introduce an ICT supply-chain security framework. | It remains under legislative consideration; its restrictions are not yet generally applicable. |
The European Parliament has discussed the relationship between NIS2 and the Cyber Resilience Act in an answer on the two instruments. A European cybersecurity certificate would not necessarily resolve ownership or foreign-control concerns: the proposal contemplates certificate withdrawal where a supplier is classified as high-risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What affected organizations can do now
The following are prudent preparations under the proposal’s approach, not new duties already imposed by Cybersecurity Act 2. They can also support existing supply-chain risk management.
- Inventory ICT dependencies: Record hardware, embedded components, network-management systems, cloud and hosted services, managed-service providers, remote-access tools, maintenance, and support.
- Map ownership and control: Document parent companies, subsidiaries, beneficial ownership, control rights, relevant government ties, data-processing locations, and remote-administration locations.
- Classify assets by criticality: Identify systems supporting essential services, processing sensitive data, creating cross-border disruption risk, or relying on a narrow supplier base.
- Test replacement feasibility: Assess alternative vendors, interoperability, certification, migration time, spare parts, firmware support, contract exit rights, and the cost of transition.
- Strengthen supplier contracts: Consider ownership-change notices, supply-chain disclosures, audit rights, remote-access limits, data-location terms, security-update commitments, and exit assistance.
- Keep evidence ready: Maintain supplier assessments, architecture diagrams, hardware and software inventories, risk decisions, monitoring and segmentation controls, and contingency plans.
A smaller supplier may not itself fall within NIS2’s direct scope but can still face due-diligence requests or substitution pressure from an in-scope customer. External supplier ratings and GRC tools can help organize evidence, but they cannot determine the Commission’s future legal classification or replace legal and engineering review.
Costs and operational trade-offs
The cost of a possible transition cannot be reduced to the price of replacement equipment. Depending on the affected asset and timetable, organizations may also need engineering work, parallel operations, interoperability tests, certification, staff training, site visits, service planning, and contract changes. The proposal does not establish a universal cost figure; actual exposure would depend on the equipment, network, available alternatives, and final requirements.
- Security versus cost: Replacement and migration can be expensive, while retaining a component may require compensating controls or be disallowed by a future act.
- Supplier diversity versus complexity: Multiple suppliers can reduce dependency, but increase integration work and the number of interfaces that must be secured. The Commission’s ICT supply-chain toolbox addresses diversification and resilience.
- Reduced dependency versus competition: Restrictions may reduce strategic exposure but also narrow the supplier pool, raise costs, or concentrate demand among a few approved providers.
- Certification versus broader risk: Technical certification may not resolve questions about ownership, control, or foreign interference.
- EU consistency versus timing uncertainty: A common mechanism could reduce uneven national approaches, but businesses may not know which assets or suppliers are covered until later decisions are made.
Where the proposal stands and what comes next
The Commission proposed Cybersecurity Act 2 on January 20, 2026. The European Parliament’s legislative file records committee work and a rapporteur, and indicates that Parliament and the Council still need to negotiate and agree on the final text. The EESC adopted an opinion on April 29, 2026, and the file records a feedback period ending May 12, 2026. As of August 18, 2026, the measure remains a proposal under consideration, not a completed supplier ban. Follow the Parliament legislative file and the Commission’s January 20 announcement for status updates.
If the regulation is adopted, the practical sequence would still include the relevant risk assessments and implementing acts, supplier and asset determinations, any exemptions or mitigation requirements, and applicable transition periods. The final law may differ from the Commission proposal. Until official designations and measures exist, no supplier should be described as banned under this proposal.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




