Securing Europe’s Telecom Supply Chain

Securing Europe’s Telecom Supply Chain
U.S. Department of Defense photo / Wikimedia Commons (Public Domain)

Europe's telecom operators still rely on network equipment from suppliers that European regulators consider high-risk from a national security perspective, and replacing it is not free. Removing that equipment from European fixed, mobile, and transport networks could cost approximately €35 billion, according to analysis from GSMA Intelligence, the research arm of GSMA (or GSM Association with GSM standing for Global System for Mobile communications), the global trade association representing more than 750 mobile network operators worldwide and the organizer of Mobile World Congress, highlighted by Light Reading. The estimate is based on information provided by European telecommunications operator groups, and the report argues that mandatory replacement could materially disrupt operators and consumers.

From the European Union’s perspective, the vulnerability is not limited to the possibility of a specific backdoor or isolated cyber incident.  It arises from strategic dependence on suppliers that may be subject to influence through third-country laws and governance structures, which is why the European Commission considers Huawei and ZTE (the two Chinese telecommunications equipment manufacturers that supply much of Europe's radio and core network hardware) to present materially higher risks than other 5G suppliers. That assessment rests on more than generalized third-country risk: China's 2017 National Intelligence Law compels Chinese organizations and citizens to support, assist, and cooperate with state intelligence work when directed to do so, giving Beijing a channel into foreign telecommunications infrastructure where Chinese vendor equipment is present. U.S. authorities have reached the same conclusion independently. The Federal Communications Commission has placed both companies on its Covered List of communications equipment posing an unacceptable national security risk, and federal agencies and contractors have been barred from procuring or using their equipment since the 2019 National Defense Authorization Act (Section 889) and the Secure and Trusted Communications Networks Act. In the broader context of irregular and hybrid warfare, telecommunications infrastructure is strategic pre-positioning terrain: dependency can create opportunities for disruption, unauthorized access, coercive leverage, or degradation of the communications governments, militaries, and societies require during a crisis, making resilient civil communications an element of deterrence and national resilience.

That cost deserves serious consideration, but it does not support indefinite dependence on suppliers that the European Commission has identified as presenting materially higher risks. Nor does it establish that operators must immediately finance a network-wide replacement entirely from their own cash flow.

The European Commission’s proposed Cybersecurity Act 2 would require high-risk supplier components to be phased out of designated key information and communications technology (ICT) assets. The appropriate response is to convert high-risk supplier transition into a phased, financeable infrastructure modernization program.

Financing Institutions and Instruments Already Exist

Huawei Technologies is a Chinese multinational founded in 1987 by Ren Zhengfei, a former engineer in the People's Liberation Army, and has grown into one of the world's largest suppliers of telecommunications network equipment — radio access, core, and transport infrastructure — alongside Nokia and Ericsson. Aggressive pricing and vendor financing helped it win a substantial share of European operators' business as they built out 3G, 4G, and early 5G networks over the past two decades, which is why replacing it now is a large infrastructure undertaking rather than a routine vendor swap. There is no single European “Huawei replacement fund,” but the institutions, instruments, and precedent transactions needed to finance a transition already exist.

Within the EU, the European Investment Bank (EIB) and InvestEU already finance 5G (the fifth-generation mobile network standard that began rolling out across Europe in 2019 and remains a multi-year buildout) deployment, standalone core modernization, cybersecurity improvements, and strategic telecommunications infrastructure. For example, the EIB’s financing of Latvia’s LMT included 5G radio deployment, a new standalone core, operations support systems (OSS) and business support systems (BSS), access-network expansion, and cybersecurity investments.

For EU enlargement countries, Eastern Neighborhood nations, and other partner markets, Global Gateway, the European Fund for Sustainable Development Plus (EFSD+), EIB Global, and the European Bank for Reconstruction and Development (EBRD) provide loans, guarantees, grants, and technical assistance for digital infrastructure. The EFSD+ Digital Transformation Platform specifically provides financing and technical assistance for private telecommunications operators and other digital-sector companies in eligible partner markets.

These are demonstrated mechanisms, not theoretical policy concepts.

