Research method and policy status, reviewed July 29, 2026: This analysis uses primary documents from the FCC, U.S. Bureau of Industry and Security, European Commission, UK government and UK National Cyber Security Centre. It distinguishes enacted restrictions from proposals and telecom security from semiconductor export controls. No Huawei or SMIC product was independently laboratory-tested for this article. Government risk assessments are attributed as assessments, not presented as public proof of a product compromise. Buyers should confirm current rules before contracting.

Why Do Europe and the United States Restrict Huawei and SMIC? Is It Bias?

Why do governments in Europe and the United States discourage or restrict products associated with Huawei and Semiconductor Manufacturing International Corporation, better known as SMIC? Is the concern based on engineering evidence, or is it prejudice against Chinese companies?

The short answer is that the issue contains both legitimate security questions and political judgement. Huawei supplies equipment that can sit inside mobile and fixed communications networks. SMIC is primarily a semiconductor foundry, not a conventional telecom equipment vendor. Western measures therefore address different risks. Some are based on published technical findings, supply-chain exposure and national-security law. Others depend partly on classified assessments that outside buyers cannot independently test. Treating every Chinese product as unsafe would be prejudice; assessing a supplier’s access, legal jurisdiction and role in critical infrastructure is ordinary risk management.

There is no single Western rule. The United States, the European Union, European national governments and the United Kingdom apply different measures. A public mobile core, a police radio network, a private factory network and a solar power cabinet also present different risks.

Start With a Correction: Huawei and SMIC Are Not the Same Type of Supplier

Huawei designs and supplies telecom network equipment, enterprise networking products, cloud systems, handsets and related software. Depending on the deployment, its products may process traffic, manage network functions, receive remote updates or provide operational visibility into critical infrastructure.

SMIC manufactures integrated circuits for other companies. A chip made by SMIC might appear inside communications, industrial or consumer equipment, but SMIC does not generally sell a complete 5G radio access network or mobile core to an operator. Calling SMIC a telecom equipment supplier confuses the component-manufacturing layer with the network-vendor layer.

Question Huawei SMIC
Primary role Telecom and information-technology equipment and services Semiconductor foundry and chip-manufacturing services
Main Western policy concern Critical-network access, supplier influence, software assurance and dependence Access to advanced manufacturing technology, military end use and strategic chip capacity
Typical buyer impact Restrictions on procurement, deployment, authorization or continued use in specified networks Export-licence checks, component-origin review and possible supply disruption
Is it on the FCC Covered List? Huawei telecommunications equipment and services are included SMIC is not listed there as a telecom equipment provider
Is it on the U.S. Commerce Entity List? Huawei entities are subject to U.S. export controls SMIC and specified related entities are subject to U.S. export controls

This distinction matters during procurement. A rule that excludes Huawei from a public 5G core does not automatically prohibit every industrial device containing a chip fabricated in China. Conversely, a product that is not prohibited by name can still fail a customer’s security, funding or supply-chain requirements.

What the United States Actually Restricts

Huawei: communications equipment and market access

The United States has taken the more categorical position. The FCC Covered List dated May 18, 2026 includes telecommunications equipment and services produced or provided by Huawei and its subsidiaries or affiliates. FCC rules have also blocked authorization of new covered equipment.

On June 26, 2026, the FCC went further by prohibiting continued importation and marketing of certain previously authorized covered communications equipment added to the list in 2024 or earlier. The notice says this action does not prevent the continued use or operation of equipment already purchased. That is a good example of why “Huawei is banned” needs qualification: authorization, import, marketing, federal support, new deployment and continued operation are separate legal questions.

Huawei is also affected by U.S. Commerce Department export controls. These measures restrict access to specified U.S.-origin items and, in some circumstances, foreign-produced items derived from controlled U.S. technology. The practical effect reaches beyond American buyers because global electronics supply chains use U.S. software, intellectual property and manufacturing equipment.

