Multiple Chinese business chambers in the EU have expressed strong opposition to the proposed revision of the Cybersecurity Act (CSA2), They reiterated that mandatory, comprehensive, and time-bound exclusion policies across multiple key industries would cause disruption to normal market operations. They would also undermine the EU's own green and digital transitions, and harm China-EU economic and trade relations. The China Chamber of Commerce to the EU (CCCEU) said that the Chamber has submitted its feedback on the CSA2, stating that strengthening cybersecurity and protecting critical infrastructure should adopt a proportionate, risk-based, evidence-based, and technology neutral regulatory approach, while safeguarding the openness and competitiveness of the EU single market, according to a statement provided to the Global Times.
The Chinese Chamber noted that certain elements of the current CSA2 proposal could introduce overly broad restrictive measures that are not based on a transparent, evidence-based risk assessment methodology. In particular, the proposed mandatory, comprehensive, and time limited exclusion clauses across multiple critical sectors raise serious concerns. These measures could disrupt normal market operations, increase compliance costs for businesses, and have broader adverse effects on Europe's green and digital transitions, industrial competitiveness, and economic relations with key trading partners, it said. The fresh warning came as the European Commission (EC) proposed a new cybersecurity package including a “Proposal for a Regulation for the EU Cybersecurity Act” in January, which aims to gradually phase out components and equipment from “high-risk suppliers” in critical infrastructure. This move is widely seen as targeting Chinese companies and forms part of a broader set of EU protectionist tools targeting China.
Brussels is targeting "high-risk" vendors, commonly understood to be Chinese suppliers in critical sectors, Politico.eu reported. The proposed rules set new criteria for European governments when deciding to ban vendors from their networks, including assessing “non-technical risks” like whether companies are subject to political pressure, according to the report.
In addition to the CCCEU, a number of Chinese business chambers based in European countries, including Chambers in Poland, Spain and Italy, have also voiced their concerns in recent days. For example, the Chinese business chamber in Spain (CCINCE) issued a statement saying that an open, fair and fully competitive market is the foundation for Europe's long-term industrial competitiveness, adding that “excluding specific suppliers in the name of security essentially sacrifices market efficiency and technological diversity for so-called security.” This not only fails to create a sustainable risk governance mechanism, but may also introduces new vulnerabilities, according to the CCINCE statement. The Cybersecurity Act will be applicable immediately after approval by the European Parliament and the Council of the EU. The EU's proposed revision of the CSA2 could carry a price tag of nearly €367.8 billion if it forces the replacement of Chinese suppliers across 18 critical sectors, according to a report released by the CCCEU and London-based professional services provider KPMG, as reported by the Global Times.