The EBRD structured up to €190 million for Tunisie Telecom to modernize its mobile access, backbone, core, and fiber networks. The development-linked loan is supported by an EFSD+ first-loss guarantee, with its interest rate tied to the achievement of defined transformation milestones.

The U.S. International Development Finance Corporation (DFC) has also signed a letter of interest and financing proposal to support Tele2 Kazakhstan’s transition to trusted telecommunications equipment. This is proposed financing rather than a completed transaction, but it demonstrates that trusted-supplier transition is becoming an explicit development-finance objective.

U.S. Trade and Development Agency (USTDA)-funded technical assistance in Palau has advanced from technical analysis and procurement planning to the selection of trusted suppliers for implementation of a secure nationwide 4G and 5G network. USTDA financed the project-development work rather than the capital deployment, illustrating the role that grants can play in converting a broad modernization objective into defined requirements, implementation plans, and procurement decisions to facilitate implementation financing.

High-risk supplier replacement presents a different financing challenge than ordinary network expansion. Replacing functioning equipment may generate little or no new revenue, accelerate capital expenditures planned for later years, strand assets that have not been fully depreciated, and create additional integration, testing, and parallel-operation costs. Operators may therefore be asked to assume new debt without a corresponding increase in customers or revenue.

Conventional lending alone may not resolve that problem. Public and private financing should therefore be combined with mechanisms that address the extraordinary costs of an accelerated security transition. These could include first-loss guarantees, interest-rate support, grants or tax incentives for verified stranded assets, and extended implementation periods tied to enforceable milestones. Governments and regulators could also provide spectrum-fee relief, other regulatory offsets, and treatment allowing operators to recover documented transition costs. Operator financing, export-credit support, public funding for technical assessments and procurement, and aggregated purchasing arrangements could further reduce financing costs and improve equipment pricing. Export credit agencies, commercial lenders, equipment providers, and national development banks can supplement these mechanisms through buyer credits, guarantees, deferred-payment structures, and equipment financing.

The financing toolkit exists, but it must be organized around a credible, technical transition plan with proper incentives attached. Each program will require a defined replacement scope, validated cost baseline, procurement strategy, implementation schedule, and repayment structure.

Replacement Should Be Targeted and Sequenced, Not Indiscriminate

Security risk is not distributed equally across every network asset. A credible transition plan should distinguish between active systems that must be replaced, passive infrastructure that may be retained, and administrative or security functions that must be transferred to trusted control. This approach is consistent with the EU’s risk-based 5G cybersecurity framework.

The first phase should address active systems that provide privileged access, process sensitive information, control network functions, or could materially affect network availability. Priority areas may include mobile core systems, subscriber databases, authentication functions, and policy-control platforms, as well as network-management, orchestration, and operations and maintenance systems. Operators should also assess security gateways, supplier remote-access tools, software-update mechanisms, and supplier-controlled interfaces between network infrastructure and operations support systems and business support systems (OSS/BSS) platforms. High-risk baseband and radio equipment serving government, defense, energy, transportation, financial, and other critical infrastructure users should receive particular attention, along with edge-computing environments that process sensitive, regulated, or mission-critical data. Administrative transition actions should occur in parallel. These may include revoking and rotating supplier credentials, transferring network-management authority, disabling unmonitored remote access, migrating software-signing and update controls, and placing all necessary external support connections behind monitored privileged-access systems.

Civil works and genuinely passive assets, including towers, shelters, ducts, and usable fiber plant, may often be retained. Retention should be subject to technical compatibility, security review, structural and power requirements, and the design of the replacement architecture. Active optical equipment, integrated antenna electronics, transport nodes, and network-management systems should not be treated as passive merely because they are associated with fiber or tower infrastructure.

This is not an argument for partial compliance. Covered high-risk components should be removed within applicable legal timelines. It is an argument for replacing the systems that create security exposure without unnecessarily discarding compatible infrastructure that does not provide logical access to the network.

