On 19 March 2026, Advocate-General Capeta issued an opinion in the case of Elisa Eesti AS v Estonian Government Security Committee (C-354/24). This case concerned, among other things, whether a 2022 order from the Estonian Government for Elisa Eesti AS—a 5G network operator—to remove Huawei components from its network for national security reasons was subject to EU law, constituted a lawful restriction on the right to offer an electronic communications network, and amounted to a “deprivation of property” requiring compensation.
AG Capeta concluded that the relevant Estonian regime was within scope of EU law—specifically the European Electronic Communications Code (“EECC”)—even though that regime allowed for the imposition of orders on electronic communications network (“ECN”) providers for national security reasons. She also concluded that the requirement to obtain prior authorization from the Estonian government for use of network equipment constituted a restriction on the freedom to provide an ECN, but that this could be justified on national security grounds if the decision was based on a genuine risk assessment that meets the requirements for proportionality under EU law. She stated that this determination should be left to the referring court. Finally, she concluded that the Estonian Government’s order did not amount to a “deprivation” of property for which compensation would be required, as it was instead a mere “restriction” on the use of property.
Below, we describe these non-binding conclusions in more detail. The Court’s final ruling in this case will have significant implications for the European Commission’s proposed revisions to the EU Cybersecurity Act, which as drafted would—among other things—allow the Commission to require ECN providers to remove and cease using components from designated high-risk jurisdictions in their networks. See our prior blog post on the proposal for a revised Cybersecurity Act here.
Estonia’s implementation of the EECC included an ex ante authorisation system requiring ECN providers to obtain government approval for hardware and software prior to deploying it in their networks. Under this framework, the Estonian government concluded that Huawei, among others, was a “high‑risk” vendor on the basis that use of its equipment could harm national security. The Estonian government therefore only granted permits for Elisa Eesti AS to use Huawei equipment in its networks for a limited time only—effectively requiring it to strip Huawei equipment from its networks by set dates.
Elisa Eesti AS challenged these decisions and the underlying regime, which led the Estonian courts to refer several questions to the CJEU. AG Capeta’s main conclusions were:
The CJEU’s final judgment in this case will be one for ECN providers to watch closely, particularly in light of the ongoing negotiations on revisions to the Cybersecurity Act, which would provide for an EU-wide mechanism to remove high-risk providers’ components from ECNs.
* * *
Covington’s Privacy and Cybersecurity team continues to monitor developments in this case and on the proposed changes to the Cybersecurity Act. If you would like support assessing how this case or changes to the law may affect your organization, please let us know.