Loading…
Loading…
Commission Recommendation (EU) 2024/779 is the genesis instrument of the EU's submarine-cable-security architecture. Issued under TFEU Article 292, it addresses structural vulnerabilities that pre-date—but were crystallised by—the 2022–2024 series of Baltic Sea undersea-infrastructure incidents (Nord Stream, Baltic Connector, BCS East-West Interlink, and C-Lion1).
Four institutional pillars introduced:
1. Submarine Cable Infrastructure Expert Group — an informal coordination body chaired by the Commission (DG CNECT) with Member State competent authorities (transport, defence, intelligence) and ENISA as technical secretariat. The Group maps EU cable infrastructure, aggregates incident notifications, and coordinates the consolidated risk assessment cycle.
2. Consolidated Union-wide Risk and Vulnerability Assessment — a structured annual cycle covering physical threats (anchor drag, sabotage, seismic), cyber threats (BGP hijacking, wiretapping, OAM system compromise), and third-country ownership dependencies. Feeds the Cable Security Toolbox.
3. Cable Security Toolbox — a non-binding but politically weighted set of mitigating measures derived from the risk assessment: supplier-diversity requirements for landing equipment, security-of-supply clauses in cable maintenance contracts, diversification of landing station locations, and minimum repair-ship capacity targets.
4. Cable Projects of European Interest (CPEI) designation — criteria for identifying cable projects eligible for expedited permitting and priority access to CEF Digital, IPA III, InvestEU, and RRF financing. A CPEI must connect at least two Member States or a Member State to its islands / overseas territories / third countries where the connection has strategic significance. This mechanism was operationalised in full by JOIN(2025) 9 (filed as 2025-02-21-eu-cable-security-action-plan), which allocated €347M in concrete funding and published a first CPEI candidate list.
Regulatory character: A recommendation under TFEU Art. 292 carries no direct legal obligation but creates strong "comply-or-explain" norms within the EU governance cycle. The Expert Group's consolidated risk assessments feed NIS2 national transposition workstreams, and the CPEI mechanism references CEF Digital funding rules that carry compliance conditions. In practice, Member States whose cable infrastructure hosts CPEIs assume de-facto coordination obligations.
The recommendation itself is non-binding, which would ordinarily cap at severity 2. Severity 3 is warranted because: (a) it creates the institutional architecture—Expert Group, CPEI list, Toolbox—that all subsequent binding instruments (JOIN(2025) 9, NIS2 cable-sector guidance) flow from; (b) CPEI designation will redirect hundreds of millions in CEF Digital funding; and (c) the Toolbox supplier-diversity recommendations carry implicit signals about Chinese equipment suppliers (HMN Technologies, formerly Huawei Marine Networks) that influence procurement decisions even without legal force.
procurement advantage in the EU market as the dominant non-Chinese cable suppliers; Chinese competitors (HMN Technologies) are structurally excluded from CPEI-financed projects.
coordination requirements when cables connect EU territory, particularly for landing station licensing in France, Portugal, Spain, and Ireland.
for the Expert Group's incident-reporting framework and the risk assessment cycle.
cable repair vessels; JOIN(2025) 9 subsequently proposes a European repair-ship procurement vehicle.
privately owned subsea assets, a structural precedent beyond the terrestrial Critical Entities Resilience Directive (CER Directive) scope.
Critical Undersea Infrastructure Coordination Cell?
data-localisation mandates on traffic carried)?
multiple EEZs — flag-state, landing-state, or NIS2 critical-entity lead-supervisor?