deploy new and more secure forms of encryption, and to devise new ways of protecting
critical communication and data assets, can help keep sensitive information and, in turn,
critical infrastructures safe.
In this perspective, and going further, the Commission will explore the possible deployment
of a multi-orbital secure connectivity system. Building on GOVSATCOM and QCI, it would
integrate cutting edge technologies (Quantum, 5G, AI, edge computing) adhering to the most
restrictive cybersecurity framework in order to support secure-by-design services such as
reliable, secure and cost-effective connectivity and encrypted communication for critical
governmental activities.
1.4 Securing the next generation of broadband mobile networks
EU citizens and companies using advanced and innovative applications enabled by 5G and
future generations of networks should benefit from the highest security standard. Member
States, together with the Commission and with the support of ENISA, have established with
the EU 5G Toolbox48 of January 2020 a comprehensive and objective risk-based approach to
5G cybersecurity that is based on an assessment of possible mitigation plans and
identification of the most effective measures. Moreover, the EU is consolidating its
capabilities in 5G and beyond to avoid dependencies and to foster a sustainable and diverse
supply chain.
In December 2020, the Commission published a report on the impacts of the
Recommendation of 26 March 2019 on the Cybersecurity of 5G networks49. It showed that
considerable progress has been made since the Toolbox was agreed, and that most Member
States are on track to complete a significant part of the Toolbox implementation in the near
future, albeit with some variations and remaining gaps as already identified in the Progress
report published in July 202050.
In October 2020, the European Council called on the EU and the Member States ‘to make full
use of the 5G cybersecurity toolbox’ and ‘to apply the relevant restrictions on high-risk
suppliers for key assets defined as critical and sensitive in the EU coordinated risk
assessments, based on common objective criteria’51.
Looking forward, the EU and its Member States should ensure that the identified risks have
been mitigated adequately and in a coordinated way, in particular as regards the objective of
minimising the exposure to high risk suppliers and of avoiding dependency on these suppliers
at national and Union level, and that any new significant development, or risk, is taken into
account. Member States are invited to make full use of the Toolbox in their investments in
digital capacities and connectivity.
Based on the report of the impacts of the 2019 Recommendation, the Commission encourages
Member States to accelerate the work towards completing the implementation of the main
and their certification and validation before their integration in the QCI. It will be designed to support additional
applications as they reach the necessary technological maturity level. The current OpenQKD pilot
(https://openqkd.eu/) is a precursor to this testing and compliance infrastructure.
48
Communication on Secure 5G deployment in the EU - Implementing the EU Toolbox, COM(2020) 50.
49
Commission Report on the impacts of the Commission Recommendation of 26 March 2019 on the
Cybersecurity of 5G networks, 15 December 2020.
50
Report by the NIS Cooperation Group on the implementation of the Toolbox, of 24 July 2020.
51
EUCO 13/20, Special meeting of the European Council (1 and 2 October 2020) – Conclusions.
8