European digital sovereignty and the risk of confusing security with geopolitics

The former advisor at the Representation of Spain to the EU, Carlos M. Ortiz Bru, analyzes in Demócrata the dangers of Brussels' technological strategy: why changing external suppliers is not true strategic autonomy, but a simple change of dependence

9 minutes

Add DEMÓCRATA to Google

Ask FREN

Published

9 minutes

Most read

Europe has been talking about digital sovereignty for several years. The expression appears in speeches, regulations, and industrial strategies as a response to a legitimate concern: in an increasingly technological and unstable world, any power that aspires to preserve its decision-making capacity needs to maintain certain of its own industrial, scientific, and strategic capabilities.

The problem arises when some of the policies presented today under that label are examined. Then a disturbing paradox appears: part of supposed European autonomy seems to consist of replacing some dependencies with others while proclaiming an independence that is more rhetorical than real.

This transformation is especially visible in the treatment of Chinese technology. What just a few years ago was a debate about competitiveness, innovation, and industrial costs has progressively become a matter of national security. Infrastructures that were considered efficient and acceptable yesterday are now described as strategic threats. And this evolution coincides, not by chance, with the growing technological rivalry between the United States and China.

The issue becomes particularly relevant in the debate Brussels is having about the presence of Chinese suppliers in European telecommunications infrastructures. Over the past few years, the European Commission and several Member States have promoted measures to limit the participation of certain suppliers considered high-risk. The process began with the so-called 5G Toolbox, a set of recommendations to strengthen the security of mobile networks, and now continues with the revision of European cybersecurity legislation, which proposes more binding mechanisms that could facilitate broader restrictions and even the replacement of already installed equipment.

The official justification is well-known: to strengthen the security of critical infrastructures and increase European resilience. The question is whether all these measures truly respond to a logic of security or if, at least in part, they reflect a geopolitical and commercial response presented in more politically acceptable language. In other words: are we building true strategic autonomy or transforming an economic competition problem into a national security issue?

To answer that question, it is worth starting with the economic context.

The true origin of the problem

For decades, the relationship between Europe and China was based on a relatively clear complementarity. Europe exported technology, industrial machinery, and capital goods. China provided manufacturing capacity, competitive costs, and a gigantic market. That balance began to change when China ceased to be solely the factory of the world and also became a technological power.

The growing European trade deficit with China has reinforced the perception that the relationship has become unbalanced. And it is not a completely unfounded concern. However, it is advisable to carefully distinguish between different problems.

A significant part of China's progress is concentrated precisely in sectors that Europe considers strategic for its own economic transformation: electric vehicles, batteries, photovoltaic energy, and technologies linked to the energy transition. China produces many of the goods that Europe needs to meet its climate and industrial objectives with extraordinary competitiveness.

The President of the European Commission, Ursula von der Leyen, and the Chinese President, Xi Jinping. DATI BENDO / EUROPEAN COMMISSION
The President of the European Commission, Ursula von der Leyen, and the Chinese President, Xi Jinping. DATI BENDO / EUROPEAN COMMISSION -

It would be naive to ignore that part of this competitive advantage is related to aggressive industrial policies, public financing, and state support systems that generate controversy. The European Union itself has opened investigations to analyze possible market distortions.

But precisely for this reason, it is advisable to avoid confusion. If the problem is commercial, the response should be commercial: anti-dumping mechanisms, investigations into subsidies, reciprocity clauses, or a more ambitious European industrial policy. It is difficult to justify using instruments designed for national security as substitutes for an economic strategy. When an issue of industrial competition is automatically redefined as a security threat, there is a risk of applying inadequate remedies to real problems.

The curious European strategic autonomy

To this economic context is added another factor impossible to ignore: the growing technological rivalry between the United States and China. Washington has been pressuring its allies for years to reduce the presence of Chinese companies in sectors considered strategic. The arguments are well-known: risks of espionage, backdoors, and hidden vulnerabilities.

