Updated augustus 9, 2026
Summary: The Digital Networks Act (COM(2026) 16) and the EU 5G Cybersecurity Toolbox together impose structured high-risk vendor assessment obligations on regulated organisations, directly affecting procurement timelines, existing contracts and the sovereign connectivity posture required under NIS-2 Article 21 and DORA.

Sovereign connectivity means that the physical and logical infrastructure carrying an organisation’s communications remains free from compelled access by foreign states, either through compromised hardware, vendor backdoors or the legal reach of foreign intelligence laws. For regulated organisations in the EU public sector, finance and healthcare, this definition has moved from theoretical concern to active compliance obligation, driven by the EU 5G Cybersecurity Toolbox, the proposed Digital Networks Act (DNA, COM(2026) 16) and NIS-2 Article 21.

The High-Risk Vendor Problem: Why Connectivity Is a Jurisdiction Risk

Network equipment from vendors subject to authoritarian-state intelligence laws introduces a structural foreign-jurisdiction risk that no contractual clause can fully neutralise.

China’s Cybersecurity Law (2017) and the National Intelligence Law (2017) together require Chinese companies and individuals to “support, assist and cooperate” with national intelligence work. This is not a theoretical possibility: it is a statutory obligation that travels with every base station, router and network management platform a vendor ships. A regulated organisation whose mobile operator relies on Huawei or ZTE radio access network (RAN) equipment is therefore connected, through the supply chain, to a legal regime that can compel the equipment manufacturer to act against the interests of the organisation’s data subjects and regulators.

The US side of this problem is different in structure but similarly real. CLOUD Act warrants and FISA 702 collection orders can compel US-headquartered network vendors and managed service providers to disclose traffic metadata and, in some circumstances, content, without notifying the affected EU party. Organisations that have addressed cloud sovereignty by migrating to EU-hosted infrastructure may still carry residual exposure if their connectivity layer runs on US-controlled network management platforms.

Key risk: Sovereignty decisions made at the cloud layer do not automatically propagate to the connectivity layer. A fully EU-hosted workload that transits a network with HRV components or US-controlled management plane retains a foreign-jurisdiction vulnerability.

The EU 5G Cybersecurity Toolbox and Its Assessment Methodology

The EU 5G Cybersecurity Toolbox, coordinated through the NIS Cooperation Group and updated with progress reporting in 2023, provides the foundational methodology for classifying high-risk vendors (HRVs) and mandating Member State action.

The Toolbox asks national authorities to assess vendors against a structured set of risk factors: the legal and regulatory environment of the vendor’s country of origin, the degree of state ownership or influence, the vendor’s track record on vulnerability disclosure, and the vendor’s level of access to sensitive network functions. Critically, the Toolbox distinguishes between core network functions, where HRV restrictions are considered mandatory, and the RAN, where restrictions are strongly recommended. This distinction matters for regulated organisations because a mobile operator may have already cleaned its core while retaining HRV equipment in the RAN, which still processes signalling data that can expose communication patterns.

According to the European Commission and NIS Cooperation Group’s 2023 progress report, approximately 40% of EU Member States reported significant HRV presence in their 5G core or RAN, indicating that remediation is still in progress across the bloc.

The NIS Cooperation Group has been explicit in its position: “The presence of high-risk vendors in 5G networks poses significant risks to the security and resilience of the EU’s digital infrastructure, and Member States must take coordinated action to mitigate or, where necessary, exclude such vendors.”

See how Qsentinel solves this in practice.Start a 10-user pilot →

The Digital Networks Act: From Toolbox to Binding Framework

The proposed Digital Networks Act (COM(2026) 16) translates the Toolbox’s recommendations into a harmonised legislative framework, closing the inconsistency that currently allows HRV presence to persist in Member States with weaker national transposition.

The DNA’s most significant contribution for regulated organisations is its explicit extension of HRV assessment obligations to future 6G deployments. Where the Toolbox was designed around the 5G architecture of the late 2010s, the DNA builds in a forward-looking assessment cycle that requires Member States and, through their regulatory frameworks, essential entities to evaluate supply-chain risk at each major network generation transition. BEREC, the Body of European Regulators for Electronic Communications, is assigned a coordination role in this framework, providing technical input that national regulators then apply to operator licensing and market access conditions.

The DNA also introduces an EU-level Preparedness Plan for Digital Infrastructures. This is directly useful for compliance officers and audit teams: it establishes a common European standard for resilience assessment that organisations can reference in their NIS-2 and DORA documentation. Rather than defending a bespoke internal resilience methodology to a national supervisor, an organisation can demonstrate alignment with a recognised EU-level framework, which provides both substance and defensibility.