SMIC: technology transfer rather than a telecom-equipment ban

SMIC and several related entities were added to the U.S. Commerce Department’s Entity List in December 2020. A 2026 Commerce Department enforcement document describes SMIC as a partially state-owned semiconductor foundry and states that exports, re-exports or in-country transfers of items subject to the Export Administration Regulations require a licence. It attributes the listing to U.S. concerns about China’s military-civil fusion policy and activities involving entities in the Chinese military-industrial complex.

The Bureau of Industry and Security’s enforcement explanation illustrates what this means in practice: companies must screen not only SMIC itself but also listed related parties. This is principally a control on supplying regulated technology to those entities. It is not the same as an FCC declaration that every finished product containing an SMIC-fabricated chip is prohibited in the United States.

For a buyer, the questions are more specific. Is the chip or equipment subject to an applicable import, procurement or funding restriction? Can the supplier lawfully obtain replacement parts and design tools? Will an export licence be needed for maintenance? Does the contract allocate the risk of a future rule change? Those questions are more useful than asking whether SMIC is “allowed” in the abstract.

Europe Does Not Have One Uniform Huawei Policy

Europe is often described as if it had copied the United States, but the legal picture is more fragmented. National security remains largely a Member State responsibility. Some countries have imposed strong restrictions, some use authorization procedures for sensitive network components, and others have moved more slowly.

At EU level, the 5G Cybersecurity Toolbox established a risk-based framework. It considers both technical and non-technical factors, including a supplier’s governance, the possibility of influence by a non-EU state, and the danger of excessive dependence. In 2023, the European Commission stated that Huawei and ZTE present materially higher risks than other 5G suppliers and regarded Member State decisions to restrict or exclude them as justified under the toolbox.

In January 2026, the Commission proposed revising the EU Cybersecurity Act to create a more consistent approach to high-risk suppliers and a three-year phase-out for affected 5G equipment. At the time of this article’s review, that measure was a proposal, not a sentence that every European operator could treat as already enacted law. The distinction between a Commission proposal, an EU regulation in force and a national restriction should remain visible in any tender.

The United Kingdom has a clearer vendor-specific requirement. Legal directions issued to public communications providers require Huawei equipment to be removed from UK 5G networks by the end of 2027. The UK government’s Huawei notice also records earlier controls on network cores, access-network concentration and nationally significant sites.

There is no comparable Europe-wide declaration that SMIC is a prohibited telecom network vendor. European companies can still be affected by U.S. export controls, their own national security rules, EU sanctions or customer-specific supply-chain clauses. Again, the effect depends on the transaction rather than the company name alone.

Why Governments Treat Some Telecom Suppliers as High Risk

A network vendor can hold privileged access

A telecom supplier may provide software updates, remote diagnostics, network-management systems, maintenance accounts and security patches. In a mobile core or government network, those privileges can be more consequential than the country printed on the equipment label. A compromised vendor account or malicious update could affect many sites at once.

This does not prove that a named supplier has installed a backdoor. It explains why governments assess capability and access, not only documented incidents. Security planning asks what a supplier could do if compromised, coerced or cut off from support.

Legal jurisdiction changes the trust calculation

Western assessments frequently refer to the possibility that a supplier headquartered in China could face obligations under Chinese national-security and intelligence laws. Chinese companies dispute claims that they would provide unauthorized access and argue that they comply with the laws of the countries where they operate.

Both statements can be true at the level of corporate policy, yet a government may still decide that conflicting jurisdictions create an unacceptable residual risk. The same logic can apply to data hosted under U.S. law, Russian security software, or any foreign supplier serving sensitive infrastructure. A fair policy should apply comparable tests to comparable access.

Published engineering concerns exist, but they are not the whole argument

The debate is not based only on nationality. The UK’s Huawei Cyber Security Evaluation Centre reviewed Huawei products for years. The National Cyber Security Centre reported recurring concerns about software engineering, product quality, component traceability and opaque processes. Its high-risk-vendor guidance also explained why U.S. sanctions made future product assurance harder: Huawei would need to change parts of its technology and supply chain that UK evaluators already understood.