Of course, any critical infrastructure deserves rigorous scrutiny. No one disputes the need to protect telecommunications networks or energy systems. What is debatable is the tendency to turn geopolitical suspicions into regulatory certainties.

After years of public accusations and political debates, open technical evidence to justify some of the more radical measures remains scarce. That does not mean the risks do not exist. It simply means that regulatory decisions should be based on verifiable evidence, transparent technical analyses, and assessments proportionate to the real risk.

And here lies one of the great contradictions of the moment. Brussels constantly invokes strategic autonomy while adopting positions extraordinarily aligned with Washington's geopolitical priorities. Europe claims to want to reduce external dependencies, but risks substituting one for another. Excluding certain Chinese suppliers does not create European technological sovereignty; it simply redistributes the market among suppliers considered politically acceptable. If the end result is to depend less on China to depend more on other external actors, surely North Americans, strategic autonomy will have been reduced to a mere change of supplier.

From the 5G Toolbox to CSA2

This political evolution has translated into increasingly ambitious regulatory changes. What began in 2019 as a set of voluntary recommendations is evolving into more restrictive mechanisms through the revision of the Cybersecurity Act, informally known as CSA2.

The European Commission intends to have tools that allow it to identify suppliers considered high-risk, restrict their participation in essential infrastructures, and even promote the withdrawal of already installed equipment.

All this is justified in the name of resilience. The problem is that the concept risks becoming a label capable of legitimizing any measure without demanding the same attention to its costs as to its supposed benefits.

Because costs exist. Replacing already deployed equipment would mean billions of euros for European operators. Resources that would cease to be allocated to innovation, research, or network modernization to fund premature replacements of fully functional infrastructures. And this without clear guarantees that the increase in security would be proportional to the cost incurred.

Another practical problem is added to this. Although some argue that European manufacturers like Nokia and Ericsson can quickly fill any gap, numerous operators in the sector have warned that a massive replacement in a short period would be extremely complex.

Furthermore, the problem might not be limited to telecommunications. The same regulatory logic could extend to energy, transport, or technologies linked to the ecological transition. Europe maintains a significant dependence on Chinese components to meet its decarbonization objectives. Solar panels, batteries, energy storage systems, and numerous industrial components are part of that reality. Automatically applying an exclusion logic to these sectors could increase investment costs, slow down strategic projects, and hinder precisely the industrial and climate objectives that the European Union itself considers priorities.

The paradox would be evident: trying to strengthen strategic autonomy while simultaneously weakening the continent's industrial capacity.

Spanish Pragmatism

Spain has opted, until now, for a relatively more pragmatic approach.

After years of infrastructure deployment and analysis, no evidence has emerged to justify a massive and immediate expulsion of certain suppliers. In parallel, Madrid has opted to attract industrial investment linked to Chinese manufacturers. Projects promoted by Ebro and Chery, the collaboration between Stellantis and CATL, or the future industrial implementation of MG in Galicia represent attempts to transform a commercial relationship into productive capacity located in European territory.

The President of the Government, Pedro Sánchez, receives an honorary professorship at the Chinese Academy of Sciences MONCLOA
The President of the Government, Pedro Sánchez, receives an honorary professorship at the Chinese Academy of Sciences MONCLOA -

It would be premature to present them as consolidated successes. The history of technological transfers between the West and China offers contradictory examples and reasons for caution. Frequently, knowledge has circulated in only one direction. But even accepting these uncertainties, it is difficult to find a more promising alternative than trying to attract investment, production - and in the long term, know-how - and employment to Europe.

At least this strategy seeks to build its own industrial capacity. A policy based exclusively on prohibitions does not build factories, does not generate employment, and does not create technological autonomy.

The alternative that is barely debated

There is also a surprisingly absent issue in much of the European debate. Even accepting that certain suppliers may present additional risks, why does the only imaginable response seem to be their complete exclusion?

In practically any other technological field, a different logic applies: reduce risks through additional controls. Modern cybersecurity works precisely like this. The most advanced architectures start from a simple idea: do not fully trust anyone. It is not assumed that a supplier is perfect. Systems are designed to continue functioning even if some of their components are compromised.

