Guest Post: Preliminary Thoughts on the European Commission Proposal for the Cybersecurity Act 2.0

This is a guest post by Peter Van den Bossche [1] Chair Professor of International Economic Law, Xi’an Jiaotong University School of Law; former Member and Chair of the WTO Appellate Body; Professor Emeritus of International Economic Law, World Trade Institute, University of Bern; and external legal advisor, King & Wood.

Executive Summary

This paper offers general observations on the key mechanisms and WTO consistency of the Proposal for the EU Cybersecurity Act 2 (‘CSA2.0’). The proposed CSA2.0 lays down the ICT supply chain security mechanism and the European cybersecurity certification mechanism, under which the European Commission may designate certain third countries as posing cybersecurity concerns, by taking account of the cyber-related legal systems and practices of such countries. Providers of ICT products and services that are established in, or have certain affiliation with, the designated third countries constitute ‘high-risk suppliers’. Most notably, the proposed CSA2.0 prohibits ‘high-risk suppliers’ from providing ICT products and services for ‘key ICT assets’ used by EU entities in 18 critical sectors and denies their access to cybersecurity certification and other market opportunities in the EU. If adopted, the proposed CSA2.0 will have significant economic impact on sectors where foreign exporters play a major role on the markets, including those related to telecommunications, solar inverters, battery energy storage, and connected and automated vehicles. 

While the potential impact on trade is profound, it is surprising and disappointing that the EU seems to have largely ignored the WTO consistency issues inherent in the proposed CSA2.0, as they have never properly and sufficiently addressed these issues in the proposal and other accompanying documents during the legislative process. China’s Ministry of Commerce, however, has questioned the WTO consistency of this legislative proposal in its comments submitted to the European Commission, pointing to violations of various obligations under the WTO agreements. If adopted, the CSA2.0 may trigger a major WTO dispute due to the systemic concerns shared by many affected countries. Against this background, this paper provides preliminary thoughts on the WTO consistency of the CSA2.0, with a particular focus on the non-discrimination obligations under the GATT 1994, the GATS, and the TBT Agreement.

The non-discrimination obligations under the GATT 1994 and the GATS are clearly applicable to the measures targeting products and services of the ‘high-risk suppliers’, as defined by the proposed CSA2.0, while the applicability of the TBT Agreement is less straightforward and requires further demonstration by the potential complainant. One of the key issues concerning those measures’ consistency with the said obligations is the ‘likeness’ test under the WTO agreements, which can be shown through the comparison of relevant factors or presumed if the measure is origin-based. Either way, a complainant is likely to be able to show that the products are ‘like’.

On the basis that the affected products are ‘like’, this paper further observes that under Article I of the GATT 1994, the blanket prohibitions established by the CSA2.0 fail to accord to ICT products of high-risk suppliers from a Member, immediately and unconditionally, the advantages accorded to those of other suppliers from other countries. Under Article III:4 of the GATT 1994, it is also not difficult for a complaint to show that the imported ICT products of high-risk suppliers are treated less favourable than the ‘like’ domestic ICT products of other suppliers, as the former’s products are outright excluded from the EU market. The same is true for claims under Articles II and XVII of the GATS. On the other hand, however, to establish violations of the non-discrimination obligations under Articles 2.1 and 5.2 of the TBT Agreement may be trickier, given the doctrine of legitimate regulatory distinction underlying these clauses.

When a complainant successfully establishes violations of the non-discrimination obligations under the GATT 1994 and the GATS, the EU will likely argue that the CSA2.0 is justified under the applicable exceptions of these WTO agreements. For the general exceptions, even assuming that any of the grounds for justification are relevant, which does not appear to be the case, it would be challenging for the EU to establish that such exclusionary measures introduced by the CSA2.0 are ‘necessary’ for protecting the stated objective of cybersecurity and/or the application of these measures does not constitute arbitrary discrimination or unjustifiable discrimination. For the security exceptions, it is clear from the treaty text as consistently interpreted in prior WTO disputes that political or economic differences between Members themselves are not sufficient to constitute an ‘emergency in international relations’. 

The EU's trading partners—most notably China—have warned that if the CSA2.0 is adopted in its current form, they will enact corresponding countermeasures against EU businesses. Moreover, if adopted, it is likely that China will initiate WTO dispute settlement proceedings against the EU and its Member States, which implement the CSA2.0. China could bring a WTO complaint against, in particular, Germany and France, which both have substantial trade volumes with China and played a decisive role in the CSA 2.0 proposal's adoption. Note that China and the EU are parties to the Multi-Party Interim Appeal Arbitration Arrangement (MPIA), and that, therefore, any WTO dispute between them will be brought to a legally binding resolution.

