I. Introduction
EU cybersecurity regulation rarely stands still, but three developments now converging make this a particularly consequential moment for the sector: the European Commission's proposal to revise the Cybersecurity Act (“CSA2”), the ongoing operationalisation of the NIS2 supply-chain security framework across Member States, and Advocate General Ćapeta's Opinion of 19 March 2026 in ECJ Case C-354/24, “Elisa Eesti AS v TTJA”. Individually, each is significant. Read together, they expose some tensions that will define EU supply-chain cybersecurity law for the coming years. This article maps how the three tracks interact, and identifies some of the legal questions most likely to determine whether the emerging framework survives judicial scrutiny.
1. Background
In January 2026 the European Commission published its proposal for a revised Cybersecurity Act (CSA2), introducing binding EU-level supply-chain security measures. These include the designation of third countries as posing cybersecurity concerns, the classification of “high-risk suppliers”, and mandatory phase-out obligations for critical networks.
At almost the same time, Advocate General Ćapeta delivered her Opinion in Case C-354/24, examining the proportionality of country-based supplier restrictions under EU law, in the specific context of Estonia's ex ante authorisation regime for network equipment.
Meanwhile, NIS2 (Directive (EU) 2022/2555) has now been transposed in most Member States, though implementation remains uneven. It requires national cybersecurity strategies and risk-management obligations covering supply-chain security for ICT products and services, while leaving many concrete choices to national authorities and regulated entities.
A brief context is necessary to help situate the CSA2. The original NIS Directive established a horizontal EU network security framework. The EU 5G Toolbox then introduced a coordinated but voluntary methodology for assessing and restricting high-risk suppliers. More recently, the NIS Cooperation Group adopted the EU ICT Supply Chain Security Toolbox, focused on identifying and mitigating supply-chain risk, including dependence on high-risk suppliers. Other adjacent instruments exist but are set aside here to keep the analysis focused.
2. CSA2 in the context of EU law
CSA2 is intended to replace the current Cybersecurity Act. Its most consequential innovation is Title IV, which establishes a trusted ICT supply-chain framework applicable across all NIS2 sectors. The target is explicitly non-technical: the likelihood that a supplier may be subject to third-country influence capable of disrupting services, compromising products, or enabling data exfiltration.
The mechanism operates in layers:
- The NIS Cooperation Group or the Commission may conduct Union-level coordinated security risk assessments.
- The Commission may then designate a third country as posing cybersecurity concerns, based on criteria such as vulnerability-reporting obligations, the absence of effective judicial remedies, and cyber campaigns linked to that country.
- Entities established in, or controlled from, a designated country may consequently become “high-risk suppliers”.
- The Commission may impose restrictions – procurement exclusions, certification consequences, data-transfer restrictions, mandated supplier diversification, and phase-out obligations.
This cascading architecture is coherent in design but potentially fragile in law. If supplier classification follows automatically from country designation without affected suppliers having an effective opportunity to be heard, or to challenge the factual basis of the restriction before a court – the structure could sit uneasily with Articles 41 and 47 of the the Charter of Fundamental Rights of the European Union (Charter).
The regime is even stricter for electronic communications networks, building on the (voluntary) EU 5G Toolbox. Annex II of CSA2 lists the key ICT assets covered for mobile, fixed and satellite networks. For mobile networks, the phase-out period for components from high-risk suppliers may not exceed 36 months from publication of the relevant high-risk supplier list. Covered 5G assets include core network functions, network function virtualisation and orchestration, and the radio access network.
So, another foundational question could concern the legal basis. CSA2 relies on Article 114 TFEU – the internal market competence. The Commission's justification is that divergent national approaches fragment the internal market and produce uneven resilience. Yet, to the extent that country designations and supplier exclusions function as instruments of foreign and security policy rather than market harmonisation, a conflict may arise with Article 4(2) TEU, which reserves national security as a Member State competence – reinforced by the established principle that Article 114 TFEU cannot be used where the centre of gravity of a measure lies outside market harmonisation (e.g. ECJ Case C-376/98, “Germany v Parliament and Council” (“Tobacco Advertising”).
3. The NIS2 link: from national strategies to Union-level restriction powers
CSA2 is built directly onto the NIS2 ecosystem, covering all entities within the sectors listed in NIS2 Annexes I and II, and using the NIS Cooperation Group as the procedural entry point for coordinated risk assessments. NIS2 already requires risk-management measures covering supply-chain security, vulnerability handling, and assessment of supplier-related risk, and mandates that national cybersecurity strategies address supply-chain security for ICT products and services.
Where NIS2 leaves concrete risk management largely to Member States and regulated entities, CSA2 would impose a binding Union-level mechanism. The NIS Cooperation Group may be tasked with completing coordinated security risk assessments within six months, identifying key ICT assets, threat actors, vulnerabilities and mitigating measures. In effect, the NIS2 coordination architecture becomes the procedural gateway to restrictions affecting ultimately procurement, certification, data transfers, outsourcing, personnel vetting, and the use of components in key ICT assets.
National NIS 2 implementation will also interact directly with CSA2. Member States may adopt or maintain stricter measures where justified, but now within a more centralised EU framework. For example, Bulgaria’s amended Cybersecurity Act (Art. 27, as amended, SG No. 17/2026) illustrates this as it empowers the Bulgarian Cybersecurity Council to propose restrictions on specific technologies or critical ICT supply chains, but expressly conditions this power on compliance with mandatory EU law and consistency with coordinated EU-level risk assessments – imposing a three-year phase-out period, shortened where a heightened national security risk is identified.