These are genuine assurance findings. They are not, by themselves, public proof that every Huawei device contains intentional espionage functionality. Much of the broader national-security case rests on threat modelling and classified intelligence that ordinary operators cannot inspect. That gap is one reason the policy continues to be contested.

Dependence can be dangerous even without malicious behaviour

A single supplier can become a resilience problem through ordinary commercial events: sanctions, bankruptcy, discontinued components, unavailable patches or a political dispute. Removing an embedded radio vendor is expensive because antennas, radios, management software and operating procedures are tightly connected.

The UK’s decision itself demonstrates this trade-off. Authorities set a multi-year removal schedule partly because an abrupt replacement could disrupt networks. Supplier diversity, spare-parts availability and an executable exit plan are therefore security controls, not merely purchasing preferences.

Semiconductor controls pursue a wider strategic goal

Advanced chips support artificial intelligence, surveillance, cryptography, weapons, telecommunications and ordinary commercial systems. U.S. policy toward SMIC is concerned with the manufacturing capability behind those applications. The government seeks to limit access to selected tools, technology and know-how that could support advanced production or military end uses.

That makes SMIC policy more geopolitical than a product vulnerability assessment. A foundry does not need remote access to a telecom tower to become strategically important. Control over semiconductor capacity affects who can build future communications and computing systems.

So, Is It Bias?

A useful answer needs more than “yes” or “no.”

It is not automatically prejudice to apply stricter controls to a supplier with privileged network access, unresolved engineering findings, exposure to a foreign legal system and a role in critical infrastructure. Governments are expected to consider low-probability events with national consequences. They do not need to wait for a catastrophic breach before reducing a dependency.

It can become prejudice when country of origin replaces evidence entirely; when passive hardware is treated like a remotely managed core network; when a Chinese supplier is required to meet controls that comparable suppliers from allied countries avoid; or when no transparent appeal, testing or mitigation path exists. Economic protectionism can also hide inside security language.

Sign of a defensible risk decision Sign of possible bias or protectionism
The rule identifies the network function and consequence being protected The decision treats every product from one country as equally dangerous
Suppliers are tested against published technical and governance criteria Requirements change according to the preferred supplier’s nationality
Restrictions are proportionate to access, data and criticality A passive component receives the same treatment as a remotely managed core
Independent testing, mitigation or appeal is available where risk permits No evidence threshold or review route is disclosed
Concentration and exit risk are assessed for every major vendor The policy replaces one dependency with another and calls the problem solved

Huawei has consistently rejected allegations that it presents a security threat and has argued that restrictions based on origin rather than technical evidence are discriminatory. SMIC has also disputed allegations of military ties. Those responses belong in an objective analysis. So does the fact that several governments, after technical and intelligence review, reached a different risk judgement.

The honest conclusion is narrower: the restrictions cannot be dismissed as pure prejudice, but neither should every government assertion be treated as public technical proof. Buyers still need to examine the actual product, access model, customer requirement and governing law.

A Better Procurement Test Than “Chinese or Not Chinese”

For a private network or overseas infrastructure project, begin with the system’s trust boundaries. Mark which equipment carries subscriber traffic, holds encryption keys, can change radio parameters, reaches the core network, receives remote commands or stores operational data. Then review the supplier controls for those functions.

  1. Check the law and funding conditions. Screen the exact legal entity, subsidiaries, product category, end user and end use. A distributor’s statement is not a legal determination.
  2. Classify the function. Core-network software, radio management, passive antennas, chips, batteries and solar controllers do not create the same exposure.
  3. Map every remote connection. Record destinations, protocols, ports, credentials, support accounts, cloud dependencies and the customer’s ability to disable access.
  4. Demand software and hardware transparency. Request an SBOM, critical-component list, firmware-signing method, vulnerability-disclosure policy and supported-lifetime schedule.
  5. Test rather than assume. Use an independent laboratory or customer-controlled acceptance environment for firmware behaviour, traffic capture, update validation and failure testing.
  6. Separate management planes. Keep power, environmental monitoring and vendor maintenance networks away from subscriber, dispatch and core-network traffic.
  7. Control data location. Specify what leaves the site, where it is stored, who can read it and how access is logged and revoked.
  8. Plan the exit before installation. Define configuration export, replacement interfaces, spare parts, source-code or key escrow where justified, and assistance obligations after termination.
  9. Avoid hidden concentration. Two product brands may still rely on the same chipset, cloud service, code library or contract manufacturer.
  10. Reassess after sanctions or ownership changes. A supplier that passed review three years ago may now depend on different components, developers or support routes.

