Technology
5G telecommunications infrastructure and high-risk vendor controls
5G telecommunications infrastructure and high-risk vendor controls covers government measures concerning Huawei and ZTE equipment in 5G and adjacent networks. Australia, Canada, the United States, the United Kingdom and European authorities have used security obligations, procurement restrictions, funding conditions, covered-equipment lists and removal directions to reduce supply-chain risk. These measures establish official risk judgements and legal action. They do not establish that every product contains a backdoor or that either company acts on state instructions in every market.
Architecture and control points
A mobile network combines radio access, transport, core functions, network management, software updates and managed services. Vendor access and operational risk differ across those layers. Visibility into traffic depends on the deployed function, architecture, encryption, configuration, maintenance privileges and operator controls. A vendor does not automatically see or control every communication simply because some of its equipment is present.
The strategic issue is continued dependence on equipment, software and support that a government believes could be subject to foreign direction or become unavailable during crisis. Public authorities act through regulated carriers, government contractors, funding recipients and procurement bodies. Network operators still install, configure, operate and remove the equipment, making the state nexus a regulated-intermediary relationship.
Government controls
Australia's 2018 approach used telecommunications-security obligations and a country-agnostic test concerning vendors likely to be subject to extrajudicial direction by a foreign government. It was not published in the same legal form as Canada's May 2022 policy excluding Huawei and ZTE products and services from 5G networks.
The European Union's 2019 recommendation and 2020 5G Toolbox created a common risk-management framework. In June 2023 the European Commission stated that decisions by member states to restrict or exclude Huawei and ZTE were justified and compliant with the Toolbox. That was a policy and security-risk judgement, not a judicial finding of espionage or a technical finding about every product.
The United Kingdom's 2022 Designated Vendor Direction imposed binding controls on Huawei equipment and required its removal from 5G networks by the end of 2027. The timetable does not establish that removal was complete as at 29 July 2026.
In the United States, section 889 of Public Law 115-232 restricts defined federal procurement and contracting involving covered telecommunications equipment and services. It is not a universal prohibition on possession or commercial use. The Federal Communications Commission's Covered List identifies covered equipment and services. Its Secure and Trusted Communications Networks reimbursement programme is a separate mechanism that funds eligible removal and replacement. The Covered List baseline used here is DA 26-548, dated 4 June 2026.
Evidence and trade-offs
Foreign intelligence legislation, ownership, governance, maintenance access and product assurance can inform a risk assessment. China's National Intelligence Law is one such factor, but it does not prove that a particular backdoor, request or company response occurred. Huawei and ZTE also differ in ownership, governance, products and enforcement history and should not be treated as one firm.
Removal can reduce one category of dependency while increasing transition, interoperability, cost and supplier-concentration risk. Current assessment must therefore identify the network layer, authority, legal instrument, deadline and available substitutes in each jurisdiction. The record remains in the main sequence because binding public measures transmit declared resilience and security objectives through regulated network operators.
See also
Allied restrictions on Huawei in 5G networks (2018-present) · United States Entity List and foreign direct product rule campaign against Huawei (2019-present) · Telecommunications network equipment and semiconductor supply dependence · Chokepoint effect · Supply-chain resilience
Sources
- Australian Department of Home Affairs, Telecommunications Sector Security Reforms, 2018 to 2019 Annual Report.
- Australian Department of Home Affairs, Critical Technology Supply Chain Principles: A call for views (2020).
- Government of Canada, "Policy Statement: Securing Canada's Telecommunications System" (19 May 2022).
- European Commission, Recommendation (EU) 2019/534 on cybersecurity of 5G networks (26 March 2019).
- European Commission, Secure 5G deployment in the EU: Implementing the EU toolbox (29 January 2020).
- European Commission, "Implementation of the 5G cybersecurity Toolbox" (15 June 2023).
- United Kingdom Government, Huawei Designated Vendor Direction (13 October 2022).
- United Kingdom National Cyber Security Centre, "NCSC advice on the use of equipment from high-risk vendors in UK telecoms networks" (updated 14 July 2020).
- Federal Communications Commission, Covered List, DA 26-548 (4 June 2026).
- Federal Communications Commission, Secure and Trusted Communications Networks Reimbursement Program: Frequently Asked Questions (updated October 2023).
- Congressional Research Service, Huawei and U.S. Law, report R46693 (updated 2025).
- Huawei Investment and Holding Co., 2025 Annual Report (31 March 2026).
Recommended citation
Cite this entry
Tennant, James J., ed. '5G telecommunications infrastructure and high-risk vendor controls.' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/5g-telecommunications-infrastructure-huawei-zte/.
Suggest an edit