Introduction

To maintain momentum in the ongoing WTO Reform negotiations, the European Union circulated on 13 July 2026 three new discussion papers on subsidies and industrial policy (WT/GC/REFORM/W/5), foundational issues (WT/GC/REFORM/W/6), and the governance and decision-making (WT/GC/REFORM/W/7). Each of these papers makes a valuable and inspired contribution to the discussion on how to adapt the multilateral trading system and its principal institution, the WTO, to the geopolitical and geoeconomic realities of the 2020s. They reflect the European Union’s longstanding view that international trade must be rules-based. Recently, however, the European Union has adopted, or is considering, several trade-related measures of which the consistency with WTO law is, at the very least, debatable. Be that as it may, in the internal policy discussions on these measures (adopted or under consideration), the question of their WTO consistency is remarkably muted or virtually absent. This is odd for a WTO Member which professes to be a strong supporter of rules-based international trade. The current rules may be in urgent need of change, but they are still the ones that apply and should be abided by until new rules are in place. A telling example of this absence of consideration of WTO consistency in the internal policy discussions is the European Commission’s Proposal for the EU Cybersecurity Act 2 (‘CSA2.0’)[2]. As the European Commission points out in the Explanatory Memorandum of its Proposal, in recent years ‘cyberattacks have surged and became more sophisticated, targeting critical infrastructure, businesses, and the general public’.[3] It is clear that the threat to cybersecurity has significantly worsened, and that the current EU cybersecurity legislation and policy instruments, primarily including the EU Cybersecurity Act of 2019 (‘CSA1.0’)[4], the Directive (EU) 2022/2555 of 14 December 2022 (‘NIS 2 Directive’)[5] , and the 5G Cybersecurity Toolbox, fall short of addressing this heightened threat. The transposition of the NIS 2 Directive into the domestic law of EU Member States was slow and is uneven among Member States. On 8 July 2026, the European Commission announced its decision to refer Ireland, Spain, France and the Netherlands to the European Court of Justice for failing to notify measures transposing the NIS 2 Directive into national law.[6] The 5G Cybersecurity Toolbox is a non-binding policy document, merely requesting Member States to assess the national risk profiles of their 5G network suppliers on inter alia the likelihood of interference by non-EU governments, and to restrict or exclude ‘high-risk suppliers’ from participating in critical and sensitive assets. Member States have taken divergent attitudes and approaches to implementing the non-binding 5G Cybersecurity Toolbox. To achieve the EU’s stated objective of effectively protecting Europe from cyber threats, mandatory cybersecurity instruments are considered necessary. This is where the proposed CSA2.0 comes in.

Key Features of the Proposed CSA2.0

The CSA2.0, as proposed, establishes two principal mechanisms that are of particular importance to international trade in ICT products and services, namely the ICT supply chain security mechanism, and the European cybersecurity certification mechanism.

As to the first of these mechanisms, the proposed CSA2.0 establishes a ‘trusted ICT supply chain framework’ designed to address non-technical risks, i.e., risks not related to hard- or software vulnerabilities of ICT, products or service, but to geopolitical, legal, and systemic dependencies in ICT supply chains on third countries. Central to this ‘trusted ICT supply chain framework’ are five related concepts, namely ‘critical sectors’, ‘essential and important entities’, ‘key ICT assets’, ‘countries posing cybersecurity concerns’, and ‘high-risk suppliers’. Of these concepts, the first three reveal the very wide scope of application of the proposed CSA2.0. Eighteen economic sectors are defined as ‘critical sectors‘, including inter alia energy, transport, health, finance, water, digital infrastructure & ICT services, public administration and manufacturing. ‘Essential and important entities’ are all large and medium-sized companies operating in any of the 18 ‘critical sectors’. ‘Key ICT assets’ are ICT products manufactured or services provided by ‘essential and important entities’. The fourth concept, i.e., ‘countries posing cybersecurity concerns’, refers to third countries that, according to the European Commission, pose a non-technical risk to ICT supply chains, as indicated by security risk assessments or other public sources. In identifying ‘countries posing cybersecurity concerns’, the Commission shall consider four elements: (1) whether any laws or practices from that third country require entities under its jurisdiction to report software or hardware vulnerabilities to authorities before such vulnerabilities are known to have been exploited; (2) the absence of effective judicial remedies and independent democratic oversight mechanisms capable of correcting such security concerns; (3) substantiated information about malicious cyber activities or campaigns carried out by threat actors operating from the territory of that country; and (4) the lack of ability or willingness of the third country to cooperate with the European Commission or Member States to address such risks. Finally, the fifth concept, i.e., ‘high-risk suppliers’, is defined in the proposed CSA2.0 as referring to: (1) an entity established in a third country designated as posing cybersecurity concerns; (2) an entity controlled by such a third country; (3) an entity controlled by an entity established in such a third country; and (4) an entity controlled by a national of such a third country.[7] In short, the European Commission designates manufacturers of ICT products or providers of  ICT services as ‘high-risk suppliers’ based on their place of establishment, ownership and control structure. In addition, albeit under exceptional circumstances only, the European Commission can directly designate an entity as a ‘high-risk supplier’ without that entity having any affiliation with a country designated as posing cybersecurity concerns.[8]

