Securing Europe Without Sacrificing Regulatory Certainty

Must read

Diplomat Magazine
Diplomat Magazinehttp://www.diplomatmagazine.eu
DIPLOMAT MAGAZINE “For diplomats, by diplomats” Reaching out the world from the European Union First diplomatic publication based in The Netherlands. Founded by members of the diplomatic corps on June 19th, 2013. "Diplomat Magazine is inspiring diplomats, civil servants and academics to contribute to a free flow of ideas through an extremely rich diplomatic life, full of exclusive events and cultural exchanges, as well as by exposing profound ideas and political debates in our printed and online editions." Dr. Mayelinne De Lara, Publisher

Europe’s Security Imperative: Protecting Critical Infrastructure Without Undermining Regulatory Certainty

By M. De Lara

Cybersecurity and geopolitical security measures must not undermine regulatory certainty, technical standards, and investment confidence. When Geopolitics Enters Technical Rules: Europe Needs Security—and Must Preserve Certainty and Its Standards Advantage

Geopolitical tensions are increasingly reshaping global trade, technology and industrial cooperation. For the European Union, growing supply-chain dependencies, foreign interference and cyber threats have made the security of critical infrastructure a strategic priority. Europe therefore has legitimate reasons to strengthen its ability to identify and address risks that extend beyond the technical security of individual products and systems.

The challenge, however, is to ensure that stronger security measures do not come at the expense of the regulatory certainty that underpins the Single Market. In recent years, Member States have adopted different approaches to non-technical supply-chain risks and high-risk suppliers, creating the risk of fragmentation. The European Commission’s proposed revision of the Cybersecurity Act—CSA 2.0—in January 2026—seeks to address this through a common EU framework for trusted ICT supply chains.

Alongside strengthening ENISA and reforming the European Cybersecurity Certification Framework, the proposal adds a binding “trusted ICT supply chain framework”. This would bring factors such as third-country legislation, foreign influence, ownership and control structures into EU cybersecurity governance.

The regulatory question would therefore no longer be limited to whether a product is technically secure. It would also encompass whether a supplier is considered trustworthy from a geopolitical and institutional perspective.

That shift responds to genuine concerns. Critical infrastructure cannot be protected solely by addressing software vulnerabilities and product performance. Europe must also consider the risks of foreign interference, malicious control and systemic supply-chain dependency.

Yet security policy must answer more than one question. It must define the risks Europe seeks to prevent—but it must also allow European businesses to know whether the technologies they select, the equipment they purchase and the investments they make today will remain lawful, usable and valuable ten years from now.

The key question is therefore not whether Europe should strengthen security, but how it can do so while preserving the clarity, predictability and standards-based system on which long-term investment and the competitiveness of the Single Market depend

How would CSA 2.0 work?

CSA 2.0 would establish a common EU mechanism for assessing and mitigating ICT supply-chain risks.

The Commission, or a group of at least three Member States, could trigger a coordinated EU-level supply-chain security assessment. The Commission could subsequently designate “third countries posing cybersecurity concerns”, identify “key ICT assets” used across the 18 sectors covered by NIS2, and determine high-risk suppliers on the basis of factors including establishment, ownership and control.

The Commission could then require relevant entities to implement measures such as audits, restrictions on data transfers and contractual relationships, and supplier diversification. It could also prohibit the use of components from specified suppliers in key ICT assets and, in certain circumstances, require the phase-out of components already deployed. European Commission proposal for CSA 2.0

The objective is legitimate: to prevent fragmented national responses and build a more resilient Single Market. But the current design raises a fundamental concern:

The proposal creates a potentially powerful decision-making mechanism without providing businesses with equally clear decision-making standards

The greatest industrial risk is an inability to price the future

The proposal contains criteria for concepts such as “key ICT assets”, “significant cybersecurity risks” and “serious and structural non-technical risks”. Yet these criteria do not currently provide sufficiently granular or measurable thresholds for businesses operating across very different sectors.

Which components will ultimately be considered key? Which suppliers may face restrictions? What level of risk will trigger an audit, diversification requirement, procurement restriction or outright prohibition? Much of this would be determined later through risk assessments and implementing acts.

Consequently, even a product that complies with European technical standards and has obtained cybersecurity certification may not remain eligible for use in critical infrastructure. Market access could depend not only on the product’s technical characteristics, but also on its supplier’s ownership, the legal environment of its home country and an evolving geopolitical assessment.

The costliest regulatory burden is not the price of compliance. It is the inability to know whether compliance will still secure access to the market

Critical infrastructure is normally planned over ten- or twenty-year investment cycles. If companies cannot assess the long-term eligibility of suppliers, installed equipment or entire technology pathways, they will respond before any formal restriction is imposed. They may freeze procurement, shorten contracts, reduce research spending, redesign systems or relocate factories, data centres and R&D programmes to jurisdictions offering greater regulatory predictability.

