The Cost of Cheap: Why Europe's Fragmented Tech Procurement is a Security Liability
A new report from the Royal United Services Institute warns that the EU's inconsistent approach to high-risk vendors creates dangerous vulnerabilities across the bloc.
Q: What is the primary concern regarding Europe's current technology procurement strategy?
A: As first reported by The Register, the Royal United Services Institute (RUSI) warns that relying on Chinese technology for European infrastructure poses risks that are not being taken seriously by all member states. The think tank argues that the EU's current "hodgepodge" tech policy leaves the bloc vulnerable, suggesting that a unified risk assessment framework is necessary to safeguard critical infrastructure.
Q: How has the EU attempted to address these security risks so far?
A: The EU launched the voluntary EU Toolbox for 5G Security in January 2020 to create harmonized standards for mitigating 5G risks. However, The Register reports that only 10 of the 27 member states have fully implemented it. To address this lack of adoption, the European Commission proposed amendments to the Cyber Security Act (CSA) that would allow for a list of "untrusted vendors." If passed, members would be required to remove equipment from these vendors within 36 months across 18 critical sectors. The European Commission has already indicated it would suggest including Huawei and ZTE on this list.
Q: Why is the "untrusted vendor" designation currently ineffective?
A: As reported by The Register, there is currently no official or legal definition of what constitutes a "high-risk vendor." This lack of clarity allows member states to bypass scrutiny and continue purchasing the technology they prefer, even if CSA amendments are enacted.
Q: Can you provide examples of how different European nations are handling Chinese vendors?
A: The Register highlights three distinct approaches based on RUSI research:
* **Germany:** Chinese suppliers made up an estimated 59 percent of Germany's 5G RAN in 2024. While Chancellor Friedrich Merz is slowly shifting policy, Germany has historically prioritized its economic relationship with China—worth €251.8 billion ($284.4 billion) annually—over reducing supply chain risk. * **Spain:** In 2024, Chinese equipment was estimated to comprise 32 percent of Spain's 5G RAN. Spain has frequently prioritized the most cost-effective options, exemplified by a contract awarded to Huawei for storing judicial wiretap recordings. * **The UK:** In contrast, the UK is moving to completely remove Chinese technology from its telecoms network by the end of next year, aligning with US security concerns.
Q: What specific security and economic threats does RUSI identify?
A: RUSI states that concerns are "well-founded" because the Chinese government can compel companies like Huawei to provide data on demand and host Chinese Communist Party (CCP) representatives. Furthermore, a law requires companies to report vulnerabilities to the Chinese government within 48 hours while withholding that information from overseas counterparts. RUSI notes this creates a state-controlled pipeline giving intelligence services early access to vulnerabilities.
Economically, RUSI warns that China's ability to offer more capable products at lower prices creates "unwelcome dependencies." This allows China to dominate crucial supply chains and exercise political influence, as seen in 2019 when China threatened Germany with "consequences" during 5G debates.