This is the principle known as Zero Trust. Applied to telecommunications, it implies segmenting infrastructures, isolating critical components, strengthening encryption mechanisms, permanently monitoring traffic, and subjecting hardware and software to continuous audits. Simply put: it is not necessary to fully trust a supplier to use their equipment; it is enough to design the system so that this trust is not essential.

European Comission
European Comission -

Proponents of widespread exclusions respond that 5G networks present higher levels of technological integration and that completely isolating certain components is more complex. This is a technically legitimate objection. But even accepting it, a fundamental question remains: does it make sense to incur multi-billion euro replacement costs when mechanisms exist that can significantly reduce risks?

Some European operators are already exploring precisely this approach and have begun to develop segmentation and reinforced control strategies aimed at managing risks without necessarily resorting to massive equipment replacements. It is a less spectacular solution politically, but probably more coherent from a technical point of view. Bans generate headlines and allow for the transmission of strong messages. Engineering rarely makes the front page.

Sovereignty or simple change of dependence

If the objective is truly to strengthen European security, there are more proportionate alternatives than those currently proposed: allowing already installed equipment to complete its life cycle, avoiding premature replacements that generate enormous costs with questionable benefits; applying new regulatory requirements only to future deployments, allowing for a gradual and economically sustainable regulatory transition; strengthening the role of the European Union Agency for Cybersecurity (ENISA) through transparent certification mechanisms based on hardware, software, and source code audits applicable to all suppliers without discrimination based on nationality, and perhaps most importantly, extending security architectures based on segmentation, continuous monitoring, and Zero Trust principles.

These measures would allow for the management of real risks without automatically resorting to general bans. Because true security does not consist of trusting some suppliers and distrusting others. It consists of building systems capable of withstanding even when some of them fail.

The difference between sovereignty and following

Europe today faces a strategic choice of great importance. It can bet on autonomy based on its own industrial capabilities, technological innovation, productive investment, and objective technical criteria. Or it can move towards a model where geopolitics progressively replaces economic analysis and engineering.

The difference is fundamental. Changing one dependency for another is not sovereignty. True autonomy consists of depending less on everyone, not choosing whom we want to depend on. If politics ends up substituting engineering and security ends up becoming an instrument of commercial policy by other means, Europe runs the risk of sacrificing competitiveness, increasing infrastructure costs, and slowing down its technological modernization in the name of an independence that it may never achieve.

 

More key points, information and questions with FREN

AI-GENERATED CONTENT

What is the parliamentary status of the Cybersecurity Act (CSA2) review in the European Union and what are the next steps for its approval?

Parliamentary status of CSA2 and next steps

Current status of CSA2 and next steps in the EU

As of June 13, 2026, the review of Regulation (EU) 2019/881, informally known as “Cybersecurity Act 2” (CSA2), is in an early stage of the ordinary legislative procedure of the European Union. The Commission has already submitted a proposal to amend the Regulation, and it has been sent to national parliaments for subsidiarity control, a phase that in Spain concluded in April 2026 without formal objections. It is not yet recorded that the European Parliament has adopted its first reading position nor that the Council has approved a general approach, so trilogues have not been initiated. Consequently, the next steps involve internal work within Parliament and Council and, only afterwards, the interinstitutional negotiation that will lead to the final text.

1. Starting point: current Regulation and scope of the review

The reference framework remains Regulation (EU) 2019/881, which establishes ENISA's mandate and creates the European cybersecurity certification framework. The base text can be consulted on EUR‑Lex. This regulation has already been amended occasionally, for example through Regulation (EU) 2025/37 on managed security services, but the CSA2 reform is conceived as a broader revision of the system, strengthening ENISA's powers and adjusting the certification framework, in line with other instruments such as NIS2 and the future deployment of the Cyber Resilience Act, which is a distinct instrument.

According to the analysis by El Demócrata, the reform also fits into a geopolitical context marked by concern over providers considered “high risk” in critical infrastructures (telecommunications, energy, etc.), introducing tools to limit their participation or even require equipment withdrawal in certain cases.