Uncertainty itself creates a regulatory overhang. Corporate boards will avoid technologies that might be restricted in the future. Banks will price additional risk into financing. Insurers will reassess exposure, while smaller suppliers will follow the location decisions of major investors.

The eventual cost is not limited to replacing equipment. It includes stranded assets, factories that are never built, research centres that are located elsewhere, and the talent and supply-chain ecosystems that move with them.

Capital can absorb risk. It cannot price discretion whose boundaries continue to move

Annual business investment in the EU is roughly €2.4 trillion. An ECB study estimates that a typical economic policy uncertainty shock reduces euro-area business investment by around 1.2% at its trough, with the impact persisting for some time. This is not an estimate of the cost of CSA 2.0. It does, however, demonstrate that even a small uncertainty effect across 18 critical sectors could place tens of billions of euros of investment at risk. European Central Bank

Global evidence also shows how quickly investment reacts to geopolitical signals. IMF research finds that, since Russia’s invasion of Ukraine, the number of announced FDI projects between geopolitically distant blocs has declined by roughly 20% relative to investment within the same bloc. Investment losses often occur before formal restrictions are adopted—and once an industrial ecosystem has been established elsewhere, attracting it back is difficult. International Monetary Fund

Nor does excluding suppliers automatically create new European capacity. In markets already characterised by a limited number of specialised vendors, exclusion may further concentrate supply, raise prices, reduce innovation and increase dependence on the remaining suppliers.

A policy designed to strengthen resilience may, if it reduces choice, competition and investment, remove one risk only to create a larger one

Standards are a foundation of Europe’s global competitiveness

Europe competes globally not only through the size of its Single Market, but through its ability to turn technical excellence into common rules.

Over several decades, common technical standards, certification and mutual recognition have helped build the Single Market. Through organisations such as ISO, IEC, ITU and ETSI, Europe has also shaped global industrial development. For European companies, early participation in standard-setting can create technological leadership, facilitate market access and support entire industrial ecosystems.

Standards may be Europe’s most successful invisible export

Studies cited by the European Commission have estimated the macroeconomic contribution of standardisation at around 0.8% in France and 1% in Germany. In Germany alone, standardisation has been estimated to generate annual economic benefits of up to €17 billion. European Commission material on the economic role of standards

The value of standards, however, cannot be measured only in direct economic gains. Their deeper value lies in the expectation they create: comparable risks should be subject to comparable requirements, and products meeting those requirements should receive broadly consistent treatment in the market.

The authority of a standard does not rest simply on the rule-maker’s power to demand compliance. It rests on the rule-maker’s willingness to be bound by the same rule

If products that comply with European standards and pass European certification can nevertheless be excluded through non-technical assessments whose boundaries are not clearly defined, technical compliance will no longer provide a predictable route to market.

Once compliance and market access become disconnected, standards cease to function as a common market passport. They risk becoming technical reference documents that can be overridden by political decisions at any time.

The consequences would extend well beyond individual suppliers. Companies would have less incentive to invest in shared standards and certification. Other regions would accelerate the development of their own standards, assurance regimes and supply-chain ecosystems. The global market could fragment into parallel technical systems that duplicate research, testing and certification while trusting one another less.

European exporters would face the same duplication abroad—and potentially reciprocal restrictions justified by other governments on geopolitical and national-security grounds.

A standard can be overridden by a single political decision. Rebuilding trust in the standards system may take a generation

When rule-makers begin to bypass the rules they have built, the first casualty is not a particular product or supplier. It is the credibility of the rules themselves. If Europe weakens technical standards to gain short-term political discretion, it risks consuming one of its most valuable—and least easily replicated—sources of global competitiveness.

Making security and certainty mutually reinforcing

CSA 2.0 does not need to disregard non-technical risk. It does, however, need clearer limits.

Technical assessment should come first, with non-technical factors serving as a complementary layer. Intervention should focus on the highest-risk scenarios capable of producing systemic consequences. A transparent risk-to-measure framework should distinguish between risks that justify monitoring, auditing or diversification and those exceptional cases that warrant prohibition or phase-out. Clear thresholds, proportionality requirements and realistic transition periods should provide businesses with the greatest possible degree of certainty.

Europe does not need unlimited security discretion. It needs a bounded security capacity capable of addressing the most serious risks with precision.

Geopolitical judgement may be necessary to manage exceptional cases. It should not replace technical rules as the normal basis of market governance. Europe must de-risk—but it must not de-rule.

If regulatory certainty and technical standards lose credibility, Europe will lose far more than individual investments or suppliers. It will weaken one of the deepest foundations of the Single Market—and one of the Union’s most valuable sources of influence and competitiveness in the global economy.

By adressing non-technical criteria in the CSA2 the cybersecurity act that originally was based on technical security standards, by design, can become a trade instrument. Whether this was intently or not is not relevant. It deviates significantly from its main objective, reinforcing Europe’s cybersecurity.

- Advertisement -spot_img

More articles

- Advertisement -spot_img

Latest article