The EU’s Vendor Vacuum: Why a Fragmented Security Policy Sets Up a Protectionist Clash

AI-generated image · US National Wire
Brussels is attempting to codify 'high-risk' vendors, but a lack of definitions and uneven member adoption create a regulatory gap that could eventually target all non-EU suppliers.
The European Union is currently operating within a regulatory void regarding vendor risk, a fragmentation that creates significant security vulnerabilities and sets the stage for a messy geopolitical reckoning. As first reported by The Register, the Royal United Services Institute (RUSI) has warned that the EU's current 'hodgepodge' of tech policy leaves member states exposed to risks associated with Chinese vendors, necessitating a complete rethink of procurement frameworks.
***
**Opinion:** *The current EU approach is not merely a failure of coordination; it is a regulatory vacuum. By failing to establish a unified definition of 'high-risk' vendors, Brussels is inviting a future where security is defined by political convenience. Once the EU finally moves to close this gap, the resulting framework will likely lean toward protectionism, potentially placing US suppliers under the same scrutiny as Chinese firms in an effort to secure 'domestic' supply chains.*
***
At the heart of the issue is a lack of cohesion. The Register notes that the EU Toolbox for 5G Security, launched in January 2020 as a voluntary framework to harmonize security standards, has been ignored by the majority of the bloc; only 10 of 27 members have fully implemented it. This voluntary nature has allowed member states to pursue wildly different strategies based on their own economic priorities.
RUSI highlights Germany, Spain, and the UK as prime examples of this divergence. Germany, which maintains a trade relationship with China valued at €251.8 billion ($284.4 billion) annually, has historically prioritized these economic ties. Consequently, Chinese suppliers made up an estimated 59 percent of Germany's 5G RAN in 2024. Spain has similarly favored cost-effective options, with Chinese equipment accounting for an estimated 32 percent of its 5G RAN in 2024, despite a controversy last year involving a Huawei contract for judicial wiretap recording storage. In stark contrast, the UK is moving to entirely remove Chinese technology from its telecoms networks by the end of next year, following strong US demands regarding geopolitical security.
The risks are not merely theoretical. According to RUSI, the Chinese government can compel companies like Huawei to provide data on demand and host Chinese Communist Party (CCP) representatives. Furthermore, a law requiring companies to report vulnerabilities to the Chinese government within 48 hours—while withholding that information from overseas counterparts—effectively turns private security research into a state-controlled intelligence pipeline. RUSI also notes that China has demonstrated the capability to launch cyberattacks against the critical infrastructure of political rivals and has used its market dominance to threaten Germany with "consequences" during the 2019 5G debate.
Brussels is now attempting to move from voluntary guidelines to mandatory restrictions. The European Commission has proposed amendments to the Cyber Security Act (CSA) that would allow the creation of a list of "untrusted vendors." If passed, member states would be required to purge these vendors from 18 critical sectors within 36 months. The European Commission has already indicated that Huawei and ZTE would be candidates for this list.
However, a critical legal gap remains. As The Register reports, there is currently no official definition or legal category for what constitutes a "high-risk vendor." Without this baseline, member states can continue to bypass scrutiny to acquire the technology they desire. Until the EU establishes a rigorous, harmonized risk assessment framework that balances national security with sector-specific flexibility, the bloc remains a patchwork of vulnerabilities.

