best practices, in particular about: States - Restrictions on high-risk suppliers (SM03) and authorities, measures related to the provision of managed Commission services (SM04); - Supply chain security and resilience, notably following up on the survey conducted by BEREC about SM05-SM06. Conduct technical deep-dives and develop common ENISA, Capacity building and guidance and tools, including: Member guidance on technical measures - A comprehensive and dynamic matrix of security States authorities controls and best practices for 5G security; Guidance in support of implementation of selected technical measures from the Toolbox. Key objective 2: Supporting continuous exchange of knowledge and capacity building information and best practices on strategic measures related to suppliers Areas Continuous knowledge building Main short- and mid-term actions Organise knowledge building activities on technology and related challenges (open architectures, 5G features – e.g. virtualisation, containerisation, slicing etc.), threat landscape evolutions, real-life incidents, etc. Risk assessments Update and exchange information on updated national risk assessments Joint EU-funded projects to support the Toolbox implementation Provide financial support to projects supporting the Toolbox implementation using EU funding, notably under the Digital Europe Programme (e.g. capacity building projects for national authorities, test beds or other advanced capacities, etc.) Foster collaboration and cooperation between national authorities engaged in 5G cybersecurity (e.g. NIS Cooperation Group, cybersecurity authorities, telecom regulatory authorities) and with private stakeholders Lead actors ENISA, Member states authorities, other stakeholders Member States authorities, Commission, ENISA Member States authorities, Commission Member States authorities, Commission, ENISA Key objective 3: Promote supply chain resilience, and other EU strategic security objectives Cooperation among stakeholders Areas Standardisation Supply chain resilience Main short- and mid-term actions Define and implement a concrete action plan to enhance EU representation in standard setting bodies as part of the next steps of the work of the NIS sub-group on standardisation, in order to achieve specific security objectives, including the promotion of interoperable interfaces to facilitate diversification of suppliers. - Conduct an in-depth analysis of the 5G ecosystem and supply chain to better identify and monitor key assets and potential critical dependencies - Ensure the functioning of the 5G market and supply chain is in line with EU trade and competition rules and objectives, as defined in the Commission Communication of 29 January, and that FDI screening is applied to investment developments potentially affecting the 5G value chain, 27 Lead actors Member States authorities Member States authorities, Commission

Select target paragraph3