Appendix: Next steps on cybersecurity of 5G networks Based on the results of the review of the Commission Recommendation on the Cybersecurity of 5G networks120, the next steps in the coordinated work at EU level should focus on three key objectives and on main actions for the short and mid-term set out in the table below, to be implemented by Member States authorities, the Commission and ENISA. The first priority for the next phase is to complete the implementation of the Toolbox at national level and to address the issues identified in the Progress report of July 2020. In this context, some of the Toolbox Strategic measures would benefit from enhanced coordination work or exchange of information within the NIS Work Stream, as already identified in the Progress report, which could potentially lead to the development of best practices or guidance. As regards Technical measures, ENISA could provide further support, building on the work they have already done and investigating certain topics more in-depth, as well as developing a comprehensive overview of all relevant guidelines on 5G cybersecurity requirements for mobile network operators. Secondly, Member States emphasised the importance of keeping abreast of developments through the continuous monitoring of evolutions in the technology, 5G architecture, threats and 5G use cases and applications, as well as external factors, in order to be able to identify and address new or emerging risks. Moreover, a number of aspects in the initial risk analysis should be looked into further, notably to ensure it addresses the entire 5G ecosystem, including all relevant parts of the network infrastructure and of the 5G supply chain. While the Toolbox has been designed as a flexible and adaptable instrument, if necessary, steps could be taken in the medium term to augment or amend it, in order to ensure it remains comprehensive and up-to-date. Thirdly, EU-level actions should continue to be taken to support and complement the Toolbox objectives and to fully integrate them into relevant Union and Commission policies, notably following up on the actions announced by the Commission in its Communication on the Toolbox of 29 January 2020121 in a broad range of areas (e.g. EU funding for secure 5G networks, investments in 5G and post-5G technologies, trade defence instruments and competition to avoid distortions in the 5G supply market, etc.). Where appropriate, detailed arrangements and milestones for the main actions set out below should be agreed by the lead actors in early 2021. Key objective 1: Ensuring convergent national approaches for effective risk mitigation across the EU Areas Toolbox implementation by Member States Exchange of Main short- and mid-term actions Complete the implementation of the measures recommended in the Toolbox conclusions by the second quarter of 2021, with periodic stocktaking within the NIS Work Stream. Intensify exchanges of information and consider possible 120 Lead actors Member States authorities Member Commission Report on the impacts of the Commission Recommendation 2019/534 of 26 March 2019 on the Cybersecurity of 5G networks. 121 Commission Communication COM (2020)50, Secure 5G deployment in the EU - Implementing the EU toolbox, 29 January 2020. 26

Select target paragraph3