1. Introduction
5G networks will play a central role in achieving the digital transformation of the EU’s economy and
society. Indeed, 5G networks have the potential to enable and support a wide range of applications
and functions, extending far beyond the provision of mobile communication services between endusers. With worldwide 5G revenues to reach an estimated €225 billion in 2025 1, 5G technologies
and services are a key asset for Europe to be able to compete in the global market.
The cybersecurity of 5G networks is therefore essential to protect our economies and societies and
to enable the full potential of the important opportunities they will bring. It is also crucial for ensuring
the technological sovereignty of the Union.
Following the support expressed by the European Council on 22 March, 2019 for a concerted
approach to the security of 5G networks, the European Commission adopted its Recommendation
on the cybersecurity of 5G networks (hereafter ‘The Recommendation’) on 26 March, 2019. The
Recommendation called on Member States to complete national risk assessments and review
national measures, to work together at EU level on a coordinated risk assessment and to prepare a
toolbox of possible mitigating measures.
Each Member State completed its own national risk assessment of its 5G network infrastructures
and transmitted the results to the Commission and ENISA - the European Union Agency for
Cybersecurity.
Based on these national risk assessments, on 9 October, 2019 Member States - with the support of
ENISA and the Commission - published a report on the EU Coordinated Risk Assessment on
Cybersecurity in 5G Networks 2. This report identifies the main threats and threat actors, the most
sensitive assets, the main vulnerabilities (including technical ones and other types of vulnerabilities,
such as the legal and policy framework to which suppliers of information and communications
technologies equipment may be subject to in third countries), and the main associated risks. To
complement this report and as a further input for the toolbox, ENISA carried out a dedicated threat
landscape mapping 3, consisting of a detailed analysis of certain technical aspects, in particular the
identification of network assets and of threats affecting these.
The Council Conclusions of 3 December, 2019 endorsed the work of the Member States’
Cooperation Group on Network and Information Security (NIS Cooperation Group), supporting the
findings of the coordinated risk assessment. In particular, the Council welcomed ‘the ongoing joint
European efforts on safeguarding the security of 5G networks based in particular on the Commission
Recommendation on Cyber Security of 5G Networks’ and stressed ‘the importance of a coordinated
approach and effective implementation of the Recommendation in order to avoid fragmentation in
the Single Market’. To this effect, the Council called upon Member States, the Commission and
ENISA, to ‘take all necessary measures within their competences to ensure the security and integrity
of electronic communication networks, in particular 5G networks and to continue to consolidate a
coordinated approach to address the security challenges related to 5G technologies.’ 4
1
ABI Research projection: https://www.abiresearch.com/press/abi-research-projects-5g-worldwide-service-revenue.
https://ec.europa.eu/digital-single-market/en/news/eu-wide-coordinated-risk-assessment-5g-networks-security.
3 ENISA Threat landscape for 5G networks: https://www.enisa.europa.eu/publications/enisa-threat-landscape-for-5g-networks.
4 Council Conclusions on the significance of 5G to the European economy and the need to mitigate security risks linked to 5G 3
December, 2019 14517/19 https://www.consilium.europa.eu/media/41595/st14517-en19.pdf .
2
3