European Sovereignty Monitor

Policy and law

Commission proposes Cybersecurity Act revision with 5G high-risk supplier phase-out

The Commission proposed a Cybersecurity Act revision and NIS2 amendment on 20 January 2026, requiring high-risk suppliers to be phased out of 5G networks within three years and raising ENISA's budget by more than 75%.

Verified European Commission press release, 20 January 2026

What it does not test. This does not establish that any member state has excluded a named supplier such as Huawei or ZTE, since the phase-out is a proposal awaiting Parliament and Council agreement.

How this item counts. Towards autonomy: it changes who made the parts. Binding 1 of 3 (announced), scale 3 of 3 (large), Verified counts in full: weight +3 of 36 possible. Proposed EU-wide phase-out of high-risk 5G suppliers in 3 yrs; parts, not yet agreed. European Sovereignty Index

Previously in Policy and law

Verified ANSSI leads G7 call for urgent shift to post-quantum cryptography Reported EU Commission sends AI Act information requests to over 30 companies Reported EU antitrust officials seek information on Oracle's cloud licensing practices

All Policy and law news →