RUSI research argues that the EU's fragmented technology procurement policy creates supply-chain exposure to Chinese vendors and recommends consolidation that may also scrutinize US suppliers.
Depending on Chinese technology for European infrastructure poses risks that not every country takes seriously, according to the Royal United Services Institute (RUSI). In a report released today, the UK-based think tank argues that the EU needs to do better in helping member states assess risks and take appropriate action to safeguard the bloc as a whole.
RUSI calls for the EU to develop a new risk assessment framework that applies across all members while strengthening its own powers—without encroaching on each member's right to set its own national security policies. The challenge is delicate: securing the union while maintaining the flexibility for members to pursue domestic policies and lawmakers to account for different risk profiles across sectors. The risks affecting telecoms, for instance, may not apply equally to other industries.
The EU Toolbox for 5G Security framework, launched in January 2020, was supposed to establish harmonized standards to mitigate 5G-related security risks. Yet it remains voluntary: only 10 of 27 member states have fully implemented it. Recognizing this shortfall, the European Commission proposed amendments to the Cyber Security Act (CSA) earlier this year that would allow it to create a list of untrusted vendors that member states must exclude from the networks of 18 critical sectors. Any countries using equipment from designated vendors would be forced to replace it within 36 months. The Commission has already indicated it would propose Huawei and ZTE for such a list, should the amendments pass.
But first, the EU must define what constitutes a "high-risk vendor"—a term that currently lacks an official definition and remains a non-legal category. This ambiguity allows countries to circumvent scrutiny by purchasing technology they prefer, regardless of any designation that might follow.
RUSI's researchers examined Germany, Spain, and the UK to illustrate how differently three countries approach foreign tech vendors such as Huawei and ZTE. Germany's most important trading partner is China—a relationship worth €251.8 billion ($284.4 billion) annually—and historically Berlin has prioritized these economic ties over reducing supply chain risk. Under Chancellor Friedrich Merz, this stance is slowly shifting, though RUSI expects no material change in Germany's 5G RAN composition anytime soon. Chinese suppliers accounted for an estimated 59 percent of the country's 5G RAN in 2024.
Spain's 5G RAN included an estimated 32 percent Chinese equipment in 2024, a share expected to decline. Nonetheless, the debate intensified after Spain awarded Huawei a contract for storing judicial wiretap recordings. Spain's procurement decisions have historically favored the most cost-effective options, and its government does not share the same national security concerns about China as the UK or US. The UK, by contrast, is set to eradicate Chinese technology from its telecoms network by the end of next year, bending to US pressure to exclude Huawei on geopolitical security grounds.
RUSI confirmed that concerns about Chinese IT vendors are "well-founded." The Chinese government can require companies like Huawei to provide data on demand, host Chinese Communist Party (CCP) representatives, and report activities signaling national security threats. A law requires tech companies to report vulnerabilities to the government within 48 hours of discovery and to withhold that disclosure from overseas counterparts except for the product vendor. "This converts China's private sector security research into a state-controlled pipeline that grants intelligence services privileged early access to exploitable vulnerabilities," RUSI stated. China has also demonstrated the willingness and capability to launch cyberattacks against the critical infrastructure of political adversaries.
Beyond technical security, Chinese vendors introduce economic risks. Their products sometimes outperform EU and US equivalents at more attractive prices—a cost advantage that makes it harder for some countries to justify spending extra on non-Chinese equipment. By building global reliance on its products, China creates "unwelcome dependencies" and cements itself as a dominant player in crucial supply chains, RUSI noted. China has shown recent willingness to exercise this influence; it threatened Germany with "consequences" during the 2019 5G debate over bilateral trade.
Yet a blanket ban on high-risk vendors may not solve the underlying problem. Issuing designations does not explicitly address the security vulnerabilities that make products susceptible to attack. Even if China were excluded entirely from EU tech stacks, vendors from "trusted" countries have proven unable to deliver penetration-proof software, leaving room for attacks regardless. Salt Typhoon's high-profile 2024 attack on US telecoms networks illustrates the point.
CSA-style designations could theoretically apply to US companies too. Some European countries view US vendors as similarly risky, though for different reasons. Germany under Merz worries about US-EU relations, while Spain—where US cloud companies dominate—harbors stronger anti-US sentiment than commonly acknowledged, especially regarding surveillance concerns. "One participant even noted that some officials view US legal instruments such as the Patriot Act as creating equivalent sovereignty risks to China's National Intelligence Law, a narrative that is flawed when exploring the legislation, but politically convenient," RUSI stated. Higher prices from some non-Chinese suppliers have further weakened Spain's appetite for removing equipment others deem high-risk.
RUSI concludes that the EU must summon "greater economic courage" and treat tech procurement as a critical infrastructure security priority rather than "a compliance exercise."