Much of CSA2 Is Already National Law
As the Council has begun its deliberations on Cybersecurity Act 2 (CSA2), its controversial Section 4 on supply chain security is being framed by the Member States as upending the delicate balance between national and EU competences. This section is described as overly complex and far-reaching, potentially upending the Member State competences in the treaties.
The notions of legal complexities are nominally true – but often come with the territory. But as for how far-reaching the draft is, it’s a subject of debate.
For a start, about 70% of the installed 5G equipment in the EU is already supplied by trusted vendors. More than fifteen Member States have already implemented restrictions on high-risk vendors (HRVs) under the 5G Toolbox. Of roughly 100 5G networks across the Union, 60 already lack any Chinese equipment covered by Annex II. Of the 40 networks with some exposure, only 30 are materially affected – and in many of those, phase-outs are already underway under national instruments. Thus, the political outcome that CSA2 is supposed to create is already an operative reality in national legislation.
CSA2 does not change that fact, but merely retrofits an EU framework that formalises it. For the Member States that already implemented the 5G Toolbox, CSA2 affects nothing in their installed base, procurement, or risk assessments. Their competent technical and security authorities continue to do what they were already doing, while 5G operators continue to operate under the same rulebook. The harmonisation that CSA2 introduces, for them, is a mere clean-up operation: moving rules they already follow into a binding legal EU framework that they cannot diverge from too far.
How Much Discretion Do Member States Keep?
For the Member States that did not implement the 5G Toolbox, the question is how much room the framework leaves them. The answer is more than the Commission’s drafting suggests at first reading, and less than some would prefer.
At the onset, Article 4(2) TEU is preserved, with national security remaining a Member State competence. Each of the six procedural steps from coordinated risk assessment to HRV designation is a separate implementing act, individually contestable by a minority under Regulation 182/2011.
A coalition of four Member States representing 35% of the EU population – easily assembled by Germany, Spain, Greece, Hungary, Austria, and Ireland – prevents a positive committee opinion but does not, by itself, block adoption. The Commission may proceed on a “no opinion” basis unless the basic act says otherwise, although it is less likely to do so against the express opposition of Berlin, Paris, Rome, or Madrid, as the political cost outweighs the legal authorisation. Nonetheless, the Member State check rests on Commission self-restraint rather than on a hard legal bar.
A Challenge to the Legal Basis
Needless to say, certain Member States will argue here for a legal basis that triggers unanimity at each step, such as the CFSP under Title V of TEU rather than internal market harmonisation (Article 114). The former option – i.e., to recast the high-risk designations as a form of sanctions – would give each Member State a veto and also sideline the European Parliament from the legislative process. But if CSA2 rests on the legal basis of harmonisation instead, the Member States cannot categorically refuse to apply CSA2 implementing acts by simply invoking national security exceptions.
The CSA2 contains a standard non-preclusion clause (specifically, Article 98(3) in the draft) that allows Member States to go further in their implementation. However, Member States cannot invoke the national security exception in the opposite direction – to refuse implementation of agreed measures – on the grounds that the obligations threaten their relationships with other countries.
This limitation has been established by a coherent line of case law. In La Quadrature du Net (joined cases C-511/18, C-512/18 and C-520/18), the Court held that Article 4(2) TEU does not exclude Member States from the scope of EU law where it is engaged, and that the national security reservation operates as an interpretive principle and not a cop out; and Privacy International (C-623/17), which applied the same reasoning to UK national security data retention laws.
The Commission has also successfully litigated against Member State invocations of national security to derogate from Union obligations across a coherent line of cases – including Commission v Spain (C-414/97), Commission v Finland (C-284/05), and Commission v Sweden (C-294/05), and Commission v Hungary (C-66/18) on either Article 346 TFEU or Article 4(2) TEU.
In conclusion, 4(2) TEU bites very narrowly in this context as an interpretative principle on specific treaty derogations for core military and intelligence functions (such as 346 TFEU for arms and war material) under the treaties.
Formalising the Informal
The institutional centre of gravity inevitably moves under CSA2, though less than expected. As of today, the NIS Cooperation Group (NISCG) holds the levers, with the Commission merely acting as secretariat – although in reality, significant outsourcing of both analytical and policy work takes place to DG CNECT.