Interim Controls Can Reduce Risk, but They Do Not Replace Compliance

A phased transition does not mean accepting unmanaged risk. While equipment replacement, integration, and procurement proceed, operators can reduce exposure through network segmentation, separation of data, control, and operations traffic, strong encryption, local data breakout, privileged-access management, continuous monitoring, software assurance, and strict limitations on supplier remote access.

These measures are consistent with the National Institute of Stands and Technology’s (NIST’s) 5G network security design principles, which recommends isolating data-plane, control-plane, and operations and maintenance traffic to improve network cybersecurity and privacy.

Additional measures may include moving network-management functions into trusted environments, replacing supplier-controlled authentication and administrative systems, and restricting external maintenance connections through monitored access controls. Operators can also strengthen resilience by establishing sovereign or regionally controlled security operations capabilities, separating government and critical-infrastructure traffic from general commercial traffic, and requiring supplier diversity and interoperability in future deployments. High-risk suppliers should also be excluded from new core, edge, cloud, orchestration, and network-management investments.

These controls can reduce immediate exposure and protect continuity of service while replacement proceeds. They should be treated as transitional safeguards, not as permanent substitutes for removing covered high-risk components.

Sensitive Users Can Be Moved to More Trusted Environments

Government agencies, defense organizations, utilities, transportation operators, financial institutions, and other sensitive users do not necessarily need to remain fully exposed to the existing public network architecture while national modernization proceeds. However, the available alternatives provide different degrees of technical independence and should not be treated as equivalent.

The strongest separation can be achieved through standalone non-public or private 5G networks built with trusted radio, core, authentication, management, and security systems. These environments can provide dedicated infrastructure and greater control over where data is processed and who administers the network.

Other models can provide partial separation while continuing to use portions of the public operator’s infrastructure. These may include public-network-integrated non-public networks, dedicated enterprise cores, and managed enterprise or government mobile virtual network operator (MVNO) arrangements. Their security value depends on which functions are placed under trusted control, and which remain dependent on the host operator.

Secured network slices, private access point name environments, local data breakout, and end-to-end encryption can provide additional logical isolation. They can protect data confidentiality, restrict user access, and control where traffic is processed. They do not, by themselves, remove risks associated with shared radio equipment, signaling systems, transport infrastructure, network management, availability, or supplier administrative access.

A conventional MVNO subscription is therefore not a high-risk supplier replacement strategy. It generally continues reliance on the host operator’s radio and core infrastructure. Rebranding or reselling connectivity does not alter the underlying supply-chain risk.

An enterprise or government-focused MVNO may nevertheless serve as a transitional risk-reduction measure when paired with a trusted dedicated core, enterprise-controlled identity and authentication, private access points, local user-plane processing, encrypted transport, monitored administration, and clear restrictions on where sensitive data is processed.

These architectures can protect priority users during a broader transition, but they should not be presented as substitutes for replacing high-risk components where removal is legally or operationally required.

Operators are correct that accelerated replacement can strand assets, constrain investment capacity, increase integration risk, and reduce near-term supplier competition. Those effects support structured public-private financing and realistic implementation sequencing. They do not support indefinite reliance on suppliers that have been designated as high risk.

High-risk supplier dependence is not an unsolvable cost problem. It is an infrastructure financing, program design, and execution challenge. The practical choice is not between an immediate, indiscriminate nationwide replacement and doing nothing. The viable path is a risk-prioritized and financeable transition that replaces covered active systems within applicable legal timelines, addresses the most sensitive network functions first, protects critical users during implementation, and retains compatible passive infrastructure where technically and legally appropriate.

Europe does not lack financing institutions. It lacks a coordinated financing mandate to support the transition away from Huawei to trusted suppliers.


Sheena Hutchison works at the intersection of information and communications technology, digital modernization, and national security. At Widelity, she builds public- and private-sector partnerships, advances trusted-network and resilient communications initiatives from early-stage concepts to financeable, executable programs, and leads data architecture research and development to modernize analyst workflows and operations. She is an alumna of Johns Hopkins University, where she earned an M.S. in Data Analytics and Policy and an M.A. in Global Security Studies, and of the George Washington University, where she earned a B.A. in International Affairs.