2. Current phase: subsidiarity control and absence of legislative positions

After submitting the proposal, the Commission sent it to national parliaments for subsidiarity control (standard period of 8 weeks). In Spain, the initiative was examined by the Joint Committee for the European Union of the Congress and the Senate, which approved the subsidiarity report on 04/13/2026 by assent, without a negative reasoned opinion. The file can be seen in the Official Bulletin of the General Courts, Series A, no. 232, available in this Congress PDF, and in the informative tracking sheet of the European initiative at Quehacenlosdiputados.es.

With the information accessible in official and open sources, it is not yet recorded that:
– The European Parliament has approved its first reading position (neither in committee nor in Plenary).
– The Council of the EU has adopted a general approach that serves as a negotiation mandate.
Trilogues between Parliament, Council, and Commission have been initiated.

This places the file in a preparatory phase: assignment to Parliament committee(s) (likely ITRE and/or LIBE), appointment of rapporteur, drafting of report, and technical debates in Council working groups (Telecommunications/Information Society).

3. Formal next steps in the ordinary legislative procedure

The standard path expected for CSA2 is as follows:

a) In the European Parliament
– Formal assignment of the file to the competent committee and appointment of rapporteur and shadow rapporteurs.
– Presentation of a committee draft report, with amendments from political groups.
– Vote on the report and, if applicable, on a negotiation mandate authorizing the start of trilogues before the Plenary.
– Vote in Plenary on the first reading position.

To follow these steps once the file is fully indexed, the entry point is the Legislative Observatory (OEIL): European Parliament OEIL.

b) In the Council of the EU
– Meetings of sectoral working groups to refine the position of Member States.
– Adoption by the Council of a general approach, which functions as a negotiation mandate vis-à-vis Parliament.
– Possible revisions of the mandate as dialogue with Parliament progresses.

Monitoring is done through the Council's legislative tracker: Council legislative tracker.

4. Trilogues, final adoption, and timeline

Only when Parliament has set its first reading position and the Council has its general approach can trilogues begin. In this phase, the three institutions negotiate a compromise text; if agreed, it is consolidated into a Council first reading position and Parliament endorses it in second reading, or vice versa, depending on when the agreement is reached. Afterwards, the signature and publication in the Official Journal of the EU (OJ) take place, after which the revised regulation enters into force (usually 20 days after publication, unless otherwise provided).

Since to date there are no formal positions from Parliament or Council nor trilogues underway, it is not possible to set a reliable schedule for final adoption. As a guideline, reforms of this scope usually take between 18 and 30 months from the Commission's proposal. Taking as reference that subsidiarity control in national parliaments ended in mid-April 2026, a reasonable horizon, always subject to the agenda of the new European legislature and the degree of consensus among Member States, could be between late 2027 and 2028, but this is a speculative projection.

To contextualize the review, the political analysis on the dimension of digital sovereignty and the risk of confusing security with geopolitics published by El Demócrata may be useful, as well as the monitoring of internal impact in Spain and debates on delays in the cybersecurity framework, described in this report.

What are the powers and attributions of the European Commission in cybersecurity and regulation of technology providers?

Summary

The European Commission plays a central role in cybersecurity and in regulating technology providers, but its power is mainly normative, promotional, and supervisory of compliance, not direct operational over Member States. It proposes major rules (such as NIS2, the Cyber Resilience Regulation, or digital services legislation) and monitors that States and companies apply them correctly. Additionally, it defines cybersecurity certification frameworks, coordinates responses to cross-border incidents, and can intervene in competition matters against large platforms or dominant providers. Many concrete security decisions remain the competence of Member States, but under a common framework designed and overseen by the Commission.

1. General role of the European Commission in cybersecurity

At the Union level, cybersecurity is conceived as an area of shared competence: Member States retain competencies in national security, but the Commission promotes and coordinates common policy in everything affecting the internal market and the provision of digital services. This includes harmonizing requirements for operators of essential services and digital service providers, creating minimum obligations for risk management and incident notification, and strengthening the resilience of technological supply chains operating throughout the EU.