CSA2 preserves that pathway as “default”, as the Commission or three Member States may trigger a NISCG-led assessment. What is new under Article 99(3) is how the Commission may conduct its own assessment in significant-threat cases, with Member States merely consulted.
While this point has become another fault line in the deliberations, this addition makes very little difference: There is probably no point in history where the Commission could not find at least three like-minded Member States. Conversely, the Commission is unlikely to initiate even a study when it cannot do so.
However, the right to propose the designation of third countries, the identification of key ICT assets, and the HRV listing all sit with the Commission, pending approval of the Member States. The draft codifies the group dynamics and pattern of influence that already exists informally. The initiation and operational tempo of each toolbox was always set by a small group of individuals across the agencies and associated Signal groups, with NISCG ratifying each output.
This staging gave Member States equal seats as principal actors, while the Commission retained control over the pace. CSA2 switches the lens, but for Member States with a national interest and the technical staff to engage with the comitology process, nothing materially changes. And for those capitals that relied on the NISCG to do the work for them, they will continue to rely on the consensus among the Member States.
Changing the Politics
For five years, mobile operators in Member States have argued – in Berlin, Dublin, Vienna, or Athens – that the absence of a Union legal framework left their national governments without a reason to act. Their argument was thin – as echoed recently in the AG Opinion in the Elisa Eesti (C-354/24) – and without legal merit under CSA2. An operator claiming that EU law does not authorise non-technical risk mitigation in the ICT supply chain is making a statement that is no longer credible.
Similarly, operators have argued that the equipment in their networks is not Chinese but a mix of “components” integrated into systems they themselves operate – the implication being that anything short of a finished HRV product should fall outside whatever Brussels eventually legislates. The draft closes the loophole, as the mitigation covers “ICT components or components that include ICT components” (articles 103 and 111) from an HRV, reaching at least into tier-2 into the supply chain.
In conclusion, CSA2 changes are not necessarily legal outcomes but rather political pretexts: Member States collectively agree to minimum mitigating measures and may attribute them to Union law, thereby providing plausible deniability that they are national policy choices. Chinese demarches or Trump tweets threatening reciprocal action against European companies are now owed to the EU level. The friction will never fully disappear, but it will change its address from Willy-Brandt-Straße to Rue de la Loi.
Member States Are Not the Regulated Entities
In conclusion, the Council’s position on the new framework will depend on a few parameters. For Member States that are doctrinally inclined, the limits on national policy space under CSA2 are likely to matter most. Whether they fight back by introducing derogations during drafting – or litigate for annulment once the Act is agreed – is a matter of tactics.
But for those inclined towards more transactional realpolitik, the breadth of the HRV prohibitions under Annex 2 – i.e. whether it will include fixed networks – will determine which side of the fence they come out on.
It bears reminding that the actual regulated entities under the draft are not the Member States but a few operators with concentrated national positions that all bet on retaining political influence over their national governments and forgot to lobby the Commission. In reality, the thirty materially exposed operators come down to just seven or eight parent companies. For instance, the German consensus of July 2024 allowed Chinese vendors in the RAN but required open OSS interfaces – a mitigation that is structurally inconsistent with the 5G toolbox that Germany once signed. What the draft does is to prevent such outcomes in the future.
The next point of contention will be the 36-month phase-out clock for mobile networks, which begins upon publication of the high-risk supplier list, which, in turn, occurs after the CSA2 regulation comes into force. Realistically, the earliest deadline is for 5G, and still at least five or six years out. By that time, most of the 5G base stations will be written off, and those operators who hoarded Chinese equipment ahead of CSA2 – fully aware of the possibility of regulatory action – can safely transfer these assets to their subsidiaries outside the EU.
The current CSA2 draft may be far from perfect. But it is best read as harmonising and codifying existing ambitions rather than changing them. What it harmonises is not necessarily outcomes but excuses, as it does not impose any new policy but removes the legal cover for evading the soft obligations already undertaken via the toolbox.
For better or worse, the CSA2 draft closes that waffling gap between agreed texts and pretexts.
2 responses to “Cybersecurity Act 2 and National Security: Same as It Ever Was”