Legal analysis flags WTO risks in EU Cybersecurity Act 2.0 revision | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


It suggests that the EU Cybersecurity Act 2.0 may conflict with the World Trade Organization’s non-discrimination rules.

The European Commission’s proposed revision of the Cybersecurity Act could conflict with international trade rules by enabling restrictions based on suppliers’ links to particular countries, according to a legal analysis by former WTO Appellate Body member and chair Peter Van den Bossche.

Proposed by the Commission in January 2026, the revised act would establish a trusted information and communications technology supply chain framework alongside changes to the European cybersecurity certification system.

Under the proposal, the Commission could designate third countries as posing cybersecurity concerns by considering their laws, oversight mechanisms, reported cyber activity and willingness to cooperate with the EU authorities. Suppliers established in, controlled by or otherwise linked to those countries could be classified as ‘high-risk’.

Restrictions could prevent essential entities from using components supplied by such companies in key ICT assets across the 18 sectors covered by the NIS2 Directive. Those sectors include energy, transport, health, finance, water, digital infrastructure, public administration and manufacturing.

Electronic communications providers may also be required to remove existing components from high-risk suppliers within 36 months. Further measures would restrict affected suppliers’ access to the EU cybersecurity certification, to certain public procurement procedures, to funding programmes, and to cybersecurity standardisation activities.

Van den Bossche argues that origin-based restrictions could raise non-discrimination and market-access questions under the General Agreement on Tariffs and Trade and the General Agreement on Trade in Services. Applying rules under the WTO Agreement on Technical Barriers to Trade would be less straightforward, according to the analysis.

The European Commission maintains in its impact assessment that the proposed measures comply with WTO commitments and that any trade-restrictive effects would be justified by the legitimate objective of securing critical ICT supply chains. Van den Bossche questions whether the EU could demonstrate that broad exclusions are necessary, proportionate and free from arbitrary discrimination.

China’s Ministry of Commerce has also disputed the proposal’s compatibility with WTO rules and warned that corresponding measures could be taken against EU companies. However, no formal WTO dispute has yet been initiated.

Telecommunications equipment, solar inverters, battery storage systems and connected vehicles could be particularly affected because foreign suppliers hold substantial shares of those markets.

The proposal remains under negotiation in the Council of the EU and the European Parliament, where lawmakers could amend the supplier assessment and exclusion mechanisms before adoption.

Why does it matter?

The dispute tests where cybersecurity policy ends and discriminatory trade treatment begins. The EU lawmakers will need to show that restrictions linked to a supplier’s origin or ownership are evidence-based, necessary and proportionate. At the same time, any resulting exclusions could reshape procurement, certification and technology supply chains across critical European sectors.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW