Technology · Digital regulation
EU cybersecurity law targeting Chinese tech delayed as capitals resist Brussels control
The European Commission's plan to ban untrusted vendors from critical supply chains faces pushback from member states unwilling to cede national security powers, delaying publication by a week.
The European Commission has pushed back the publication of its revised Cybersecurity Act by six days, a small delay that reveals a larger fracture. Henna Virkkunen, the commissioner responsible for tech sovereignty, security and democracy, had been expected to unveil the text on 14 January. It will now appear on 20 January. The postponement follows unusually tight control over the draft, officials from other Commission departments were required to visit a secure room at the Berlaymont without phones to read it, and mounting resistance from national capitals unwilling to surrender security competences to Brussels.
A broader toolbox for a wider threat
The regulation updates the 2019 Cybersecurity Act, which established certification schemes and defined the role of the EU Agency for Cybersecurity (ENISA). The new version goes further. It would give the EU executive powers to restrict or ban suppliers deemed "untrusted" from critical infrastructure across multiple sectors: telecommunications, connected vehicles, solar inverters, wind turbines, medical devices, surveillance cameras and security scanners. The measure is explicitly designed to address Chinese dominance in several of those markets. Huawei and ZTE in telecoms, Huawei again in solar inverters, Nuctech in airport and border scanners, and Hikvision in surveillance equipment are the names most often cited in internal risk assessments.
Accompanying the legal text is an ICT supply chain toolbox, a policy manual for national governments and security services on mitigating risks from specific technologies and vendors. Unlike the 2020 5G toolbox, which focused on a single industry, this one covers the digital supply chain broadly. The Commission's economic security strategy, published last month, signalled that the cyber law would be the vehicle for EU-level restrictions on high-risk suppliers, intertwining economic and security policy in a way the bloc has avoided until now.
The 5G precedent looms large
Five years ago, the EU adopted a 5G security toolbox urging member states to limit or exclude high-risk vendors from core networks. The language was careful: it did not name China or Huawei. The results have been uneven. Germany, France and Spain have imposed de facto restrictions through administrative hurdles and security certification. Italy used golden powers to block specific contracts. But several eastern and southern members took no binding action. Operators argued that stripping out existing Huawei kit would cost billions and delay rollout. Governments feared Chinese retaliation against exporters. The Commission has no enforcement lever; the toolbox is voluntary.
That experience shapes the current debate. Noah Barkin, senior advisor at the Rhodium Group, puts it bluntly: "If this is a repeat of the 5G toolbox across a broader set of industries, then I think it will be a failure." The Commission wants to avoid that outcome by writing binding EU-level restrictions into law. Capitals see a power grab.
Capitals guard their competence
The Czech Republic has been among the loudest European voices warning of Chinese espionage and influence. Its cyber agency, NÚKIB, drove the 5G toolbox and pushed for the broader ICT instrument. Yet even Prague baulks at the new proposal. Vladěna Sasková, director of international cooperation at NÚKIB, told reporters: "This topic is closely connected to national security, which is in exclusive responsibility of a member state, and our national-level system for managing supply chain risks should not be undermined by a centralised EU instrument." She added that the threat should be addressed at EU level, but not through new legislation without a proper assessment of existing tools.
Poland offers a middle path. Dariusz Standerski, deputy minister for digitalisation, suggests a joint list of high-risk vendors maintained at EU level. National governments would consult the list and decide individually whether to act. "There's still room to cooperate between member states without taking this competence totally to the European level," he said. The approach preserves sovereignty while creating peer pressure, if Germany and France list a company, others may follow.
Industry pushback from Beijing
Chinese industry has mobilised early. Linlin Liang, director of communication and research at the China Chamber of Commerce to the EU, argued that cybersecurity policy must be "evidence-based [and] technically-neutral." She said: "The risk cannot be associated with the origins of the companies. It should really be based on evidence and facts, and unfortunately, we failed to see this in the implementation of the 5G security toolbox. We are now very worried that this trend or this methodology will be implemented in the coming revision of the Cybersecurity Act." Liang warned that origin-based bans create legal uncertainty and deter Chinese investment.
The Chamber's position mirrors Beijing's diplomatic line: that the EU is weaponising security to protect domestic champions. European solar manufacturers, for instance, have long complained that Chinese state-backed firms undercut them on price while benefiting from opaque financing. The Commission's own anti-subsidy investigation into Chinese solar imports, launched in 2024, remains open. The cyber law would give a security justification for market exclusion that trade rules might not allow.
Parliament demands action
Not all European voices favour caution. Bart Groothuis, a Dutch liberal MEP who helped draft the 2019 Act and the NIS2 directive, wrote to the Commission last year warning of Chinese dominance in solar inverters, devices that convert panel output into grid-compatible electricity. "If not now, then when?" he said. "It's long overdue … It's about supply chain security, national security, it's also about competitiveness and about European industries being able to compete." Parliament will have co-decision power on the final text, and Groothuis's Renew group is likely to push for stronger mandatory measures.
The political dynamic is familiar: the Commission proposes, Parliament wants more ambition, the Council waters it down. In the 5G toolbox negotiations, the Council, representing capitals, stripped out any binding language. The same pattern may repeat. The difference this time is the scope: a single sector becomes a dozen, and the economic security strategy has already committed the Commission to using the law for EU-level bans.
What happens next
The text lands on 20 January. The European Parliament's industry committee (ITRE) will take lead, with civil liberties (LIBE) as associated committee. Council working parties will begin technical scrutiny in February. The Czech presidency of the Council in the second half of 2026 may try to broker a compromise, but Prague's own scepticism of centralised powers complicates that role. A final agreement before the 2029 European elections is plausible only if member states accept some EU-level listing mechanism. If they do not, the law becomes another toolbox: advisory, voluntary, and patchily applied.
Sources
People mentioned
Linlin Liang
Vladěna Sasková
Noah Barkin
Organisations
European Commission · European Parliament · China Chamber of Commerce to the EU · Czech National Cyber and Information Security Agency · Rhodium Group · Huawei