NIS-2 Article 21(2)(d): Supply-Chain Security as a Legal Obligation

NIS-2 Article 21(2)(d) requires essential and important entities to implement measures addressing supply-chain security, including the security posture of direct suppliers and service providers. For regulated organisations in finance, healthcare, public administration and digital infrastructure, this creates a direct line of legal obligation from the Toolbox’s HRV classification to internal procurement and vendor management processes.

The practical implication is that a hospital, bank or government ministry that consumes connectivity services from a mobile operator cannot treat the operator’s equipment supply chain as out of scope. Under Article 21(2)(d), the organisation must assess and document the risk associated with that supply chain, including whether the operator has implemented applicable HRV restrictions. ENISA’s NIS Investments Report 2023 found that fewer than 40% of operators had a fully documented supplier risk assessment process in place, which means many in-scope entities are already operating with a compliance gap.

Framework Scope HRV obligation Applies to regulated consumers?
EU 5G Cybersecurity Toolbox 5G networks, Member States and operators Risk assessment and restriction measures recommended Indirectly, through operator obligations
Digital Networks Act (COM(2026) 16) 5G and 6G, harmonised across EU Binding harmonised measures, extended to 6G Yes, through essential entity classification and procurement rules
NIS-2 Article 21(2)(d) Essential and important entities in all sectors Supply-chain security risk management required Yes, directly
DORA ICT third-party risk Financial entities ICT supplier concentration and dependency risk Yes, directly for finance sector

Network Slicing and the Limits of Logical Isolation

The DNA’s Open Internet framework accommodates network slicing and specialised services, which is commercially necessary for 5G deployments but introduces a specific sovereignty complication for sensitive workloads.

Network slicing allows an operator to carve logically separate virtual networks from a shared physical infrastructure. A government agency might receive a dedicated slice with quality-of-service guarantees and apparent separation from consumer traffic. However, if the physical layer beneath that slice includes HRV base stations or management platforms, the logical boundary provides no protection against firmware-level access or covert channel exploitation. The Chinese Cybersecurity Law obligation runs to the hardware manufacturer, not to the slice tenant.

Sovereign infrastructure operators should therefore require connectivity providers to attest, in contractual and technical terms, whether slices designated for sensitive workloads physically traverse any HRV equipment. Where physical isolation cannot be demonstrated, quantum-safe encryption at the application or transport layer becomes a compensating control, though not a full substitute for clean physical infrastructure.

Parliamentary Pressure and Procurement Consequences

European Parliament Resolution 2025/2007(INI) on technological sovereignty calls for stricter measures to de-risk HRVs in 5G and future 6G networks, and explicitly links this to the broader goal of European digital independence. The Parliament’s position states: “Technological sovereignty requires that Europe not only sets the rules but also controls the critical infrastructure through which those rules are enforced, including the networks that carry government and financial communications.”

For procurement teams, the resolution signals that the political trajectory is toward stricter enforcement, not accommodation of existing HRV relationships. Organisations that are currently mid-contract with equipment vendors that would be classified as HRVs under Toolbox criteria should not assume those contracts will run to their natural term without regulatory intervention. Several Member States, including Sweden and Romania, have already enacted national HRV exclusion orders that required operators to remove Huawei and ZTE equipment on defined timelines, with associated costs that fell primarily on the operators but created service disruption risks for enterprise customers.

The IBM Cost of a Data Breach Report 2024 recorded an average breach cost of USD 4.88 million, the highest in the report’s history. This figure provides a financial anchor for the business case behind proactive HRV remediation: the cost of replacing connectivity infrastructure with sovereign alternatives is typically far below the liability exposure of a breach attributable to a supply-chain compromise that regulators can demonstrate should have been addressed.

Procurement action point: Regulated organisations renewing or extending connectivity contracts should require operators to provide written documentation of HRV status in the equipment supply chain and map this against national transposition measures under the DNA. This documentation serves both due diligence and NIS-2 audit purposes.

Building an Audit-Ready Sovereign Connectivity Framework

A consolidated sovereign connectivity risk framework that satisfies the Toolbox, the DNA, NIS-2 Article 21(2)(d) and DORA should be built around four documented components: a vendor risk register that maps each connectivity provider’s equipment supply chain against Toolbox HRV criteria; a contractual clause requiring operators to notify the organisation of any change in HRV status or national regulatory restriction; a resilience assessment aligned with the DNA’s EU-level Preparedness Plan, covering both the connectivity layer and its integration with the organisation’s broader ICT resilience; and a remediation roadmap with defined milestones for eliminating residual HRV exposure.

This framework converts a disparate set of regulatory obligations into a single governance artefact that compliance officers can present to supervisors under NIS-2’s reporting requirements and DORA’s ICT resilience testing obligations. The DNA’s Preparedness Plan provides the external benchmark that makes such a framework defensible rather than self-referential.