Since it is a highly cross-border area (networks, cloud services, platforms, digitized critical infrastructures), the Commission relies on the legal basis of the internal market to justify adopting directives and regulations that avoid a divergent regulatory mosaic among countries. In practice, this allows it to establish a “common floor” of technical and organizational requirements, which States can tighten but not lower.

2. Normative powers: proposal and development of legislation

The Commission's most relevant attribution is legislative initiative in cybersecurity and technological regulation. It can propose directives and regulations which, after approval by the European Parliament and the Council, become binding. Among the major recent regulatory packages fitting this area are cybersecurity of networks and systems (such as the framework replacing and expanding NIS), the Cyber Resilience Regulation, and specific regulation of digital services and platforms (including security, risk management, and transparency requirements for large technology providers).

Additionally, the Commission is empowered to adopt delegated and implementing acts foreseen in those norms. Through these acts, it can specify technical requirements, risk assessment methodologies, incident notification formats, or detailed criteria to classify services and providers by criticality level. This grants it significant capacity to adapt the regulatory framework to technological evolution without constantly reopening major legislative texts.

3. Supervision, enforcement, and infringement procedures

Once the rules are approved, the Commission has the attribution to ensure they are properly applied in all States. It supervises the transposition of directives into national legal systems, reviews that Member States designate competent cybersecurity authorities, single points of contact, and incident response teams, and that they provide those authorities with sufficient sanctioning powers against operators and providers who fail to comply.

If it detects that a State does not transpose on time, does so incompletely, or does not properly apply cybersecurity or technology provider regulation obligations, the Commission can open infringement procedures. These procedures can culminate in cases before the Court of Justice of the EU and, ultimately, economic sanctions. It can also launch reviews of the regulation's functioning (impact assessments, implementation reports) and propose adjustments when it detects regulatory gaps or widespread compliance problems.

4. Regulation and control of technology providers

Regarding technology providers, the Commission acts on several levels. First, it sets security and data governance requirements for certain services (e.g., cloud services, content platforms, online marketplaces, or mobile operating systems), depending on their size, systemic role, or criticality. These requirements may include security audits, vulnerability management obligations, algorithmic transparency, or enhanced data protection and service continuity measures.

Second, it promotes EU-wide cybersecurity certification frameworks, which allow labeling technological products and services according to assurance levels. Although technical management is handled by specialized agencies and evaluation bodies, the Commission defines the general framework and can propose specific schemes for high-risk product categories (e.g., connected devices or network components). This directly affects how providers design and market their solutions in the European market.

Third, it uses its competition and internal market powers to intervene against dominant providers' conduct that may affect, among other aspects, the security and resilience of the digital ecosystem. It can impose structural or behavioral remedies, require interoperability and fair access to essential infrastructures, and monitor that control of key technologies is not used to distort the market to the detriment of security or innovation.

5. Coordination, incident response, and international cooperation

Although operational incident management remains national, the Commission has coordination powers when a cybersecurity incident has significant cross-border impact. It participates in coordinated response mechanisms, promotes information exchange among States, and fosters joint exercises and contingency plans at the EU level. Likewise, it promotes European cybersecurity strategies that guide investment in capabilities, public-private cooperation, and the development of the cybersecurity industry.

Finally, the Commission represents the EU in many international forums on technical standards, Internet governance, and cybersecurity, and negotiates or coordinates common positions in agreements with third countries. In this way, it exports European regulatory standards on digital security abroad and influences the practices of global technology providers wishing to operate in the European market, transferring the so-called “Brussels effect” to the cybersecurity field.

What legal requirements are necessary for the European Union to restrict the participation of providers considered high risk in critical infrastructures?

