Comment

The price of openness

Francesco Cappelletti / Sep 2026

Image: Shutterstock

 

Digital policy can no longer be treated as a technical specialism for engineers and procurement officials; it has become a question of statecraft. Digital infrastructure, comprising data centres, cloud platforms, and connectivity networks, now underpins nearly every critical sector, from energy and finance to healthcare and public administration. When this infrastructure is sound, its dependability is invisible. When it fails, or is made to fail, the consequences are immediate, systemic, and costly.

When Openness Becomes Exposure

For a generation, Europe drew real benefits from open markets and integrated trade: lower costs, faster innovation, and access to leading technologies. Yet, that same openness created a dense web of dependencies and chokepoints that can now be turned into instruments of coercion. Russia’s war against Ukraine, China’s growing assertiveness, and abrupt shifts among partners have made the lesson unavoidable: strategic dependence is not merely about hostile intent; it is about structural exposure.

Europe’s task, therefore, is not to abandon openness, but to discipline it. The question is no longer whether to act, but how to protect both security and the Single Market. A fragmented response would produce the worst of both worlds: too weak to shield Europe, and too uneven to preserve fair competition within the Union.

Enter the Cybersecurity Act 2

This is the context for the proposed Cybersecurity Act 2.  The proposal would not merely update the 2019 Regulation; it would repeal and replace it, reform ENISA’s mandate, and introduce a dedicated architecture for ICT supply chain security. This is a strategic pivot because it establishes a trusted supply chain framework and shifts the organising category from mere compliance to trust. The vocabulary is deliberate: trust is no longer an afterthought, but a condition for participation in Europe’s most sensitive digital infrastructures.

The Mechanism of Trust

The framework’s core innovation is its capacity to distinguish between the benign and the structurally risky. Its instinct is liberal, not protectionist: openness is not the same as credulity, and a liberalism worth the name must come with judgement. The case is for intelligent openness: a Europe confident enough to remain open to trusted partners, yet clear-eyed enough to recognise when a dependency has quietly become a channel of coercion.

The criteria are jurisdictional and control-based, not a simple nationality test. They ask whether the legal and governance architecture of a supplier’s home state creates a systemic lever of coercion: whether that jurisdiction can compel the surrender of undisclosed vulnerabilities, whether independent judicial and democratic oversight exists, and whether there is a record of state-linked malicious activity.

That is a calibrated, evidence-based test, not a blanket ban. It would also allow an affected supplier to seek an exemption by demonstrating independence, mitigation measures, or safeguards that can reduce the identified risk.

Connectivity: The Front Line

The framework will be tested first, and most visibly, in connectivity. Networks are no longer neutral plumbing; they are the substrate on which all other sectors run. Energy grids, payment systems, hospitals, transport, defence, and edge-deployed artificial intelligence are, in effect, applications running on top of connected infrastructure. Compromise the substrate, and you do not merely damage one sector; you gain leverage over all of them.

Consequently, the proposal treats networks as a special case, creating a dedicated chapter on ICT supply chains for mobile, fixed, and satellite communications. For key network assets, components from high-risk suppliers would have to be excluded and phased out. In mobile networks, the proposed maximum phase-out period is 36 months from the publication of the list of high-risk suppliers.

Here, the Cybersecurity Act meets the Digital Networks Act. Network security and market design can no longer be treated as separate policy problems. The choices made now about who may build and operate connectivity will shape European resilience for a generation. That is why connectivity must come first.

Three Principles for the Framework

Three principles should guide the legislative process. First, European coherence: a Union-wide assessment and a common list of high-risk suppliers are necessary to prevent security gaps and internal market fragmentation. Second, proportionality: the strongest safeguards should be concentrated where risks are highest, especially in connectivity and other key ICT assets. Third, speed: a well-designed regime that arrives too late will be overtaken by the threats it seeks to address. Pace is not a concession to expediency; it is a condition of effectiveness.

Open Europe, Free Europe

European freedom does not require openness without conditions. It requires the ability to set the terms under which interdependence remains safe, fair, and politically sustainable. Openness without trust does not produce resilience; it produces systemic vulnerability dressed up as principle.

Trusted suppliers are not a technical side issue to be settled after the political choices have been made. They are part of the political choice itself. If Europe wants to remain open, resilient, and free to decide, it must ensure that the systems carrying its data, services, and critical functions are not built on dependencies that others can turn into leverage. Openness can remain Europe’s strength only if it is anchored in trust.

 

Francesco Cappelletti

Francesco Cappelletti

September 2026

About this author ︎►

cartoonSlideImage

Sirens

See the bigger picture ►

cartoonSlideImage

NATO 2026

See the bigger picture ►

cartoonSlideImage

Trump-Meloni

See the bigger picture ►

cartoonSlideImage

Tank Fodder

See the bigger picture ►

cartoonSlideImage

Mine!

See the bigger picture ►

cartoonSlideImage

x

See the bigger picture ►

cartoonSlideImage

State visit

See the bigger picture ►

cartoonSlideImage

Orbán and Putin

See the bigger picture ►

soundcloud-link-mpu1 rss-link-mpu soundcloud-link-mpu itunes-link-mpu