1. Introduction 5G networks will play a central role in achieving the digital transformation of the EU’s economy and society. Indeed, 5G networks have the potential to enable and support a wide range of applications and functions, extending far beyond the provision of mobile communication services between endusers. With worldwide 5G revenues to reach an estimated €225 billion in 2025 1, 5G technologies and services are a key asset for Europe to be able to compete in the global market. The cybersecurity of 5G networks is therefore essential to protect our economies and societies and to enable the full potential of the important opportunities they will bring. It is also crucial for ensuring the technological sovereignty of the Union. Following the support expressed by the European Council on 22 March, 2019 for a concerted approach to the security of 5G networks, the European Commission adopted its Recommendation on the cybersecurity of 5G networks (hereafter ‘The Recommendation’) on 26 March, 2019. The Recommendation called on Member States to complete national risk assessments and review national measures, to work together at EU level on a coordinated risk assessment and to prepare a toolbox of possible mitigating measures. Each Member State completed its own national risk assessment of its 5G network infrastructures and transmitted the results to the Commission and ENISA - the European Union Agency for Cybersecurity. Based on these national risk assessments, on 9 October, 2019 Member States - with the support of ENISA and the Commission - published a report on the EU Coordinated Risk Assessment on Cybersecurity in 5G Networks 2. This report identifies the main threats and threat actors, the most sensitive assets, the main vulnerabilities (including technical ones and other types of vulnerabilities, such as the legal and policy framework to which suppliers of information and communications technologies equipment may be subject to in third countries), and the main associated risks. To complement this report and as a further input for the toolbox, ENISA carried out a dedicated threat landscape mapping 3, consisting of a detailed analysis of certain technical aspects, in particular the identification of network assets and of threats affecting these. The Council Conclusions of 3 December, 2019 endorsed the work of the Member States’ Cooperation Group on Network and Information Security (NIS Cooperation Group), supporting the findings of the coordinated risk assessment. In particular, the Council welcomed ‘the ongoing joint European efforts on safeguarding the security of 5G networks based in particular on the Commission Recommendation on Cyber Security of 5G Networks’ and stressed ‘the importance of a coordinated approach and effective implementation of the Recommendation in order to avoid fragmentation in the Single Market’. To this effect, the Council called upon Member States, the Commission and ENISA, to ‘take all necessary measures within their competences to ensure the security and integrity of electronic communication networks, in particular 5G networks and to continue to consolidate a coordinated approach to address the security challenges related to 5G technologies.’ 4 1 ABI Research projection: https://www.abiresearch.com/press/abi-research-projects-5g-worldwide-service-revenue. https://ec.europa.eu/digital-single-market/en/news/eu-wide-coordinated-risk-assessment-5g-networks-security. 3 ENISA Threat landscape for 5G networks: https://www.enisa.europa.eu/publications/enisa-threat-landscape-for-5g-networks. 4 Council Conclusions on the significance of 5G to the European economy and the need to mitigate security risks linked to 5G 3 December, 2019 14517/19 https://www.consilium.europa.eu/media/41595/st14517-en19.pdf . 2 3

Select target paragraph3