Security News

Think Tank Warns EU's Patchwork Tech Rules Leave Door Open to Risky Vendors

The Register · 2 Oct 2026
Key Takeaway Australian SMBs relying on infrastructure or software from overseas vendors should ask suppliers about their own vendor risk assessments, since inconsistent global standards can mean unclear security assurances further up the supply chain.

The Royal United Services Institute (RUSI) has warned that the European Union's fragmented approach to assessing technology vendor risk is leaving member states exposed, particularly where Chinese suppliers are involved. In a new report, the think tank calls for a unified risk assessment framework that applies across all EU members, while still allowing countries flexibility to set their own national security policies.

Currently, the EU relies on a voluntary 5G Security Toolbox introduced in 2020, but only 10 of 27 member states have fully implemented it. In response, the European Commission has proposed amendments to the Cyber Security Act that would let it designate 'untrusted vendors' to be excluded from networks across 18 critical sectors, with a 36 month removal deadline for any existing equipment. Huawei and ZTE have already been flagged as likely candidates for this list.

However, RUSI points out a key gap: there is still no official, legally binding definition of what makes a vendor 'high-risk.' This ambiguity allows countries to interpret the rules differently, as seen in varying approaches taken by Germany, Spain and the UK toward vendors like Huawei and ZTE. Without clearer standards, the report suggests, the EU risks uneven protection across the bloc even if new vendor restrictions are adopted.

supply chain security vendor risk telecommunications EU policy critical infrastructure
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.