Table 1 - Risk categories and scenarios (source: the EU coordinated risk assessment report) I - Risk scenarios related to insufficient security measures R1-Misconfiguration of networks II - Risk scenarios related to 5G supply chain R3-Low product quality III - Risk scenarios related to modus operandi of main threat actors R5- State interference through 5G supply chain IV - Risk scenarios related to interdependencies between 5G networks and other critical systems V - Risk scenarios related to end user devices R2-Lack of access controls R4-Dependency on any single supplier within individual networks or lack of diversity on nation-wide basis R6- Exploitation of 5G networks by organised crime or organised crime group targeting end-users R7- Significant disruption of critical infrastructures or services R8-Massive failure of networks due to interruption of electricity supply or other support systems R9-Exploitation of IoT (Internet of Things), handsets or smart devices To effectively address these risks and strengthen the security and resilience of 5G networks a comprehensive approach is required. This implies putting in place a key set of measures, as well as related supporting actions which can simultaneously address the risks. Ultimately, the key to ensure coordinated Member State approaches will be the effective implementation of the risk mitigation measures and actions in all Member States, as adapted to the respective situation in each Member State. This toolbox also provides an indicative assessment of measures which would require or benefit from a common approach and/or some form of coordination at EU level, or which may be best implemented in coordination with other Member States or by individual Member States, depending on the respective national context. Altogether, the measures presented in this toolbox contribute to achieving a number of important and mutually reinforcing security objectives, which are relevant to address the risks identified in the risk assessment report and protect the confidentiality, integrity and availability of 5G networks: • • • • • Reinforcing security in the design, deployment and operation of networks; Raising baseline security standards for the security of product and services; Minimising the exposure to risks stemming from the risk profile of individual suppliers; Avoiding or limiting major dependencies on any single supplier in 5G networks; and Promoting a diverse, competitive and sustainable market for 5G equipment, including by maintaining EU capacities in the 5G value chain. The measures identified are presented in Section 4 of this report and further detailed in the annexed tables. 5

Select target paragraph3