EU Governments Scrapped Telecom Equipment Phase-Out Deadline

The removal of a fixed 36-month timeline allows for risk-based hardware replacement to manage infrastructure costs.

Updated on Sept. 29, 2026 in Telecommunications

Bold flat-color editorial illustration of fiber optic cables and steel server hardware, representing the shift to risk-based infrastructure policy.
EU regulators have replaced a mandatory 36-month telecom hardware phase-out deadline with a risk-based policy to support fiber and 5G network investment. AI Illustration. Upload story photo >

Live Poll

Should governments prioritize security mandates even if they increase costs for telecom and technology services?

EU governments have officially removed a mandatory 36-month phase-out deadline for high-risk telecom equipment from a broader cybersecurity proposal. The policy change responds to industry concerns regarding the capital requirements of replacing existing network infrastructure.

Why it matters

The decision aims to prevent a significant financial strain on mobile operators, who warned that the initial timeline could disrupt funding for vital fiber, 5G, and 6G deployments. By pivoting to a risk-based approach, regulators seek to balance national security requirements with the economic reality of maintaining large-scale digital networks.

Telecom operators estimated that the original mandate would incur 40 billion euros in replacement costs, an amount that would otherwise support regional fiber, 5G, and 6G infrastructure investments. The current proposal replaces a rigid 36-month deadline with a schedule tied to risk levels and product lifecycles.

The players

European Commission

The executive arm of the European Union responsible for proposing legislation, including the current cybersecurity overhaul.

Deutsche Telekom

A major European telecommunications provider that leads the industry in advocating for infrastructure investment and policy stability.

The details

The cybersecurity proposal was first introduced by the European Commission in January 2026 to address security concerns surrounding high-risk suppliers. The original plan mandated a total phase-out of specified hardware within 36 months, a policy that Deutsche Telekom and 16 other industry peers argued would necessitate costly, premature equipment removal. The revised approach shifts to a model where replacement timelines are indexed to the actual security risk, existing equipment lifecycles, and the immediate availability of alternative components.

Timeline

  1. January 2026: The European Commission proposed the initial cybersecurity overhaul.

  2. September 2026: Industry peers, led by Deutsche Telekom, submitted a joint letter regarding costs.

  3. September 22, 2026: EU governments removed the 36-month phase-out deadline from the proposal.

  4. Next five years: The expected timeframe for the eventual equipment replacement process.

The Tech Race

This policy pivot adjusts the implementation of the European Commission's cybersecurity proposal to accommodate the reality of heavy capital-expenditure cycles in national networks. It effectively slows the forced retirement of legacy components to protect the financial viability of next-generation 6G and fiber build-outs.

For European mobile subscribers, this change reduces the likelihood of sudden, high-cost capital outflows that might have otherwise triggered service fee increases or delayed network upgrades. The actual pace of network equipment replacement will now be determined by technical risk assessments over the coming five years.

The takeaway

The removal of the hard deadline signals a shift toward a more pragmatic regulatory approach to network security that prioritizes operational continuity. Observers should track upcoming negotiations between EU lawmakers and member states to see how the specific criteria for 'risk levels' and 'infrastructure lifecycles' are eventually defined.

Further reading

For broader context on how infrastructure policy affects network rollouts, visit our Telecommunications section.

Live Poll

Should governments prioritize security mandates even if they increase costs for telecom and technology services?