Under the CSA2.0, as proposed, the European Commission may adopt three kinds of exclusionary measures adversely affecting ICT products and services of ‘high-risk suppliers’. First, the Commission may prohibit European providers of electronic communication networks from using, installing, or integrating in ICT components from ‘high-risk suppliers’ in operation of ‘key ICT assets’, and require that components of ‘high-risk suppliers’ already installed shall be phased out within no more than 36 months.[9] Second, the Commission may prohibit ‘essential and important entities’ operating in the 18 ‘critical sectors’ from using, installing, or integrating ICT components from ‘high-risk suppliers’ in operation of ‘key ICT assets’.[10]  Third, the Commission may exclude ICT components supplied by a specific entity from being used, installed or integrated by ‘essential and important entities’, without engaging in separate identification of ‘key ICT assets’ or designation of ‘countries posing cybersecurity concerns’.[11] In short, the CSA2.0, as proposed, empowers the Commission to prohibit European ‘essential and important entities’ from using, installing, or integrating ICT components from ‘high-risk suppliers’ in operation of ‘key ICT assets’. Furthermore, ‘high-risk suppliers’ are also precluded from participating in: (1) European standardisation activities in the area of cybersecurity; (2) public procurement procedures in relation to provision of ICT components used in ‘key ICT assets’; and (3) the EU funding programs related to provision of ICT components used in ‘key ICT assets’.[12]  Overall, the CSA2.0, as proposed is designed to preclude from the EU market ‘high-risk suppliers’ and their ICT products and services which the EU considers to exhibit ‘non-technical risks’ associated with particular third countries.

Apart from the ‘ICT supply chain security mechanism’, the proposed CSA2.0 also establishes a second mechanism, which is of particular importance to international trade in ICT products and services, namely the ‘European cybersecurity certification mechanism’. This mechanism aims to create a unified certification regime across the EU and strengthens the European Cybersecurity Certification Framework (‘ECCF’), which was established under the CSA1.0. The ECCF provides for a mechanism to evaluate and attest that ICT products, services and processes meet the applicable cybersecurity requirements. Certification under the ECCF is generally voluntary, unless otherwise specified in EU or national law.[13]  EU Members States and the European Commission may make certification mandatory for certain types of ‘essential and important entities’.[14]  Also, under the EU Cyber Resilience Act of 2024, EU cybersecurity certification is mandatory certification for critical products with digital elements, listed in Annex IV of this Act.[15] A manufacturer of ICT products or provider of ICT services may either apply for and obtain a conformity certificate or issue a statement of conformity, both of which have the effect of presumed conformity with the relevant technical requirements, and should be recognised across all EU Member States. Besides general rules fleshing out the European cybersecurity certification regime, the CSA2.0 introduces three targeted restrictions on ‘high-risk suppliers’ regarding cybersecurity certification. First, ‘high‑risk suppliers’ are not entitled to apply for or be a holder of any European cybersecurity certificates.[16] Second, ‘high-risk suppliers’ are not entitled to become accredited conformity assessment bodies or authorised attestation providers.[17] Third, holders of a European cybersecurity certificate are prohibited from using, installing, or otherwise integrating ICT components from ‘high‑risk suppliers’ in their certified ICT products and services that are identified as ‘key ICT assets’.[18] In short, the CSA2.0, as proposed, excludes ICT products and services of ‘high-risk suppliers’ from the EU market by denying them certification or a statement of compliance.

