The EU introduces new cybersecurity rules restricting Chinese telecom firms
The European Commission has unveiled a new cybersecurity regulation that bans Chinese companies from operating telecom networks within the EU. Henna Virkkunen, European Vice President for Technological Sovereignty, announced the measure after voluntary recommendations to limit ‘high-risk’ providers failed to yield consistent results across member states. The rule will legally oblige EU countries to exclude these companies—particularly Chinese firms involved in 5G networks—within three years, at an estimated cost between 3 and 4 billion euros. The regulation forms part of a broader initiative aimed at securing the information and communication technology supply chain across 18 critical sectors, including energy, transport, healthcare, cloud services, and semiconductors.
The law also enhances the mandate of the EU Agency for Cybersecurity (ENISA), doubling its staff and budget while expanding its powers to issue alerts, manage cybersecurity incidents across Europe, and collaborate with Europol. ENISA will also launch a European-wide certification program in cybersecurity competencies to fill approximately 300,000 job vacancies in the sector.
Critics argue that the regulation undermines EU principles of free competition and non-discrimination by targeting firms based on their country of origin. Some have pointed out that, while Chinese companies face restrictions, major American cloud providers such as Amazon, Microsoft, and Google remain unaffected. The article presents this as evidence of political bias and questions the EU’s approach to technological sovereignty, warning that China might retaliate economically or diplomatically.
