Guillaume Lambert   •  11 March 2026
Digital Sovereignty   •   Critical Communications   •   Cybersecurity

Digital Networks Act (DNA): strategic autonomy and reducing technological dependencies

What the DNA and the revised Cybersecurity Act change for network security, supply chains and critical communications.

Digital Networks Act illustration
FIG. 01Illustration accompanying the analysis published on LinkedIn.

At Mobile World Congress (#MWC2026), leading figures from the telecommunications industry addressed the structural trends shaping the evolution of mobile networks.

Many of the issues discussed — the relevant scale of telecom markets in the context of 5G deployment, the disruption driven by satellite-enabled mobile networks, the imperative to reinforce critical infrastructure, and the continuing and broad impact of AI — lie at the heart of the proposed Digital Networks Act (#DNA), presented by the European Commission on 21 January 2026.

The DNA seeks to redefine the legislative framework governing electronic communications in Europe to reflect these new realities. It is designed as a structural reform, consolidating several sectoral instruments into one: the 2018 European Electronic Communications Code, the BEREC Regulation, the Radio Spectrum Policy Programme and the 2015 Open Internet Regulation. It would replace directives with a directly applicable regulation and ensure uniform implementation across Member States.

One of the proposal’s most strategic strands concerns reducing technological dependencies and preserving strategic autonomy in communications networks. Its ambition is to move digital sovereignty from an abstract concept to an operational reality embedded in mobile-network infrastructure.

This implies:

  • using only components audited and approved by European cybersecurity agencies, while developing trusted supply chains;
  • strictly implementing the EU 5G Toolbox guidelines — something that is still not the case in every Member State.

A paradigm shift: from recommendation to obligation

The DNA’s security strand continues a policy initiated in 2020, but crosses a decisive threshold. It formalises measures already taken by the Commission and Member States for mobile networks, which led to the voluntary 5G Toolbox framework designed to reduce risk.

That voluntary framework did not deliver the intended results: only ten of the twenty-seven Member States used the Toolbox to impose obligations on high-risk suppliers by restricting or excluding them from their 5G networks.

This limited action has led to a mandatory system through the DNA and the revised Cybersecurity Act, imposing a strict three-year deadline for Member States to phase high-risk suppliers out of 5G networks.

DNA + Cybersecurity Act 2: a two-tier framework

The DNA is not, by itself, the supply-chain security regime. It operates alongside the revision of the Cybersecurity Act (#CSA2), presented on 20 January 2026. The proposed DNA refers to cybersecurity-regulation requirements that must also be met for authorisation under the DNA.

In practical terms, the two texts are complementary: the DNA sets network-access and authorisation conditions; CSA2 defines the criteria for identifying suppliers at risk and the associated removal measures.

Three operational pillars

Identify key ICT assets, classify suppliers at risk, then apply targeted mitigation measures.

First pillar — identifying key ICT assets. The European Commission identifies assets used by essential or critical sectors under Annexes I and II of the NIS2 Directive: components, equipment or services considered critical to their operation.

Second pillar — classifying high-risk suppliers. Supply-chain security is no longer solely about the technical security of products and services. It also includes dependency, foreign-interference, economic-espionage and state-influence risks. Classification can lead to restrictions: no European cybersecurity certification and exclusion from public procurement and EU-funded programmes involving essential ICT assets.

Third pillar — targeted mitigation measures. On the basis of risk assessments and identified key assets, the Commission may propose measures up to a prohibition on components provided by high-risk suppliers in critical IT assets. Such decisions must be supported by market analysis and an assessment of economic impact. The text also provides for a mechanism allowing a country to be designated as a cybersecurity concern for ICT supply chains.

In short, DNA and CSA2 shift network security from voluntary incentives to enforceable legal obligations, supported by a timetable, potential sanctions and centralised governance.

An essential axis for public-safety and emergency communications

The DNA’s provisions on strategic autonomy and reducing technological dependencies are essential to networks dedicated to public-safety and emergency communications: France’s #RRF and, in time, #EUCCS at European Union level.

These mission-critical communications networks must rely on 4G and 5G radio-access infrastructure that fully incorporates digital-sovereignty and strategic-autonomy requirements. Secure 5G use requires trusted infrastructure.

The DNA also confirms the convergence of telecoms, cloud and cybersecurity, and the recognition of digital networks as critical infrastructure, regulated not only through an economic lens but also through security and continuity of service.

The real impact of this shift will depend on the capacity to develop and fund a robust industrial ecosystem, so that removing suppliers deemed risky does not create new dependencies elsewhere.