Markets and Market Players Potentially Affected by the Proposed CSA2.0

As noted above, the scope, of the proposed CSA2.0 is very broad as it affects the 18 critical sectors identified by the NIS 2 Directive. Its potential impact on non-EU manufacturers of ICT products and suppliers of ICT services is therefore significant. First and foremost, the CSA2.0, as proposed, affects the digital communication and telecommunication market which was valued at EUR 1 trillion in 2023, and represents around 4.7% of the European GDP.[19]  Key players in the telecommunication market include Nokia from Finland, Ericsson from Sweden, Huawei and ZTE from China, as well as Cisco from the US. Note in this regard, that eight European countries source more than 50% of their 5G RAN equipment from Chinese suppliers. In particular, in Germany, 59% of 5G RAN equipment in 2022 was supplied by Chinese suppliers.[20]

The CSA2.0 would also affect the solar photovoltaic and battery energy storage market as its broad definition of ICT products also includes solar inverters, which are critical components of a photovoltaic system. In 2023, 70% of solar inverters installed in Europe were supplied by Chinese suppliers.[21] Between 2015 and 2023, Europe imported a total of 350 GW of solar inverters, of which 64% (225 GW) were supplied by Chinese companies, and 32.5% (114 GW) were supplied by Huawei.[22] Chinese enterprises have also expanded rapidly in the EU battery energy storage market, with companies such as Sungrow, CATL, BYD, and Huawei continuously securing major orders in Europe or planning to establish local manufacturing facilities. It is reported that Chinese manufacturers account for more than 80% of residential battery storage installations in Europe.[23]  In addition, China remains the main source of batteries import to the EU in 2025, and strengthened its position covering 85.5% of the EU external import needs in 2022-2024 (up from 81.9% in 2021-23).[24]

Also, the connected and automated vehicle (CAV) market would be affected by the CSA2.0 as the automobile industry, which accounts for 8% of European manufacturing value added and represents 6.1% of total EU employment[25], falls under one of the ‘critical sectors’, namely manufacturing. In recent years, China, Turkey and the UK are the biggest vehicle exporters to the EU. Especially, China’s exports to the EU have shown a remarkable growth, rising from the 8th largest exporter of vehicles in 2020, to the highest volume exporter to the EU in 2024, with EUR 781 billion worth of motor cars and vehicles, and EUR 784 billion worth of motor vehicle parts exported.[26]

In short, the potential adverse impact of the proposed CSA2.0 is significant and this is especially so for Chinese manufacturers of ICT products and providers of ICT services, as they are important players on the affected markets.

Questions Regarding the WTO Consistency of the Proposed CSA2.0

The proposed CSA2.0 and particularly its principal mechanisms discussed above raise important questions regarding its WTO consistency. These questions concern the consistency with the non-discrimination and market access obligations of the GATT 1994, the GATS and the TBT Agreement. Considering that the European Union professes to be a champion of rules-based trade, it is surprising and frankly disappointing, but perhaps a sign of the times, that the European Commission in its CSA2.0 proposal and accompanying documents pays scant, if any, attention to the WTO consistency of the CSA2.0. There is not even a reference to the WTO or WTO law in the text of the draft CSA2.0 or the CSA2.0 Explanatory Memorandum.[27] The CSA2.0 Impact Assessment refers twice to the EU’s obligations under WTO law. On p. 93, the European Commission states:

‘As for the impact on international competitiveness and trade, the considered options are compatible with the EU’s legal commitments under the World Trade Organisation (WTO) Agreements as well as bilateral, multilateral and plurilateral agreements. The options D.1–D.3 provide for a necessary and proportionate intervention to ensure cybersecurity of critical ICT supply chains. Whilst measures taken under these options could have a trade restrictive effect for certain goods and services, these measures would be justifiable in view of the overall legitimate objective to ensure the security of critical ICT supply chains in the EU.’ [28]

This is but a bold assertion of WTO consistency, without any analysis or supporting reasoning.  The second reference to WTO obligations is to Article 2.9 of the TBT Agreement. The European Commission notes on p. 343 of the CSA2.0 Impact Assessment that:

‘Under the TBT Agreement, WTO Members have the obligation to notify, through the WTO Secretariat, draft measures that may have a significant effect on trade of other Members and are not based on relevant international standards. In such a case, the Commission shall also submit a WTO TBT notification.’ [29]

Note that on 20 July 2026, six months after the European Commission published its CSA2.0 proposal, the EU had still not notified the WTO Secretariat of this draft measure.

