What are high-risk suppliers?
High-risk suppliers are vendors of ICT or OT products and services whose equipment, software or remote access a foreign government could influence through legislation, ownership or political pressure, making them a threat to the security of critical systems. The concern is not the quality of a single product but the non-technical risk that comes with its origin. The term emerged from the 5G debate around Huawei and ZTE and, since 2026, has been extending to energy, transport and other sectors of critical infrastructure.
🧠 What makes a supplier ‘high-risk’?
A supplier is not high-risk because its products contain more vulnerabilities; Western manufacturers have had serious flaws too. The difference lies in whether a state can compel the supplier to cooperate. The best-known example is Article 7 of China’s National Intelligence Law of 2017, which requires all organisations and citizens to “support, assist and cooperate” with state intelligence work and to keep that cooperation secret.
EU assessments therefore look at factors such as:
- Legal framework — third-country legislation that compels access to data or cooperation, without independent judicial oversight
- Ownership and control — state shareholders, subsidies or ‘decisive influence’ exercised through the board or financing
- Behaviour — the country’s cyber policy and track record of state-sponsored attacks, such as those attributed to Volt Typhoon
- Technical access — the extent to which the supplier still manages updates, configuration or data remotely after delivery
That last factor is what makes the topic so relevant to OT: the more an installation depends on the vendor’s cloud or maintenance, the greater the leverage a malicious or coerced supplier has over it.
📡 What does the EU 5G Toolbox require?
In January 2020 the member states, backed by the European Commission, adopted the EU Toolbox for 5G security. It sets out strategic and technical measures, including the instruction to assess the risk profile of suppliers and to apply restrictions or exclusions to high-risk suppliers for ‘key assets’ such as the 5G core network and network management functions. It also recommended vendor diversification so that no operator depends on a single supplier.
The Toolbox is not binding. The June 2023 progress report found that 24 member states had adopted or were preparing legislation allowing them to restrict suppliers, yet only 10 had actually imposed restrictions. The Commission stated explicitly that Huawei and ZTE posed “materially higher risks” than other 5G suppliers and announced that it would stop exposing its own corporate communications to mobile networks built with their equipment.
🏛️ What changes under the revised EU Cybersecurity Act?
On 20 January 2026 the Commission proposed a new Cybersecurity Act to repeal and replace Regulation (EU) 2019/881. Its main innovation is a trusted ICT supply chain security framework that extends the 5G approach to all 18 sectors covered by NIS2.
| Element | What the proposal contains |
|---|---|
| Risk assessments | The Commission and member states carry out EU-wide assessments of critical ICT assets and of technical and non-technical risks |
| Designation | Countries of cybersecurity concern, suppliers they control, or suppliers the Commission designates directly, become high-risk suppliers |
| Measures for entities | Among others, limits on data transfers and remote processing, segmentation, diversification and personnel vetting |
| Measures against suppliers | Phase-out of ICT components, exclusion from public funding, procurement and certification |
| Mobile networks | Phase-out within at most 36 months of the list being published (original proposal) |
The proposal follows the ordinary legislative procedure and, as of October 2026, is not yet law. A Council draft of 22 September 2026 drops the fixed 36-month deadline and ties phase-out to equipment lifespan and the availability of alternatives. Negotiations with the European Parliament still have to follow; adoption is widely expected in 2027.
Ahead of that, the Commission is already restricting EU money. Since 1 May 2026 the European Investment Bank, the European Investment Fund and other EU instruments no longer finance solar, wind or storage projects using inverters from suppliers in China, Russia, Iran or North Korea, including the power conversion systems of a battery energy storage system. Grandfathering applies only to advanced projects that can be approved by 1 November 2026.
🇳🇱 Which Dutch measures apply?
- Telecoms — the Decree on the security and integrity of telecommunications (Bvit) of December 2019 empowers the government to prescribe which suppliers operators may use in critical network parts. In May 2021 KPN, T-Mobile and Vodafone were instructed to exclude certain suppliers from critical components; Huawei was removed from the 5G core, while antennas were not covered.
- Investments — the Investments, Mergers and Acquisitions Security Screening Act (Wet Vifo), in force since 1 June 2023, screens acquisitions of vital providers and companies holding sensitive technology.
- Inverters — in a parliamentary letter of November 2025 the government stated that hidden functionality for remotely switching devices off is already prohibited, and that ministers should be able to exclude suppliers as a last resort; see Solar Inverter Cybersecurity.
- Duty of care — the Dutch Cybersecurity Act (Cyberbeveiligingswet), in force since 15 August 2026, requires essential and important entities to manage supply chain security; the Cybersecurity Decree details this in Article 10.
