Skip to main content

NEWSROOM

News | Opinion | Intelligence | Press Releases | Updates


What regulatory policies and compliance laws concern European telecoms operators the most?

European Telecoms regulation main blog image v4.1

Within the European telecoms industry, there is currently a major shift to create a homogeneous set of rules that applies to every company throughout the continent. They aim to safeguard both consumers and businesses against external threats, streamline processes, and improve the overall quality of networks.

The European Commission in conjunction with the local National Regulatory Authorities set out and enforce the frameworks to which every telecommunications company operates within Europe. Their remit encompasses consumer protection, corporate governance, cross-border co-operation, and security.

At the moment, there are three acts that are at the forefront for both telecoms operators and vendors in Europe, these are the NIS2 Directive, the Cyber Resilience Act (which is both in effect), and the forthcoming Digital Networks Act. Each of the acts comes with its own policy, compliance, and regulatory issues, and is already causing friction with operators.

The Digital Networks Act (DNA) Overhaul

Key Facts

  • Published: The European Commission officially proposed the draft legislation on January 21, 2026.
  • Next Steps: The draft is actively under review by the European Parliament and the Council of the EU. Legislative negotiations and adoption typically take up to two years, meaning it is currently being debated
  • Implementation: Once formally adopted, the DNA will replace the old 2018 Electronic Communications Code (EECC) and transition Europe’s 27 individual national markets into a single framework for digital connectivity networks. 

Aims

The “Single Passport” System
Rather than dealing with 27 separate national telecom authorities, Operators are adapting to a new cross-border authorization system that allows them to scale across the EU under a unified license. It merges four existing legal acts (including the Electronic Communications Code and the Open Internet Regulation) into one directly applicable rulebook.
Sunsetting Copper
The EU is forcing operators to execute strict national plans to completely the switch off of legacy copper networks and migrate consumers to full fiber infrastructures by 2035.
Spectrum Allocation Changes
The DNA pushes for long-term, harmonized spectrum conditions and indefinite radio spectrum assignment durations. This is a source of friction with national governments who gain revenue from localized spectrum auctions. 
Infrastructure Funding and “Fair Share” Conciliation
As a way of making big tech gatekeepers (the biggest users) pay a contribution towards 5G and fiber rollouts, European network operators will have legal recourse available to make claims against Content and Application Providers (CAPs like Netflix and Google). The structured conciliation mechanism will allow them to enter formal dispute resolution to solve traffic delivery economics. 
Cross-Border Consolidation
Historically, EU antitrust regulators blocked mergers to keep consumer prices low. Revised policies aimed at relaxing merger scrutiny are aiming to allow pan-European telecom giants to scale and pool capital. 

Hardened Supply Chain and Network Security
Geopolitical tensions have pushed network resilience to the top of the European Commission’s priority list, forcing heavy compliance spending.

NIS2 Directive (Network and Information Security 2)

Key Facts

  • The NIS2 Directive went into effect in European Union legislation on October 17, 2024, at which point Member States were required to transpose the rules into their national laws. It replaced the original 2016 NIS law.

Aims

  • The NIS2 Directive is a mandatory EU-wide cybersecurity law designed to protect critical infrastructure and digital supply chains against sophisticated cyber threats. NIS2 enforces vastly stricter security standards than its predecessor and introduces massive financial penalties, as well as holding company executives personally liable for security failures.

Who does it apply to?

  • NIS2 applies to public or private companies operating within the EU that have more than 50 employees and an annual turnover or balance sheet exceeding €10 million. Even though it splits these entities into two tiers, both face strict penalty schemes. Essential Entities are high-criticality sectors like energy, transport, banking, healthcare, digital infrastructure, and public electronic communications (telecom operators/carriers). Important Entities are critical sectors including manufacturing, chemicals, food production, postal services, waste management, and digital providers (e.g., online marketplaces).

Key Compliance Requirements

  • Organizations falling under the directive must fulfil several operational and technical mandates.
    • Executive Accountability: Senior management bodies must formally approve and oversee the organization’s cybersecurity measures. Board members can also face direct personal fines or temporary professional bans for non-compliance.

    • The 3-Tier Incident Reporting Rule: Significant security incidents must be reported to the national competent authority on an exact, strict timeline. Within 24 Hours an initial “early warning” notification must be provided. Within 72 Hours a comprehensive incident notification updating the severity and impact must be issued. Within 1 Month a finalized, detailed root-cause report must be submitted.

    • Supply Chain Security: Companies are legally responsible for evaluating and managing the security vulnerabilities of their direct third-party vendors and data suppliers. 

    • Baselining Basic Digital Hygiene: Mandated use of cryptography (encryption), multi-factor authentication (MFA), vulnerability handling, business continuity plans, and crisis management frameworks. 

Enforcement and Severe Penalties

  • Fines under NIS2 mirror GDPR structures and depend heavily on the classification tier. In Essential Entities Non-compliance can trigger fines up to €10 million or 2% of total global annual turnover, whichever is higher. In Important Entities fines can reach up to €7 million or 1.4% of total global annual turnover, whichever is higher.