Brief answer

For the European Union to restrict the participation of providers considered high risk in critical infrastructures, essentially a clear legal basis in EU law (treaties or secondary legislation) is needed, respect for the internal market and free competition, and a solid justification based on national security, public order, or network and information security. Such restrictions must be proportionate, not discriminatory without objective reason, and properly motivated. Additionally, they are usually articulated through sectoral legislation (e.g., telecommunications, energy, transport, digital services), Commission decisions, or coordination frameworks among Member States. As a specialized assistant in policy and regulation, but focused on the Spanish context, I can explain it from a general legal-political perspective without delving into the technical details of all possible European instruments.

1. Legal basis and respect for the internal market

The EU can only limit the participation of providers in critical infrastructures if it relies on a legal basis in the Treaties (mainly the Treaty on the Functioning of the European Union, TFEU) and derived legislation (regulations, directives, or decisions). The starting point is that the free movement of goods, services, capital, and the right of establishment are the general rule in the internal market. Any restriction on a provider's participation, especially if from another Member State or a third country, is considered an exception that must be well justified.

The Treaties allow exceptions to free movement for reasons of public order, public security, and public health, and the Court of Justice of the EU's case law has consolidated that the protection of critical infrastructures and cybersecurity can fit within these overriding reasons of general interest. But it is always required that the measure be proportionate (not going beyond what is necessary) and suitable to achieve the security objective.

2. National security and Member States' margin

National security is primarily a Member State competence, but national decisions affecting the internal market's functioning (e.g., excluding certain providers from 5G networks, energy systems, or essential digital platforms) must be compatible with EU law. This means that, although the EU recognizes a broad margin to protect national security, arbitrary or purely political use of that clause is not allowed: risk assessments, objective criteria, and a clear link between the “high risk” provider and the threat to critical infrastructure must exist.

From a political perspective, in Spain this balance is seen in how the Government must justify to the European Commission and other partners any relevant restriction that may affect investments or contracts in regulated sectors, aligned with the existing European frameworks on cybersecurity, foreign investments, and critical infrastructure protection.

3. Sectoral legislation and cybersecurity frameworks

In practice, restrictions on high-risk providers are mainly implemented through sectoral and network and system security legislation. At the European level, the typical approach is:

First, define what is critical infrastructure or “essential service” (e.g., sectors like energy, transport, banking, health, drinking water, digital infrastructures) through cybersecurity and infrastructure protection directives. Second, impose on operators of essential services and digital service providers obligations for risk management, supply chain security, and incident notification, including risk assessment of third-party providers. Third, enable Member States to designate certain providers as high risk, based on objective criteria (links with third-country governments, history of cyber incidents, ability to comply with security requirements, etc.) and, from that designation, limit or prohibit their participation in critical network and system components.

Within this framework, the EU usually promotes coordination: information exchange on threats, development of “toolboxes” or sets of recommended measures, and, in some cases, the possibility for the Commission to oversee that national restrictions do not violate EU law.

4. Requirements of proportionality, transparency, and control

From a legal-political standpoint, restrictions must meet a series of minimum requirements to pass European scrutiny:

First, proportionality: the measure must be necessary and the least restrictive possible to achieve the security objective. Blocking a provider's total participation would only be justified if less restrictive measures (network segmentation, certification requirements, additional controls) are insufficient. Second, non-discrimination: a provider cannot be treated worse without objective basis. Although many debates have focused on companies from certain third countries, legally there must be a risk assessment justifying differential treatment. Third, motivation and procedure: decisions must be reasoned, subject to some form of administrative or judicial review, and, when having a European dimension, notified or coordinated within the EU framework.

Finally, in the Spanish context, any such measure is inserted into national legislation on national security, cybersecurity, and critical infrastructure protection, which in turn transposes and applies European obligations. Democratic control is exercised through the Government, Parliament, and judicial oversight, ensuring that restrictions on high-risk providers in critical infrastructures are legally founded and politically supervised.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What is the main concern that has motivated Europe to promote digital sovereignty?

Question 1 of 3

What was the EU's first initiative to strengthen the security of mobile networks against risky suppliers?

Question 2 of 3

What economic consequence is mentioned regarding the replacement of already installed equipment for security reasons?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?