The European Union has unveiled a draft proposal to phase out components and equipment from so-called “high-risk” suppliers in critical infrastructure sectors, a move designed to tighten cybersecurity and reduce dependence on non-EU technology. The proposal, released by the European Commission on Tuesday, is part of a wider revision of the EU’s Cybersecurity Act and marks a significant escalation in Europe’s efforts to secure its digital supply chains amid rising cyber threats and geopolitical tensions.
Although the Commission did not name specific companies or countries in the draft, the move is expected to affect major Chinese firms, including Huawei, which has already expressed strong opposition. Huawei argued that the proposed restrictions would discriminate against non-EU suppliers based on country of origin rather than technical evidence. “A legislative proposal to limit or exclude non-EU suppliers based on country of origin… violates the EU’s basic legal principles of fairness, non-discrimination, and proportionality,” a Huawei spokesperson said, adding that the company would monitor the legislative process closely and reserve the right to protect its interests.
The proposed measures reflect growing European concern over foreign interference, espionage, and the increasing frequency of cyber and ransomware attacks. EU officials have also voiced worries about the bloc’s reliance on non-EU technology suppliers in key sectors. “With the new Cybersecurity Package, we will have the means in place to better protect our critical (information and communications technology) supply chains but also to combat cyber attacks decisively,” EU technology chief Henna Virkkunen said.
The draft identifies 18 critical sectors that would be subject to the new rules, spanning a wide range of infrastructure and industries. These include detection equipment, connected and automated vehicles, electricity supply and storage systems, water supply systems, drones and counter-drone systems, cloud services, medical devices, surveillance equipment, space services and semiconductors. The inclusion of such a broad spectrum of sectors underscores the EU’s intent to build resilience across the digital economy.
Europe has already been tightening scrutiny of Chinese technology in recent years. Germany recently formed an expert commission to reassess its trade policy toward Beijing and has banned Chinese components from future 6G telecom networks. The United States banned approvals of new telecom equipment from Huawei and rival ZTE in 2022 and has encouraged European allies to follow suit.
Under the new proposals, mobile operators would have 36 months from the publication of a high-risk supplier list to phase out key components. The Commission said phase-out periods for fixed networks—including fibre-optic and submarine cables, as well as satellite networks—would be announced later. EU officials emphasized that restrictions on suppliers would only take effect after a formal risk assessment initiated by the Commission or at least three EU member states, and would be based on market and impact analyses.
Despite the EU’s framing of the plan as a step toward technological sovereignty and improved safety, industry groups have raised concerns about the economic burden. Telecom lobby group Connect Europe warned that the new regulations could add billions of euros in compliance costs for operators already dealing with complex supply chain changes.
The updated Cybersecurity Act still faces negotiations with EU governments and the European Parliament before it can become law. The draft proposal signals a significant shift in Europe’s approach to securing critical infrastructure, highlighting the growing intersection of technology policy, national security, and geopolitical rivalry.

