Logo Teldat
European Regulatory Compliance – Public Sector – Sovereignty as a Security Measure

For the past decade, European or EU cybersecurity regulations have focused on asking public administrations what they do: what policies they have in place, what risks they’ve assessed, and how they report an incident. The new regulatory framework asks something different: what technology they have installed, and who built it.

This change in what’s being asked matters more than any timeline. European regulatory compliance in the public sector is no longer merely a paperwork exercise; it is becoming the result of architectural and procurement decisions.

EU cybersecurity compliance - sovereignty security - nis2 - cyber resilience act - Cybersecurity Made in Europe

Sovereignty is no longer a matter of preference

NIS2 marked an earlier stage in this regulatory shift. Its focus is on how an organization governs its own risk: management measures, notification deadlines, and the responsibility of the governing body.

The proposed revision of the Cybersecurity Act introduces a horizontal ICT supply chain security framework that would allow critical assets to be identified and components from high-risk suppliers to be gradually restricted or phased out.

In some tenders, European technology was little more than a stated preference, with no real technical weight behind it. The direction taken by European lawmakers turns this preference into an assessable security measure, with implications for what can continue to be used and for how long. The proposal is still going through the legislative process, and its final wording will likely change but the direction it’s taking leaves no room for doubt.

Network equipment in the public sector is typically procured on a five-to-seven-year horizon, while the European regulatory framework is being rewritten in two- to three-year cycles. Any deployment approved this year will have to comply with rules that are still being negotiated. Do you want to decide when to make this transition, or would you rather let the new legislation decide for you?

 

EU cybersecurity compliance isn’t about separate audits; it’s about architecture

NIS2, the Cyber Resilience Act, and the revision of the Cybersecurity Act are drafted, monitored, and audited independently. Yet they all share the same objective: to demonstrate, with evidence, what’s happening inside the network and what’s installed on it.

This capability cannot be bought as a product. It depends on whether the network can be managed as a whole. A public administration with centralized visibility across its headquarters, branch offices, and cloud environments can produce that evidence within hours. One managing twenty independent silos cannot, even if it has acquired exactly the same tools.

Segmentation works in the same way. It contains what visibility detects and prevents a compromised device in one office from disrupting services to citizens. Data residency also ceases to be merely a contractual clause and becomes a declared, verifiable measure.

Teldat is working on this concept under the name “geostratified cyberdefense”: control exercised at every layer of the network, treating the origin of the technology as yet another security measure.

What you buy determines what you can prove?

The Cyber Resilience Act introduces the most practical change of all, and it targets the manufacturer rather than the public administration. It requires actively exploited vulnerabilities and serious incidents to be reported within tight timeframes, and requires a product to meet essential security requirements throughout its entire lifecycle in order to be sold on the European market.

From the public buyer’s perspective, this turns the security of the installed base into a documented property of the equipment: evidence of compliance, vulnerability management, and a declared support period. The manufacturer’s disclosure practices also become part of the public body’s own notification schedule, because a late warning leaves it no leeway to meet its own deadlines.

Supplier assurances are also no longer provided just once at the bidding stage: they must be maintained throughout the term of the contract. This changes the conversation with the manufacturer, because what it declares in its bid matters less than what it can prove each year.

Cryptography is the clearest example

Encrypted traffic captured today can be stored and decrypted later, when quantum computing becomes capable of doing so. For data with confidentiality requirements spanning decades, precisely what the public sector is entrusted with safeguarding, the exposure isn’t a future risk, but a present one.

Europe has responded with a phased roadmap that begins with high-risk systems. Here, the same pattern emerges again: retrofitting cryptography across thousands of locations is a slow process, so the transition needs to be designed into the network rather than added later.

Teldat has been working in this area with Quantum-Safe SD-WAN, integrating ML-KEM for post-quantum key exchange alongside PS-PPK, an approach recognized with a Redes&Telecom award for post-quantum connectivity. Once again, what matters to a public-sector buyer is the architecture: an organization managing its SD-WAN from a unified console can plan a cryptographic migration; one managing it site by site cannot.

Compliance is the measurable side of sovereignty

Regulatory sanctions are the least compelling reason to do all this. Europe legislates in this area because public services must continue to function, citizens’ data must remain protected, and the continent needs to retain control over the infrastructure on which it depends.

Teldat is built for this role. Europe’s largest SD-WAN deployment, with more than 12,000 nodes in the Andalusian Regional Government, runs on its technology, as does the network security for more than 90% of the Spanish banking sector. GigaOm’s Firewall Radar identified Teldat as the only European manufacturer in this category, and its suite of certifications includes NATO Restricted, ENS High, CPSTIC qualification and approval, and the “Cybersecurity Made in Europe” seal.

Changing the architecture on your own terms is a project. Changing it when regulation forces you to, with the entire market doing so at once, is an urgent undertaking, with prices and deadlines beyond your control.

Related Posts 

Secure SD-Branch SASE Convergence

Secure SD-Branch SASE Convergence

For years, branch networking and enterprise security evolved independently, each with its own infrastructure, devices, and management consoles. However, widespread cloud adoption, the rise of SaaS applications, and the shift to remote work have...

read more