EU Cybersecurity Act 2.0 Sparks WTO Concerns and Potential China Countermeasures
July 30, 2026
Sectors most affected by the policy could include telecommunications equipment, solar inverters, battery storage systems, and connected vehicles due to foreign supplier market shares.
The European Commission's January 2026 proposal to revise the EU Cybersecurity Act 2.0 would establish a framework to evaluate and possibly designate third countries as cybersecurity risks based on their laws, oversight, cyber activity, and cooperation with EU authorities, enabling restrictions on suppliers tied to those countries.
Under the proposal, suppliers established in or linked to high-risk countries could be barred from providing components for key ICT assets across 18 sectors covered by the NIS2 Directive, including energy, transport, health, finance, and digital infrastructure.
The EU argues in its impact assessment that the measures align with WTO commitments and justify any trade-restrictive effects by safeguarding critical ICT supply chains, while critics question necessity, proportionality, and non-arbitrariness.
One former WTO Appellate Body member warns that origin-based restrictions could raise non-discrimination and market-access concerns under WTO rules, making compliance and justification less straightforward.
China’s Ministry of Commerce has challenged the proposal’s WTO compatibility and warned of potential countermeasures against EU firms, though no formal WTO dispute has been filed yet.
Additional measures could require removal of existing components from high-risk suppliers within 36 months and limit those suppliers’ access to EU cybersecurity certification, public procurement, funding programs, and standardisation activities.
The proposal is under negotiation in the Council and the European Parliament, where lawmakers may tighten or adjust supplier assessment and exclusion mechanisms before final adoption.
Summary based on 1 source
Get a daily email with more EU News stories
Source

Digital Watch Observatory • Jul 30, 2026
Legal analysis flags WTO risks in EU Cybersecurity Act 2.0 revision | Digital Watch Observatory