🏭 In which sectors do high-risk suppliers play a role?
| Sector | Example | Measure or concern |
|---|---|---|
| Telecoms | Huawei, ZTE | Exclusion from 5G core networks in the Netherlands and elsewhere |
| Energy | Solar inverters, battery systems | EU funding restriction since May 2026; concern about undocumented communication modules |
| Ports and transport | Ship-to-shore cranes from ZPMC | US congressional report (2024): cellular modems installed outside the contract scope |
| Physical security | Hikvision and Dahua cameras | US ban on new equipment authorisations (2022); UK halted deployment on sensitive sites |
| Drones | DJI | US added DJI to the FCC Covered List in December 2025 |
According to the September 2024 congressional report, ZPMC supplied nearly 80 per cent of the ship-to-shore cranes at US ports. In the UK, government departments were told in November 2022 to stop installing cameras from companies subject to China’s intelligence law on sensitive sites.
🔐 Why are high-risk suppliers an OT risk?
An OT installation often runs for twenty years and depends on its supplier throughout. The risk travels through four channels:
- Remote access — maintenance connections managed by the supplier itself, sometimes via a 4G modem that bypasses your firewall
- Firmware updates — whoever controls the update infrastructure can change how devices behave
- Cloud dependence — control or monitoring via a vendor platform outside the EU
- Kill switch — the ability to switch devices off at scale, with immediate physical consequences
With millions of inverters or thousands of charge points from a single brand, an individual supply chain risk becomes a systemic risk to the power grid.
🧭 How do you assess supplier risk step by step?
- Map the origin — country of incorporation, manufacturing and development for hardware, software and cloud services.
- Investigate ownership — shareholders, state influence and any listing on sanctions or exclusion lists.
- Follow the data flows — which data leaves your installation, and where is it processed?
- Inventory remote access — who can log in, through which channel, and can you block it locally?
- Control updates yourself — test and approve firmware before it is rolled out, as part of your patch management.
- Request an SBOM — so you can also see components from sub-suppliers.
- Write it into contracts — exit and replacement clauses, notification of ownership changes and requirements from IEC 62443-2-4 for integrators and maintenance providers.
- Restrict technically — place the equipment in its own zone with segmentation and allow only outbound traffic to known destinations.
These steps belong in a broader programme for Supplier Security and third-party risk management. For new products, the Cyber Resilience Act helps by setting requirements for updates and vulnerability handling. A typical outcome is a risk rating per supplier, reviewed at every contract renewal and whenever ownership changes.
❓ Frequently asked questions
Is Huawei officially a high-risk supplier in the EU?
In June 2023 the European Commission described Huawei and ZTE as suppliers posing materially higher risks than other 5G vendors. A formal, binding EU list of high-risk suppliers will only exist once the revised Cybersecurity Act has been adopted. Until then, member states decide on exclusion themselves.
Can my company still buy Chinese inverters or battery systems?
Yes, in 2026 there is no general ban on Chinese inverters or battery systems in the Netherlands. However, projects using inverters from high-risk suppliers no longer receive EU funding, and the revised Cybersecurity Act may later impose phase-outs. For procurement of critical OT, your own supplier risk assessment is therefore a sensible step.
When will the revised EU Cybersecurity Act apply?
The Commission published its proposal for the revised Cybersecurity Act on 20 January 2026. The Council and the European Parliament still have to agree, and adoption is expected around 2027. The rules on high-risk suppliers will only apply after the final regulation and the resulting lists have been published.
Is a high-risk supplier the same as an insecure supplier?
No, a high-risk supplier may deliver technically sound products. The risk lies in the possibility that a foreign government compels the supplier to assist with espionage or sabotage. That is why the assessment looks at legislation, ownership and remote access, not only at vulnerabilities.
What does the Dutch Cybersecurity Act require regarding high-risk suppliers?
The Dutch Cybersecurity Act requires essential and important entities to manage risks in their supply chain. As in the NIS2 Directive, they must take into account the vulnerabilities and security practices of each direct supplier and the results of coordinated EU risk assessments, such as the one for 5G. The law contains no list of banned suppliers, so you must be able to justify how you weigh the risk of high-risk suppliers in your supply chain.
Does an SBOM help against risks from high-risk suppliers?
An SBOM shows which software components are inside a product, including those from sub-suppliers. It lets you see whether a product from an apparently European vendor contains modules from a high-risk supplier. An SBOM does not, however, replace control over remote access and updates.
📌 In summary
High-risk suppliers pose a risk because of their possible dependence on a foreign state, not because of inferior technology, and the EU is extending the 5G Toolbox approach to all critical sectors through the revised Cybersecurity Act. For OT this means: know where your equipment comes from, who can reach it remotely and who controls the updates, and secure exit options before regulation forces your hand.