Contrary to the Commission’s bold assertion of WTO consistency, China’s Ministry of Commerce (MOFCOM) has, unsurprising, cast serious doubt on the WTO consistency of the CSA2.0. In its comments on the CSA2.0, submitted to the European Commission on 17 April 2025, MOFCOM noted:

A victim of protectionism and unilateral bullying itself, the EU has been calling for upholding the rules-based multilateral trading system and opposing unilateral bullying and coercion. Nonetheless, the Proposal goes the opposite way.[30] 

MOFCOM argues that the CSA2.0 violates: the MFN and national treatment obligations of Articles I and III of the GATT 1994 and Articles II and XVII of the GATS; the prohibition of quantitative restrictions of Article XI of the GATT; the obligation of Article VI of the GATS that all measures affecting trade in services must be administered in a reasonable, objective and impartial manner; Article 3 of the SCM Agreement, which prohibits subsidies contingent upon the use of domestic over imported products; Articles 2.1 and 5.1 of the TBT Agreement, which impose MFN and national treatment obligations  on technical regulations and conformity assessment procedures; Articles 2.2 and 5.2 of the TBT Agreement, which require that technical regulations and conformity assessment procedures are not more trade-restrictive than necessary to fulfil a legitimate objective; Article 2.9 of the TBT Agreement on the notification of draft technical regulations; and finally, Article 39 of the TRIPS Agreement relating to the protection of undisclosed information.[31] MOFCOM further argues that none of the above alleged inconsistencies can be justified under general or national security exceptions of Article XX or XXI of the GATT 1994 or Articles XIV and XIV bis of the GATS. MOFCOM seems to throw everything but the kitchen sink at the proposed CSA2.0. Its list of alleged WTO violations is long but could be even longer. One might inter alia also argue that the proposed CSA2.0 is inconsistent with Article X:3(a) of the GATT 1994, which requires measures affecting trade in goods to be administered in a reasonable, objective and impartial manner; Article XVI of the GATS , which prohibits market access barriers in sectors for which the European Union has made market access commitments; Article 2.4 of the TBT Agreement, which requires that technical regulations are based on international standards; and Article 2.5 of the TBT Agreement, which requires that national certification bodies use relevant guides or recommendations regarding conformity assessment procedures issued by international standardizing bodies. MOFCOM may have good reasons for not including the ‘missing’ claims of inconsistency, but these reasons are not clear. If CSA2.2 is adopted as it is currently proposed, China is likely to challenge its WTO consistency and bring a formal complaint against the European Union or against the European Union and its Member States. As far as the EU Member States are concerned, the complaint would focus on the measures implementing the CSA2.0. China may, however, not be the only WTO Member bringing a formal complaint. This is because of the way in which the CSA2.0 would limit trade and the justification for such limitation invoked by the European Union. The WTO consistency of the CSA2.0 raises important systemic issues. Any future EU – CSA2.0 dispute would certainly have a record number of third parties. Also note that since both the European Union and China are both MPIA parties, this dispute could not end up in legal limbo due to an appeal to the paralysed Appellate Body, but will result in a legally binding resolution of the dispute.

It is not my ambition with this paper to dive into a detailed analysis of all of possible claims of WTO inconsistency of the proposed CSA2.0. I will limit myself to a few preliminary observations on the possible inconsistency with the non-discrimination obligations under the GATT 1994, the GATS and the TBT Agreement and on whether such violations could be justified. If the CSA2.0 were found inconsistent with the non-discrimination obligations and such inconsistency were be justifiable, the European Union would have to redesign the core elements of this measure and any finding of inconsistency with other WTO provisions of secondary importance.

