20°C

few clouds

TFL Updates
London Daily News

EU telecoms may get flexible deadline to remove high-risk equipment

EU telecoms may get flexible deadline to remove high-risk equipment

European mobile operators could be given a more flexible route for removing network equipment from suppliers designated high risk under proposed EU cybersecurity rules. A Council draft dated 22 September, reported this week, drops the Commission’s proposed fixed 36-month phase-out for mobile networks and instead sets out factors that should shape the timetable. The change is not law and does not yet alter an operator’s legal obligations.

The shift matters because the earlier proposal put a single transition period at the centre of a wider effort to reduce supply-chain risks in critical communications infrastructure. The reported draft keeps that strategic objective, but moves away from treating every replacement project as if it carried the same technical urgency and could be completed in the same time.

From a uniform deadline to a risk-based timetable

Under the reported approach, the period for removing equipment would take account of the level of risk identified, the lifecycle of both products and infrastructure, normal replacement cycles, interoperability requirements and whether suitable alternatives are available. That is a significant change in emphasis. It would allow the timing of a replacement to reflect the equipment’s role in the network and the practical work needed to substitute it without disrupting service.

A fixed deadline can be straightforward to communicate, but mobile networks are not built from isolated boxes that can always be exchanged one by one. Radio equipment, core-network systems, software, maintenance arrangements and existing supplier interfaces can be closely connected. Operators may need to test replacement equipment alongside their live network, plan outages carefully and make sure a new component works with systems already in place.

That does not mean the reported draft abandons the proposed removal requirement. Rather, it suggests that a component judged to present a more serious risk could need to be addressed sooner, while other equipment might be dealt with through a planned renewal cycle if that still met the final rules. The eventual detail would matter greatly: a flexible timetable is not the same as an automatic extension.

What the proposal does — and does not — decide

The wider Cybersecurity Act revision is intended to create an EU-wide framework for managing ICT supply-chain risks. Its proposed process would allow high-risk suppliers to be identified through a formal regulatory route. The term is therefore a prospective legal category within the framework, not a finding that every product made by a particular company is insecure or that every supplier will be covered.

Neither the original proposal nor the reported Council wording amounts to an immediate, blanket instruction to remove all equipment from a named business. Before any obligation can apply, the legislation itself must be agreed and the relevant implementation steps must follow. The Commission’s original text also distinguishes mobile networks from fixed and satellite infrastructure, underlining why a single practical timetable may be difficult to apply across every type of network.

Why the lifecycle question has become central

Operators have argued that a compulsory accelerated replacement programme could be expensive and could divert engineers and investment from fibre expansion, 5G upgrades and preparation for 6G. In a joint industry intervention this month, senior operators put the possible cost across the sector at up to €40 billion. That is an industry estimate rather than a settled public cost, but it explains why replacement cycles and alternative availability have become prominent in the negotiations.

For governments, the countervailing concern is that delaying action may prolong exposure to a supply-chain risk that the framework is designed to address. The reported wording attempts to balance those considerations. It makes the severity of the identified risk one factor in the timetable, alongside the practical constraints of replacing equipment in critical infrastructure.

What happens next

Member states must still settle their position, and the Council and European Parliament must agree on the final legislation. The Commission’s original proposal remains the starting point, while the reported draft is part of negotiations rather than an agreed EU rule.

For telecoms customers, investors and suppliers, the immediate point is not that a deadline has disappeared. It is that the debate has moved towards how a security-driven phase-out could be sequenced in real networks. The final law will determine whether that flexibility survives, how closely it is tied to assessed risk and how consistently it is applied across the EU.

Pin It on Pinterest