FAQ

What makes a vendor a high-risk vendor under the EU 5G Cybersecurity Toolbox?

The Toolbox directs Member States to assess vendors against criteria including the legal and regulatory environment of the vendor’s home country, ownership structure, state influence, track record on security disclosures, and the degree of access the vendor has to the network. Vendors subject to laws such as China’s Cybersecurity Law or National Intelligence Law, which compel cooperation with state intelligence services, score adversely on these criteria and are typically classified as high-risk.

Does the Digital Networks Act legally require regulated organisations to remove high-risk vendor equipment?

The DNA (COM(2026) 16) harmonises the obligation on Member States to put restriction or exclusion measures in place and extends coordination to future 6G deployments. For regulated organisations, the practical effect comes through national transposition measures and through NIS-2 Article 21(2)(d), which requires essential and important entities to include supply-chain security in their risk management. Organisations that consume connectivity services must verify that their providers comply with applicable HRV restrictions.

Can a regulated organisation in finance or healthcare continue using a mobile operator that relies on Huawei RAN equipment?

Not without risk. Under NIS-2 Article 21(2)(d) and DORA’s ICT third-party risk requirements, the organisation must assess and document the risk profile of its connectivity providers, including their equipment supply chains. If the national competent authority has imposed restrictions on that vendor, the operator is expected to have a remediation plan. Continuing without such a plan creates demonstrable compliance gaps that supervisors can act on.

How does network slicing under 5G create new sovereignty risks for sensitive workloads?

Network slicing allows a physical 5G network to present logically separate virtual networks to different customers. If the underlying physical infrastructure uses HRV components, isolation at the slice level does not eliminate the risk of covert access at the hardware or firmware layer. Sovereign operators should require their connectivity providers to demonstrate that slices carrying sensitive government or financial traffic are physically or cryptographically isolated from segments where HRV equipment operates.

How does the DNA’s EU-level Preparedness Plan support NIS-2 and DORA audit documentation?

The Preparedness Plan establishes a common EU framework for assessing and stress-testing digital infrastructure resilience, including connectivity. Organisations can reference their alignment with the Plan’s assessment criteria in audit documentation to demonstrate that their resilience posture meets a recognised EU standard, directly relevant to NIS-2’s requirement for documented and tested business continuity measures and to DORA’s ICT resilience testing obligations.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

What makes a vendor a 'high-risk vendor' under the EU 5G Cybersecurity Toolbox?
The Toolbox directs Member States to assess vendors against criteria including the legal and regulatory environment of the vendor's home country, ownership structure, state influence, track record on security disclosures, and the degree of access the vendor has to the network. Vendors subject to laws such as China's Cybersecurity Law or National Intelligence Law that compel cooperation with state intelligence services score adversely on these criteria and are typically classified as high-risk.
Does the Digital Networks Act legally require regulated organisations to remove high-risk vendor equipment?
The DNA (COM(2026) 16) harmonises the obligation on Member States to put restriction or exclusion measures in place, and it extends coordination to future 6G deployments. For regulated organisations, the practical effect comes through national transposition measures and through NIS-2 Article 21(2)(d), which requires essential and important entities to include supply-chain security in their risk management measures. Organisations that consume connectivity services must verify that their providers comply with applicable HRV restrictions.
Can a regulated organisation in finance or healthcare continue using a mobile operator that relies on Huawei RAN equipment?
Not without risk. Under NIS-2 Article 21(2)(d) and DORA's ICT third-party risk requirements, the organisation must assess and document the risk profile of its connectivity providers, including their equipment supply chains. If the national competent authority has imposed restrictions on that vendor, the operator is expected to have a remediation plan. Continuing without such a plan creates demonstrable compliance gaps that supervisors can act on.
How does network slicing under 5G create new sovereignty risks for sensitive workloads?
Network slicing allows a physical 5G network to present logically separate virtual networks to different customers. If the underlying physical infrastructure uses HRV components, isolation at the slice level does not eliminate the risk of covert access at the hardware or firmware layer. Sovereign operators should require their connectivity providers to demonstrate that slices carrying sensitive government or financial traffic are physically or cryptographically isolated from segments where HRV equipment operates.
How does the DNA's EU-level Preparedness Plan support NIS-2 and DORA audit documentation?
The Preparedness Plan establishes a common EU framework for assessing and stress-testing digital infrastructure resilience, including connectivity. Organisations can reference their alignment with the Plan's assessment criteria in audit documentation to demonstrate that their resilience posture meets a recognised EU standard, which is directly relevant to the NIS-2 requirement to have documented and tested business continuity and incident response measures, and to DORA's ICT resilience testing obligations.