For claims of inconsistency with the non-discrimination obligations to be successful, a complainant would first have to show the applicability of the relevant obligations. The applicability of Articles I or III of the GATT 1994 is clear. As it currently stands, the CSA2.0 is a ‘law … affecting the sale … of products’ to which Article III:4 of the GATT 1994 applies, and Article I of the GATT 1994 applies to ‘all matters referred to in paragraphs 2 and 4 of Article III’. Also Articles II and XVII of the GATS would apply to the CSA2.0 as the latter is a ‘measure by a Member affecting trade in services’ within the meaning of Art. I of the GATS; none of the EU’s exemptions from the MFN treatment under Article II:2 is relevant; and, as reflected in its Services Schedule, the European Union has made national treatment commitments in the services sectors and regarding the modes of supply covered by the CSA2.0. The applicability of the non-discrimination obligations under Articles 2.1 and 5.2 of the TBT Agreement may be less obvious. For example, for Article 2.1 of the TBT Agreement to apply, the measure at issue must be a technical regulation. Pursuant to Annex 1.1 of the TBT Agreement, a technical regulation is ‘a document which lays down product characteristics or their related processes and production methods.’ Does the CSA2.0 lay down the product characteristics or their related PPMs of the ICT products affected by it? To date, no WTO adjudicator has addressed the question whether a measure of this kind constitute a technical regulation within the meaning of Annex 1.1. This question is still to be decided.

Having shown that some or all the relevant non-discrimination provisions apply, the complainant would subsequently have to show that the products or services at issue, i.e., the ICT products or services of ‘high-risk suppliers’ and ICT products or services of other suppliers, are ‘like’ products or services. According to well-established case law, products and services may be presumed to be ‘like’ when the measure at issue distinguishes between products or services solely on the basis of their origin. The CSA2.0, as proposed, distinguishes between the ICT products and services on the basis of the origin of the product or service, namely on the basis of whether the product is manufactured or the service provided by a supplier with a link to a country posing cybersecurity concerns. A complainant can thus argue that the ‘likeness’ of the ICT products and services may be presumed. Alternatively, a complainant may, of course, address the ‘likeness’ issue in full. The determination of the ‘likeness’ of products or services is, according to firmly established case law, a determination of the nature and extent of the competitive relationship between the products or services at issue. This determination is made based on factors such as – when products are concerned – physical characteristics, end use, consumer tastes and preferences and customs classification, and – when services are concerned – the characteristics of the services and service suppliers and consumer preferences regarding these services and service suppliers. None of these factors is considered determinative in and of themselves and other factors may also be of relevance. I will limit my comments to the ‘likeness’ of the products at issue, but I note that similar considerations may be relevant for the ‘likeness’ of the services at issue. It is clear is that both the end use and the customs classification of ICT products supplied by ‘high-risk suppliers’ and those supplied by other suppliers are the same. The physical characteristics would also be the same, as ‘physical’ should be understood as referring to properties pertaining to the product itself. As to consumer tastes and preferences, note that the consumer of the ICT products at issue would, generally speaking, not be ordinary citizens but entities with advanced technical knowledge of the products purchased. The tastes and preferences of these entities are likely to be determined on objectively established technical differences between the ICT products at issue, rather than non-technical differences. Taking all these factors into consideration, a complainant is likely to be able to show that the competitive relation between the ICT products at issue is sufficiently strong for these products to be considered ‘like’ under Article I and III:4 of the GATT 1994 and Article 2.1 of the TBT Agreement.

Having established the likeness of the products and services at issue, a complainant must show, under Article I of the GATT 1994, that the ICT products of ‘high-risk suppliers’ from a Member are not accorded, immediately and unconditionally, the advantages accorded to ‘like’ ICT products of other suppliers from other countries. This is the case. Under Article II of the GATS, a complainant must show that services of ‘high-risk suppliers’ from a Member are accorded less favourable treatment than is accorded to ‘like’ ICT services of other suppliers from other countries. Under Articles III:4 of the GATT 1994 and XVII of the GATS, the complainant must show that the imported ICT products or services of ‘high-risk suppliers’ are treated less favourably than the ‘like’ domestic ICT products or services of other suppliers. Showing treatment less favourable within the meaning of Article III:4 of the GATT 1994 or Articles II and XVII of the GATS requires the complainant to show the CSA2.0 distorts the conditions of competition between the products and services at issue to the detriment of the imported ‘like’ ICT products or services of ‘high-risk suppliers’. Also, this is clearly the case as the latter ICT products or services are outright excluded from the EU market. Establishing whether ICT products of ‘high-risk suppliers’ are accorded less favourable treatment within the meaning of Article 2.1 of the TBT Agreement is trickier, because, in the case of de facto discrimination, even if the CSA2.0 would have a detrimental impact on the conditions of competition, it would not be considered to accord treatment less favourable if that detrimental impact stems exclusively from a legitimate regulatory distinction. The question a complainant would have to address is whether the distinction made in casu, namely whether ICT products are supplied by ‘high-risk suppliers’ or not, is a legitimate regulatory distinction. The comments made below regarding the general exceptions under Article XX of the GATT 1994 are of relevance to this question.

