EU Proposes Cybersecurity Legislation to Restrict High-Risk Suppliers
Summary
Hide ▲
Show ▼
The European Commission has proposed new cybersecurity legislation to mandate the removal of high-risk suppliers from telecommunications networks and strengthen defenses against state-backed and cybercrime threats. The legislation aims to secure critical infrastructure and ICT supply chains, with a focus on suppliers from countries posing national security risks. The proposal includes the authority to conduct EU-wide risk assessments and impose restrictions or bans on certain equipment. The revised Cybersecurity Act will streamline certification procedures and enhance ENISA's role in threat alerts, incident response, and vetting critical tech suppliers. The legislation will take effect immediately upon approval, with member states having one year to implement national laws.
Timeline
-
20.01.2026 20:54 2 articles · 1d ago
EU Proposes New Cybersecurity Legislation to Restrict High-Risk Suppliers
The European Commission has proposed new cybersecurity legislation to mandate the removal of high-risk suppliers from telecommunications networks and strengthen defenses against state-backed and cybercrime threats. The legislation includes the authority to conduct EU-wide risk assessments and impose restrictions on equipment in critical infrastructure. The revised Cybersecurity Act will streamline certification procedures, enhance ENISA's role in threat alerts, incident response, and vetting critical tech suppliers. The legislation will take effect immediately upon approval, with member states having one year to implement national laws.
Show sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
Information Snippets
-
The EU's voluntary 5G Security Toolbox, introduced in January 2020, has been unevenly applied.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The new legislation targets high-risk suppliers, particularly Chinese tech companies like Huawei and ZTE.
First reported: 20.01.2026 20:541 source, 1 articleShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
-
The EU Commission will have authority to conduct EU-wide risk assessments and impose restrictions on equipment in sensitive infrastructure.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The revised Cybersecurity Act mandates the removal of high-risk foreign suppliers from European mobile telecommunications networks.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
ENISA will issue early threat alerts, operate a single entry point for incident reporting, and help companies respond to ransomware attacks.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
ENISA will establish EU-wide cybersecurity skills attestation schemes and pilot a Cybersecurity Skills Academy.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The legislation will take effect immediately upon approval by the European Parliament and the Council of the EU.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
Member states will have one year to implement cybersecurity amendments into national law.
First reported: 20.01.2026 20:542 sources, 2 articlesShow sources
- EU plans cybersecurity overhaul to block foreign high-risk suppliers — www.bleepingcomputer.com — 20.01.2026 20:54
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The EU Commission has launched a new cybersecurity package that includes its formal proposal for an amendment of the current Cybersecurity Act (CSA).
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The CSA was adopted in March 2019 to strengthen cybersecurity across the EU, establishing a permanent EU-wide cybersecurity certification framework and strengthening ENISA's mandate.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The CSA received criticisms for its voluntary nature and slow rollout of certification schemes, especially among SMBs.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The Act was designed before the democratization of AI threats and heightened geopolitical tensions.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The Commission identified four main problems to tackle: misalignment with stakeholders' needs, stalled implementation of the ECCF, complexity of cybersecurity policies, and increasing ICT supply chain risks.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The proposed Cybersecurity Act 2.0 includes introducing a new trusted ICT supply chain security framework, mandatory derisking of European mobile telecommunications networks from high-risk third-country suppliers, and streamlining certification schemes.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
ENISA will have an expanded role, including leading during major cyber incidents, maintaining a repository of cybersecurity exercises, sharing non-sensitive cyber threat intelligence, vetting critical tech suppliers, and piloting a European attestation scheme for cybersecurity skills.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
-
The Cybersecurity Act 2.0 will be applicable immediately after approval by the European Parliament and the Council of the EU, with member states having one year to implement the directive into national law.
First reported: 21.01.2026 14:151 source, 1 articleShow sources
- EU Unveils Cybersecurity Overhaul with Proposed Update to Cybersecurity Act — www.infosecurity-magazine.com — 21.01.2026 14:15
Similar Happenings
Global Agencies Release OT Network Security Guidance
The US Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), the Federal Bureau of Investigation (FBI), and international partners have released a new set of security principles aimed at securing operational technology (OT) environments. The guidance addresses the growing risks associated with insecure connectivity in systems that support essential services, providing a framework to help organizations design and manage secure connectivity in OT networks. The document emphasizes the importance of embedding security into network design from the outset to reduce exposure to both highly capable and opportunistic adversaries, including nation-state actors. It highlights the increased interconnection between industrial systems and enterprise networks, which has improved efficiency but expanded the attack surface for cyber threat actors.
CISA outlines strategic vision for the CVE Program's Quality Era
The Cybersecurity and Infrastructure Security Agency (CISA) has released a strategic roadmap for the Common Vulnerabilities and Exposures (CVE) Program, marking the transition from its Growth Era to the Quality Era. The new focus aims to enhance trust, responsiveness, and the quality of vulnerability data. The CVE Program, a global standard for vulnerability identification, will prioritize conflict-free and vendor-neutral stewardship, broad multi-sector engagement, transparent processes, and accountable leadership. CISA will continue to maintain CVE data as a free and openly accessible public good. The strategic vision includes expanding community partnerships, evaluating diversified funding mechanisms, accelerating technological improvements, enhancing transparency and communications, and improving data quality through collaboration with industry and international governments.
CISA and Partners Release OT Asset Inventory Guidance
The Cybersecurity and Infrastructure Security Agency (CISA) and several international partners released new guidance to assist operational technology (OT) owners and operators in creating and maintaining comprehensive OT asset inventories and taxonomies. This guidance aims to enhance the security of critical infrastructure sectors by providing deeper visibility into OT assets, reducing risk, and ensuring operational resilience. The guidance was developed in collaboration with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA), and cybersecurity agencies from Australia, Canada, Germany, the Netherlands, and New Zealand. OT systems are crucial for the safe and reliable operation of critical infrastructure, including water systems, energy grids, manufacturing, and transportation networks.
DHS and Private Sector Establish ICT Supply Chain Risk Management Task Force
The U.S. Department of Homeland Security (DHS) has formed the ICT Supply Chain Risk Management Task Force, a public-private partnership to identify and manage risks to the global ICT supply chain. The task force aims to develop consensus recommendations to address threats from foreign adversaries, hackers, and criminals targeting the ICT supply chain. The initiative is part of DHS's collective defense approach to cybersecurity risk management, involving industry and government stakeholders. The inaugural meeting of the Task Force was held on November 15, 2018, with members from leading telecom companies and government agencies. The Task Force has launched work streams to develop a common framework for bi-directional sharing of supply chain risk information, identify processes for threat-based evaluation of ICT supplies, and produce policy recommendations to incentivize the purchase of ICT from original manufacturers or authorized resellers. The Task Force recently approved a recommendation for a proposed federal acquisition rule to prevent counterfeit ICT procurement and discussed mechanisms for providing input into the Federal Acquisition Security Council. The Task Force is also expanding its scope to involve supply chain experts from outside the IT and Communications industry and aims to release a public summary of its recommendations by the end of summer.