4. Why “Elisa Eesti” (Case C-354/24) matters
Against this backdrop, Case C-354/24 takes on outsized importance. The dispute arose after Elisa Eesti, a leading Estonian telecommunications provider, challenged decisions of the Estonian authorities restricting its use of equipment in its mobile radio network – a direct, concrete instance of the kind of supply-chain restriction CSA2 seeks to generalise across the Union. The referring court asked whether such national rules fall within the scope of the European Electronic Communications Code, whether invoking national security excludes EU law review altogether, and whether restrictions on already-installed equipment engage property rights.
Advocate General Ćapeta's Opinion addresses each of these questions with direct relevance to CSA2's future architecture. Notably, it holds that where a Member State regulates a harmonised field such as electronic communications, the measure remains subject to EU law and proportionality review – even where national security is invoked.
Critically, the Opinion states that a restriction cannot rest on general suspicion. Authorities must assess whether the specific hardware or software, in its intended use and network location, presents a genuine, present and sufficiently serious risk. That assessment may legitimately take into account the manufacturer, its country of establishment, and how country-related risk translates to the supplier and the specific equipment in question – but the link must be reasoned, reviewable and concrete, and the restriction must be shown to pursue the prevention of an actual risk to network security.
The Court's eventual judgment will therefore shape the criteria and process that CSA2 – and its implementing acts – will need to satisfy.
5. What the future holds
This overview shows that the framework is still developing and that several important questions remain open. Whether CSA2 can withstand legal scrutiny will depend on how the final text deals with the following issues:
(a) Legal basis and competence
CSA2 relies on Article 114 TFEU, but implementing acts that designate countries and exclude suppliers on grounds closer to foreign and security policy than to removing trade obstacles invite the question whether Article 114 can sustain such measures. A related tension might also exist with Article 4(2) TEU: if Union acts effectively predetermine the national security assessment by designating countries and prescribing restrictions, the boundary with reserved Member State competence is tested.
(b) Reasoning, individual assessment and equal treatment
Article 296 TFEU requires legal acts to state their reasoning, and the “Elisa Eesti” Opinion demands a link to a genuine, present and sufficiently serious risk tied to specific equipment and its intended use. Classifying suppliers as high-risk solely by reference to country designation – without a reasoned assessment of their individual circumstances – invites challenge on adequacy of reasoning. Equally, where two suppliers with comparable technical and security profiles are treated differently purely because one is established in a designated country, the objective justification required by the principle of equal treatment comes under strain.
(c) Fundamental rights and proportionality
Supplier exclusions and mandatory phase-outs engage the freedom to conduct a business (Art. 16 of the Charter) and the right to property (Art. 17 of the Charter), both for suppliers and for operators forced to replace installed equipment; any restriction must also satisfy the general limitation clause in Article 52(1) of the Charter. Under the proportionality standard set out in the “Elisa Eesti” Opinion, a restriction must be suitable, necessary and proportionate – and a blanket exclusion applied without regard to the specific component, network function, or available mitigations is likely to face scrutiny.
(d) Procedural safeguards.
Articles 41 and 47 of the Charter require that affected suppliers have a meaningful opportunity to be heard before a high-risk designation takes effect, and effective judicial review of its supplier-specific consequences.
These issues are interdependent. A framework addressing non-technical supply-chain risk at Union level may well serve a legitimate objective – but its legal durability will depend on whether the implementing acts build in individualised assessment, adequate reasoning and effective review, or instead rely primarily on country-level designation with automatic, supplier-blind consequences.
II. Conclusion
Case C-354/24 remains pending before the Court of Justice, and the CSA2 legislative process is likewise still open. If the Court adopts Advocate General Ćapeta's view, that standard is likely to influence both CSA2's implementing acts and even national measures such as Bulgaria's Article 27 mechanism. In any case, the European Parliament and the Council can still reshape the designation criteria, the role of individual assessment, and the procedural safeguards.
The interaction between the Court’s eventual ruling and the final legislative text will determine whether the EU’s supply-chain security framework rests on a legally sustainable foundation. By any measure, this is an interesting period for EU cybersecurity law, for suppliers navigating it and for national authorities tasked with applying
Legal references:
- Proposal for a Regulation on ENISA, the European cybersecurity certification framework and ICT supply chain security (CSA2), COM(2026) 11 final: https://secure.ipex.eu/IPEXL-WEB/document/COM-2026-11.
- Directive (EU) 2022/2555 (NIS2).
- NIS Cooperation Group, EU 5G Cybersecurity Toolbox and related coordinated risk assessments.
- Opinion of Advocate General Ćapeta in Case C-354/24, “Elisa Eesti AS v TTJA”, delivered 19 March 2026.
- Case C-376/98, “Germany v European Parliament and Council of the European Union” (“Tobacco Advertising”).
- Articles 4(2) and 5 TEU; Articles 114 and 296 TFEU; Articles 16, 17, 41, 47 and 52(1) of the Charter of Fundamental Rights of the European Union.
- Bulgarian Cybersecurity Act (Закон за киберсигурност), Art. 27, as amended, State Gazette No. 17/2026.