Assuming a complainant is successful in establishing that the CSA2.0, as proposed, is inconsistent with Articles I and/or III:4 of the GATT 1994 and/or Articles II and/or XVII of the GATS, it would be for the European Union to show that these inconsistencies can be justified under Articles XX or XXI of the GATT 1994 or Articles XIV or XIV bis of the GATS. The grounds of justification of otherwise GATT- or GATS-inconsistent measures are exhaustively set out in Articles XX of the GATT 1994 and Article XIV of the GATS respectively. Few, if any, of these grounds appear to be relevant. Moreover, for certain of these grounds, the European Union would be required to show that the CSA2.0 is ‘necessary’ to protect itself from cybersecurity risks. The CSA2.0 will only be considered ‘necessary’ if none of the possible alternative measures, identified by the complainant, is a less trade restrictive measure that is reasonably available and that would achieve the level of protection the European Union wants to achieve. Assuming the European Union can show that the CSA2.0 is ‘necessary’, the latter would be provisionally justified under Articles XX of the GATT 1994 or XIV of the GATS. However, to be justified, the application of the CSA2.0 would need to meet the requirements of the chapeau of both provisions, i.e., the application of the CSA2.0 may not constitute arbitrary discrimination or unjustifiable discrimination. In this regard, the following questions may need to be addressed: (1) whether the European Union applies the CSA2.0 in an overly rigid and inflexible manner without due regard to the actual conditions in the country of origin of the ICT product or service; (2) whether the European Union tried to address its concerns regarding cybersecurity through multilateral negotiations before having recourse to unilateral measures, such as the CSA2.0; and (3) whether in its application, the CSA2.0 reveals discrimination that cannot be reconciled with, or is not rationally related to, the policy objective, i.e. the protection of cybersecurity, pursued by the European Union. Showing that the CSA2.0 is applied in a manner that does not constitute arbitrary or unjustifiable discrimination may be tricky for the European Union.

The European Union may also try to justify the otherwise GATT or GATS inconsistent CSA2.0 by invoking the national security exceptions of Article XXI of the GATT 1994 and Article XIV bis of the GATS. Note in this regard that in recent years the European Union strongly asserted that the national security exceptions should not be overstretched or abused. Arguably of some relevance in this case is paragraph b of either of these provisions, and, in particular, subparagraph (iii) thereof. Subparagraph (iii) concerns measures taken in times of war or other emergency in international relations. The first of these circumstances, ‘war’, is thankfully not present, but can it be argued that cyber insecurity, threats and attacks constitute an emergency in international relations? The Panel in Russia – Traffic in Transit (2019) defined an emergency in international relations as ‘a situation of armed conflict, or of latent armed conflict, or of heightened tension or crisis, or of general instability engulfing or surrounding a state’. The Panel in that case further clarified that political or economic differences between Members are not sufficient, in and of themselves, to constitute an ‘emergency in international relations’, unless they affect defence and military interests, or the maintenance of law and public order interests.

The above considerations on the consistency of the CSA2.0, if adopted as currently proposed, with the non-discrimination obligations of the GATT 1994, the GATS and the TBT Agreement are just a broad and incomplete overview of the challenges that either a complainant or the European Union must overcome to show that the CSA2.0 is WTO-inconsistent or -consistent respectively. The European Commission’s proposal is currently moving through the long EU legislative process and is currently before the Council of Ministers. A progress report by the Presidency of the Council, discussed on 7 June 2026, listed the issues raised by Member States regarding the proposed CSA2.0. The WTO consistency of the CSA2.0 is not explicitly mentioned but may well have been discussed. The CSA2.0 is also being discussed in the European Parliament (‘EP’), where the proposal has been assigned to the Industry, Research and Energy Committee (and not the International Trade Committee). Marketa Gregorova from Czechia and member of the Greens/EFA Group in the EP (and also a member of the EP International Trade Committee), has been appointed as rapporteur. It will be interesting to see whether Ms. Gregorova will address the WTO consistency in her report and/or whether this issue will be raised in the discussions in committee or in plenum. In a European Parliament’s Briefing on the CSA2.0, dated 16 June 2026, it is noted: 