What This Means for Solar Power and Battery Systems at Telecom Sites

A solar array, battery cabinet or rectifier is not automatically part of the radio access network merely because it stands inside a tower compound. Most power equipment does not process subscriber calls or mobile-core data. Its cyber risk depends on the control design.

A network-connected energy controller can still affect availability. It may be able to stop charging, change generator logic, suppress alarms or disconnect a load. For police, emergency, railway or mobile networks, loss of power is a communications incident even if no subscriber data is exposed.

This is where proportionate architecture helps. Telecom teams evaluating solar telecom power systems should require local autonomous control, documented interfaces, customer-owned credentials, segmented monitoring, signed firmware, event logs and a mode that continues serving the load when the remote platform is unavailable. A Chinese-manufactured power system that meets these controls may present less network exposure than a Western-branded device with permanent, undocumented cloud access.

The country of manufacture still matters for sanctions, public procurement, component continuity and support. It should be one field in the risk register, not the entire risk register.

Telecom-site asset Primary concern Reasonable control
Passive PV modules and mounting Product compliance, structural safety and supply continuity Certification review, traceable components and inspection
Battery and local BMS Safety, shutdown authority and firmware integrity Local protection, signed updates, service access control and event records
Hybrid controller or inverter Remote commands and impact on power availability Network segmentation, allow-listed connections and customer-controlled fallback
Site monitoring gateway Data export and pathway into operational networks One-way or tightly controlled interfaces, encryption, logs and independent testing
RAN or core-network equipment Traffic, keys, management privileges and large-scale network control Highest assurance level plus applicable national vendor restrictions

Frequently Asked Questions

Is Huawei banned throughout Europe?

No. The European Commission has classified Huawei as a materially higher-risk 5G supplier and supports Member State restrictions, but national implementation has varied. A 2026 Commission proposal seeks a more uniform phase-out of high-risk suppliers; buyers should verify whether and when final rules apply in their jurisdiction.

Is Huawei equipment proven to contain government backdoors?

Public government documents identify engineering, assurance, legal-jurisdiction and supply-chain risks. They do not provide publicly verifiable proof that every Huawei product contains an intentional backdoor. The policy case is based largely on risk and potential impact, not only on proof of a specific compromise.

Is SMIC a telecommunications equipment company?

Not in the usual sense. SMIC is a semiconductor foundry. Its chips may enter telecom products, but U.S. restrictions on SMIC primarily govern exports and transfers of regulated technology to the company and listed related entities.

Are all communications products made in China unsafe?

No. Security depends on function, design, vulnerabilities, supplier access, update controls, legal obligations and customer operation. Nationality can affect jurisdiction and supply-chain risk, but it does not replace product assessment.

Can technical controls remove all geopolitical risk?

No. Segmentation, testing and local control can reduce operational and cyber risk. They cannot override a legal prohibition, guarantee future component availability or eliminate the possibility of new sanctions.

Should a private operator copy government restrictions?

Not automatically. Government networks may face different threats and statutory duties. A private buyer should start with applicable law and customer requirements, then document its own consequence, access and continuity assessment.

The Question to Ask Before the Next Tender

Do not ask only whether a supplier is Chinese, European or American. Ask what the product can control, what data it can see, who can update it, which laws reach the supplier, how independently its claims can be tested, and how the network will continue if that supplier disappears tomorrow. If a bidder cannot answer those questions clearly, the logo on the cabinet is not the main problem.

This article provides general policy, cybersecurity and procurement information. It is not legal advice, export-control advice or a determination that a particular product is permitted for a particular customer.