11 Aug 2026 | Working Papers
Van den Bossche, Peter L.H.

Preliminary Thoughts on the European Commission Proposal for the Cybersecurity Act 2.0

This paper offers general observations on the key mechanisms and WTO consistency of the Proposal for the EU Cybersecurity Act 2 (‘CSA2.0’). The proposed CSA2.0 lays down the ICT supply chain security mechanism and the European cybersecurity certification mechanism, under which the European Commission may designate certain third countries as posing cybersecurity concerns, by taking account of the cyber-related legal systems and practices of such countries.

Providers of ICT products and services that are established in, or have certain affiliation with, the designated third countries constitute ‘high-risk suppliers’. Most notably, the proposed CSA2.0 prohibits ‘high-risk suppliers’ from providing ICT products and services for ‘key ICT assets’ used by EU entities in 18 critical sectors and denies their access to cybersecurity certification and other market opportunities in the EU. If adopted, the proposed CSA2.0 will have significant economic impact on sectors where foreign exporters play a major role on the markets, including those related to telecommunications, solar inverters, battery energy storage, and connected and automated vehicles. 

While the potential impact on trade is profound, it is surprising and disappointing that the EU seems to have largely ignored the WTO consistency issues inherent in the proposed CSA2.0, as they have never properly and sufficiently addressed these issues in the proposal and other accompanying documents during the legislative process. China’s Ministry of Commerce, however, has questioned the WTO consistency of this legislative proposal in its comments submitted to the European Commission, pointing to violations of various obligations under the WTO agreements. If adopted, the CSA2.0 may trigger a major WTO dispute due to the systemic concerns shared by many affected countries. Against this background, this paper provides preliminary thoughts on the WTO consistency of the CSA2.0, with a particular focus on the non-discrimination obligations under the GATT 1994, the GATS, and the TBT Agreement.

The non-discrimination obligations under the GATT 1994 and the GATS are clearly applicable to the measures targeting products and services of the ‘high-risk suppliers’, as defined by the proposed CSA2.0, while the applicability of the TBT Agreement is less straightforward and requires further demonstration by the potential complainant. One of the key issues concerning those measures’ consistency with the said obligations is the ‘likeness’ test under the WTO agreements, which can be shown through the comparison of relevant factors or presumed if the measure is origin-based. Either way, a complainant is likely to be able to show that the products are ‘like’.

On the basis that the affected products are ‘like’, this paper further observes that under Article I of the GATT 1994, the blanket prohibitions established by the CSA2.0 fail to accord to ICT products of high-risk suppliers from a Member, immediately and unconditionally, the advantages accorded to those of other suppliers from other countries. Under Article III:4 of the GATT 1994, it is also not difficult for a complaint to show that the imported ICT products of high-risk suppliers are treated less favourable than the ‘like’ domestic ICT products of other suppliers, as the former’s products are outright excluded from the EU market. The same is true for claims under Articles II and XVII of the GATS. On the other hand, however, to establish violations of the non-discrimination obligations under Articles 2.1 and 5.2 of the TBT Agreement may be trickier, given the doctrine of legitimate regulatory distinction underlying these clauses.

When a complainant successfully establishes violations of the non-discrimination obligations under the GATT 1994 and the GATS, the EU will likely argue that the CSA2.0 is justified under the applicable exceptions of these WTO agreements. For the general exceptions, even assuming that any of the grounds for justification are relevant, which does not appear to be the case, it would be challenging for the EU to establish that such exclusionary measures introduced by the CSA2.0 are ‘necessary’ for protecting the stated objective of cybersecurity and/or the application of these measures does not constitute arbitrary discrimination or unjustifiable discrimination. For the security exceptions, it is clear from the treaty text as consistently interpreted in prior WTO disputes that political or economic differences between Members themselves are not sufficient to constitute an ‘emergency in international relations’. 

The EU's trading partners—most notably China—have warned that if the CSA2.0 is adopted in its current form, they will enact corresponding countermeasures against EU businesses. Moreover, if adopted, it is likely that China will initiate WTO dispute settlement proceedings against the EU and its Member States, which implement the CSA2.0. China could bring a WTO complaint against, in particular, Germany and France, which both have substantial trade volumes with China and played a decisive role in the CSA 2.0 proposal's adoption. Note that China and the EU are parties to the Multi-Party Interim Appeal Arbitration Arrangement (MPIA), and that, therefore, any WTO dispute between them will be brought to a legally binding resolution.

Preliminary Thoughts on the European Commission Proposal for the Cybersecurity Act 2.0