Non-EU trade representatives and vendors have raised concerns about the legal underpinnings of the non-technical risk framework and its application. China's Minist[ry] of Commerce stressed how the proposal introduces highly subjective and arbitrary 'non-technical risk' in the name of cybersecurity and supply chain security. It notes how such exclusion policies could disrupt market operations and conflict with WTO rules and multilateral trade norms. It suggests removing provisions related to 'third countries posing cybersecurity concerns' and 'non-technical risks', and delete or substantially revise the criteria for identifying [‘high risk suppliers’], so that supply chain cybersecurity measures remain technology-neutral, evidence-based and proportionate in scope.[32] 

As MOFCOM stated in its comments on the CSA2.0 submitted to the European Commission on 17 April 2025, China ‘stands ready to conduct in-depth and frank exchanges’ on cybersecurity, but it did also warn the European Union that if the CSA2.0 is adopted as proposed, ‘China will have to respond in kind by carrying out corresponding countermeasures against the EU and EU businesses with reference to the EU’s logic and measures. [33] The European Union would act with wisdom if they were to re-consider the proposed CSA2.0 to ensure its WTO consistency and thus uphold the rules-based multilateral trading system of which it professes to be the champion. 


[1] Chair Professor of International Economic Law, Xi’an Jiaotong University School of Law; former Member and Chair of the WTO Appellate Body; Professor Emeritus of International Economic Law, World Trade Institute, University of Bern; and external legal advisor, King & Wood.

[2] Proposal for a Regulation of the European Parliament and of the Council on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2), COM(2026) 11 final, dated 20 January 2026, https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act.

[3] Ibid., p. 1.

[4] Regulation (EU) 2019/881 of the European Parliament and of the Council, Official Journal of the European Union of 7 June 2019, L 151/15, https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32019R0881.

[5] Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022  on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555. This Directive replaced  

[6] European Commission, Press Release, 8 July 2026, https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499.

[7] Article 2(39) of CSA2.0.

[8] Article 103(6)(7) of CSA2.0.

[9] Articles 110 and 111 of CSA2.0.

[10] Article 103.1 of CSA2.0.

[11] Article 103.7 of CSA2.0

[12] Article 100.4 of CSA2.0.

[13] Article 71.3 of CSA2.0.

[14] Article 24 of the NIS2 Directive.

[15] Article 32.4 of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act).

[16] Article 100.4(b) of CSA2.0.

[17] Article 100.4(c) and (d) of CSA2.0.

[18] Article 103.1 of CSA2.0.

[19] State of Digital Communications 2025, https://connecteurope.org/insights/reports/state-digital-communications-2025

[20] The Market for 5G RAN in Europe: Share of Chinese and Non-Chinese Vendors in 31 European Countries, https://strandconsult.dk/the-market-for-5g-ran-in-europe-share-of-chinese-and-non-chinese-vendors-in-31-european-countries/

[21] Commission Staff Working Document Impact Assessment Report, SWD(2026) 11 final, https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act

[22] Ibid..

[23] Anna Darmani Tous Isabel Nieto, ‘Chinese Suppliers Solidify Control of Europe’s Home Battery Market’ (pv magazine Global, 29 October 2025), https://www.pv-magazine.com/2025/10/29/chinese-suppliers-solidify-control-of-europes-home-battery-market.

[24] Battery Technology in the European Union - 2025 Status Report on Technology Development, Trends, Value Chains and Markets, 60, https://setis.ec.europa.eu/battery-technology-european-union-2025-status-report-technology-development-trends-value-chains-and_en.

[25] EU Coordinated Risk Assessment-Connected and Automated Vehicles, 30 January 2026, https://digital-strategy.ec.europa.eu/en/policies/nis-cooperation-group

[26] CSA2.0 Proposal (n 2), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026PC0011.

[27] https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026PC0011

[28] Commission Staff Working Document Impact Assessment Report, SWD(2026) 11 final, dated 20 January 2026, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52026SC0011&qid=1782442565955

[29] Ibid.

[30] Feedback from the Ministry of Commerce of China on the EU’s Proposal for a revised Cybersecurity Act, dated 17 April 2025, at https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14578-The-EU-Cybersecurity-Act/F33393498_en.

[31] Ibid.

[32] European Parliament Briefing on EU Legislation in Progress, Cybersecurity Act Revision (CSA2), dated 16 June 2026, p. 10, https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/789345/EPRS_BRI(2026)789345_EN.pdf.

[33] MOFCOM (n 30).