Cyber Resilience Act (CRA)

Key Facts

  • The EU’s Cyber Resilience Act (CRA) entered into force on December 10, 2024, but it features a phased enforcement timeline.
  • Its official title is Regulation (EU) 2024/2847.
  • Full conformity and compliance for all products with digital elements becomes mandatory on December 11, 2027.

Aims

  • The EU Cyber Resilience Act (CRA) is a mandatory regulation that establishes strict, legally binding cybersecurity standards for all hardware and software products sold within the EU market. It shifts the regulatory focus from organisational IT security to the security of the product itself by mandating that any product that connects to a network or device must be built using secure-by-design and secure-by-default principles, or it will be banned from the EU market.

What Products does it apply to?

The CRA applies broadly to “products with digital elements” (PDEs), which includes any software or hardware that features a direct or indirect data connection.

  • Consumer Tech: Laptops, smartphones, smart home appliances, wearables, and mobile apps.
  • Industrial & Enterprise Infrastructure: Routers, switches, network firewalls, and core operating systems.

Risk Classification Tiers

  • There are three tiers of classification based on their risk levels. These include Low-Risk, Important and Critical. The rigor of a product’s compliance path depends on its designated risk level. 

Key Obligations for Manufacturers

  • Under the regulation, companies placing digital products on the market are held fully accountable for their security lifecycle: 
    • The CE Mark Requirement: Products must bear the visible CE Mark to declare they meet EU cybersecurity product laws. 
    • Lifecycle Vulnerability Management: Manufacturers must actively monitor, document, and fix security flaws—providing free security patches and updates for the product’s expected operational lifetime, usually up to 5 years
    • Strict Vulnerability Reporting: Companies must report any actively exploited product vulnerability or severe security incident directly to national authorities within 24 hours of discovery. 

Enforcement Timeline and Penalties

  • Fines for non-compliance are severe: violating product design guidelines or falsifying a conformity assessment can draw administrative fines up to €15 million or 2.5% of total global annual turnover, whichever is higher.

How can Squire Technologies’ products and services address the concerns of European telecoms operators?

1. Network Security

Squire Technologies emphasizes a secure-by-design signalling infrastructure. Its platforms are designed to provide security, monitoring, and signalling control across multi-generation networks.

Relevant solutions include:

These products help operators:

  • Protect signalling interfaces
  • Control authentication and authorization traffic
  • Reduce exposure to signalling attacks
  • Create centralized security controls and governance mechanisms
  • Support audit and compliance reporting through network monitoring and management functions 

2. Fraud Management and Regulatory Risk Reduction

Telecom fraud remains a major regulatory and operational concern in Europe, particularly around roaming, premium-rate abuse, artificial traffic inflation, and identity-related fraud.

Squire’s MavenShield Fraud Prevention Platform provides:

  • Real-time fraud detection
  • Automated blocking and session termination
  • Integration with OSS/BSS and analytics platforms
  • Blacklist/whitelist management
  • GSMA-compliant roaming fraud controls 

For European operators, this helps demonstrate:

  • Active fraud-prevention controls
  • Revenue assurance processes
  • Compliance with industry anti-fraud frameworks
  • Risk-management obligations under cybersecurity and operational resilience programs

3. Subscriber Policy and Authentication Governance

European operators must demonstrate control over subscriber authentication, authorization, and policy management, especially in LTE and 5G environments.

The SVI-DSC Diameter Signalling Controller supports:

  • Secure Diameter traffic handling
  • Subscriber policy exchange
  • Authentication and authorization control
  • Routing, filtering, throttling, and policy enforcement across LTE networks 

These capabilities are important for:

  • 5G security frameworks
  • Subscriber-data protection programs
  • Identity and access management controls
  • Regulatory audits of network access governance

4. Multi-Generation Network Compliance

Many European operators continue to run mixed 2G/3G/4G/5G environments. Regulatory requirements often demand consistent controls across all generations.

The Sigla Unified Signalling Platform enables:

  • Protocol mediation
  • Interworking between legacy SS7, Diameter, SIP, HTTP/2, and 5G interfaces
  • Centralized signalling governance across generations
  • Consistent security and policy controls throughout network evolution 

This helps operators satisfy regulatory expectations for secure migration to 5G without creating unmanaged legacy-network risks.


5. Monitoring, Audit, and Compliance Reporting

European regulators increasingly require evidence of monitoring, incident detection, and operational oversight. Squire’s portfolio includes Prism Network Monitoring.

Prism’s capabilities can support:

  • Compliance reporting
  • Network activity monitoring
  • Incident investigations
  • Traffic analysis
  • Audit evidence generation for regulators and internal risk teams 

To find out more about Squire Technologies click here to download our corporate brochure.

Gareth Thomas blog pic

Gareth Thomas, Digital Marketing Executive at Squire Technologies