Evolution in EU Regulation: CSA2 and High-Risk Supplier Rules Meet Energy Reform and Industrial Policy

By Mason Hurlocker | 21 September 2026


Summary

  • On 20 January 2026, the European Commission proposed revisions to the Cybersecurity Act (CSA2), providing for the first time a mechanism to designate so-called “high-risk suppliers” and force their removal from ICT supply chains across Network and Information Systems Directive (NIS2) sectors, including energy, alongside parallel reforms to electricity market design, grid infrastructure, industrial policy, and energy security rules.

  • The reforms carry a range of political, operational, security and economic risks, ranging from Chinese retaliation and a contested European Council position, to multi-billion-euro replacement costs for grid operators and utilities.

  • Implementation is likely to be slow and contested given lengthy negotiation timelines, though the European Union (EU)’s direction of travel toward reduced dependence on Chinese ICT suppliers in critical infrastructure is now firmly set.


Context

On 20 January 2026, the European Commission (EC) published draft revisions to its Cybersecurity Act (CSA2). The proposed changes would replace the original 2019 Act’s voluntary certification regime with a mechanism to designate “high-risk suppliers” (HRS). Additionally, they restrict the use of their ICT components across sectors covered by the second Network and Information Systems Directive (NIS2), including energy, transport, and cloud computing. Under the proposal, control by, or ownership from, a designated high-risk country would trigger removal obligations. Mobile networks must phase out HRS components from key 5G assets within 36 months of a designation, while other NIS2 entities like fixed broadband, satellite, and energy operators face similar risk-mitigation duties and fines of up to 7% of annual turnover for non-compliance. EU Commissioner for Technology and Digital Security Henna Virkkunen framed the proposal as essential to protecting critical ICT supply chains. Meanwhile, Chinese suppliers Huawei and ZTE, echoed by China's foreign ministry, called it discriminatory and inconsistent with World Trade Organisation (WTO) rules.


Implications

However, CSA2 is just one part of a broader realignment of EU energy and ICT governance which have taken place since the beginning of 2026. New Electricity Market Design rules reformed grid planning governance ahead of a white paper on market integration. Gas market rules followed soon after, intended to accelerate the integration of energy systems across the EU and formalise rules around sharing of gas power reserves in an emergency, again designed to increase the EU’s “strategic autonomy”. The Council also agreed on a position on the revised trans-European energy infrastructure (TEN-E) regulation and permitting directive —the European grids package— embedding cyber and physical resilience by design.  Separately, in March the Commission released its official proposal for the Industrial Accelerator Act (IAA), intended to reduce the EU’s dependence on external suppliers in the energy and manufacturing sectors by, among other things, introducing “made in EU” requirements for battery energy storage systems, solar photovoltaic technologies, heat pumps, wind technologies, and more. In combination with CSA2, the IAA sets the groundwork for Chinese suppliers to eventually be phased out of all strategically important sectors, assuming that the proposals pass in their current forms. 

Politically, CSA2, the IAA, as well as the broader suite of measures focused on combating strategic dependency risk entrenching EU-China friction: Beijing has urged Brussels to avoid “protectionism”, making Chinese retaliation against EU firms operating in China a potential risk. This may include further export curbs for Chinese components used by EU firms, as well as for rare earth minerals used in cleantech, which Beijing already initiated in late 2025. Member states remain divided on forcing Chinese firms out of critical EU supply chains. Sweden and the Baltic states, along with Germany, have already banned Chinese components from 5G and future 6G networks, while others have moved more slowly, meaning the Council’s eventual position is likely to dilute the Commission’s proposed reforms under CSA2. Specifically, countries including Austria, Bulgaria, Cyprus, and Hungary —which have among the highest levels of dependency on Chinese-manufactured ICT and cleantech— have not set any formal timeline for the removal of such components from their supply chains, and have argued against the HRS designation of Chinese firms.

In the energy sector, these regulatory changes mean that grid operators (TSOs), distribution system operators (DSOs) and advanced metering infrastructure (AMI) vendors now face a compressed compliance timeline. They will need to audit and potentially replace embedded ICT components across the smart grid and metering rollout underpinning the EU’s electrification agenda. GSMA Intelligence has warned that some of these operators may struggle to fund wholesale replacement within the proposed 36-month window, while direct replacement costs are estimated at EUR 30-40b (USD 35-46b). Beyond the direct costs, telecoms lobbying group Connect Europe has also warned that additional compliance costs around CSA2, IAA, and the grid code changes could also run into the billions of euros. Combined with already significant investment needs, including the EUR 100b (USD 116b) Industrial Decarbonisation Bank and AccelerateEU’s crisis measures, this adds to an already heavy capital burden on the ICT and energy sectors.

From a security perspective, CSA2’s HRS mechanism, as well as the proposed requirements in the IAA about EU-sourcing  are a significant development, being the first of their kind in the EU to target “non-technical risks”, including state influence, concealed vulnerabilities and technological lock-in, which existing NIS2 and certification rules do not capture. The broader goal of these overlapping initiatives is to reduce EU electricity grids’ exposure to remote interference, a concern sharpened by the 2025 Iberian blackout and reports of physical and cyber threats to European infrastructure.


Forecast

  • Short-term (Now - 3 months)

    • CSA2 negotiations are unlikely to conclude within the next 3 months The file remains at Council working-party and Parliament committee stage, with political agreement not expected before late 2026 or 2027.

    • Grid and market reforms are likely to keep advancing, with electricity and gas market rules now in force and further Council and Parliament work on grid changes ongoing.

  • Medium-term (3 - 12 months)

    • It is a realistic possibility that the Council narrows the Commission's HRS provisions, given industry cost warnings and resistance from some member states to mandatory rip-and-replace obligations.

    • Unilateral national restrictions on Chinese ICT and cleantech components, following Germany and the Baltics, are highly likely to continue pre-empting EU-wide rules.

  • Long-term (>1 year)

    • Should the CSA2 revision be adopted broadly as proposed, European energy and telecoms operators will likely face multi-billion-euro replacement costs, with full compliance likely extending beyond 2030, given that the 36-month clock only starts at designation.

    • Chinese retaliation against EU commercial interests is also a realistic possibility, should Beijing treat CSA2 and/or IAA as a targeted measure against Huawei and ZTE.

Next
Next

External Support Networks Sustain Sudan’s Multi-Faceted Conflict