The Opinion of Advocate General Ćapeta in Case C-354/24, Elisa Eesti AS v Vabariigi Valitsuse julgeolekukomisjoni küberjulgeoleku nõukogu and Tarbijakaitse ja Tehnilise Järelevalve Amet, addresses one of the most politically sensitive and legally significant questions currently facing the European Union: the relationship between national security and the EU internal market in the context of 5G telecommunications infrastructure. The dispute arose after the Estonian authorities adopted legislation requiring prior authorisation for the use of hardware and software in electronic communications networks on grounds of national security. Pursuant to that framework, the Estonian authorities, the Office of Consumer Protection and Technical Supervision (‘the TJA’) and the Cybersecurity Council of the Security Committee (‘the KJN’), classified equipment produced by Huawei as “high risk” and limited its use in Elisa Eesti’s telecommunications network. Elisa Eesti challenged those decisions before the Estonian Administrative Court, arguing inter alia that the restrictions infringed EU law, particularly the European Electronic Communications Code (EECC), the freedom to provide electronic communications services, and the right to property under Article 17 of the Charter.
The Opinion is significant in several respects. At first glance, the case may appear to concern a technical dispute over telecom equipment and authorisation procedures. However, its implications are much broader. It sits at the intersection of 5G infrastructure, national security, internal market law, and fundamental rights. In this short article, I will focus on four aspects of the Opinion: (i) its explanation of the technical foundations of 5G infrastructure; (ii) its clarification of the scope of the EECC and the constitutional limits of national security arguments; (iii) its treatment of soft law and risk assessment in the judicial review of 5G security measures; and (iv) its analysis of restrictions on the right to property through the lens of proportionality.
- Technical Foundations of 5G Infrastructure
Before engaging with the substance of the questions referred, Advocate General Ćapeta first outlines the functionality of 5G infrastructure and explains the two principal components of a mobile telecommunications network: (i) the core network, which centrally controls and manages the entire network and serves as the main conduit for the transmission and aggregation of network traffic, and (ii) the mobile radio network, also referred to as the “edge” network, which consists of base stations enabling devices to connect to the network. Furthermore, she distinguishes between “non-stand-alone 5G” and “stand-alone 5G” functionality. While non-stand-alone 5G operates on top of the existing 2G-4G infrastructure and therefore continues to rely on the traditional core network, stand-alone 5G establishes an independent radio network architecture capable of direct device-to-device communication without depending on the pre-existing core infrastructure (paras 5-9). In this regard, the present dispute concerns only the mobile radio network, namely the “edge” network, rather than the core network infrastructure, and more specifically the applicant’s use of hardware and software manufactured by the Chinese company Huawei within that network (paras 10-11).
- The Advocate General Ćapeta’s Opinion
The referring court (Administrative Court, Tallinn) referred six questions to the Court of Justice for a preliminary ruling concerning the relationship between national security measures and EU telecommunications law. In essence, the referring court asked: first, whether Estonian legislation requiring prior authorisation for the use of hardware and software in communications networks falls within the scope of the EECC; second, whether restrictions adopted on grounds of national security fall within the exclusive competence of the Member States and therefore constitute purely national measures excluded from the scope of the EECC pursuant to Article 4(2) TEU and Article 1(3)(c) EECC; third, whether such an authorisation system constitutes a restriction on the freedom to provide electronic communications networks and services under Article 12(1) EECC; fourth, whether the alleged failure to notify those national measures to the European Commission renders them inapplicable; fifth, whether the Estonian framework complies with the principle of proportionality, particularly regarding the assessment of risks associated with “high-risk” suppliers such as Huawei; and finally, whether limiting the use of existing telecommunications equipment for a period shorter than its useful life amounts to a deprivation of property under the second sentence of Article 17(1) of the Charter.
2.1 The EECC and the Constitutional Limits of National Security
Regarding the first question, the Advocate General answers in the affirmative, explaining that the EECC applies to national measures aimed at ensuring the security of electronic communications networks and services. Since the EECC expressly requires Member States to adopt appropriate and proportionate technical and organisational measures to manage security risks, national rules regulating the use of hardware and software in telecommunications networks fall within its ratione materiae scope. She further clarifies that the concept of “security of network” covers both hardware and software elements of electronic communications infrastructure, thereby encompassing the Huawei equipment at issue in the case (paras. 36-41).
Regarding the second question, namely whether restrictions adopted on grounds of national security fall within the exclusive competence of the Member States and therefore constitute purely national measures excluded from the scope of the EECC pursuant to Article 4(2) TEU and Article 1(3)(c) EECC, the Advocate General relies on the Court’s established case-law clarifying that Article 4(2) TEU does not remove national security measures from the scope of EU law. Referring to the Court’s recent judgment in Protectus, she reiterates that “the mere fact that a national measure has been taken for the purpose of protecting national security cannot render EU law inapplicable and exempt the Member States from the need to comply with EU law” ( para. 55; see also Protectus, C-185/23, EU:C:2024:657, Judgment of 29 July 2024, para. 62). Accordingly, although national security remains the sole responsibility of the Member States, measures adopted in pursuit of that objective must nevertheless comply with the requirements of EU law, including the EECC. In other words, “Article 4(2) does not give a carte blanche to the Member States nor does it have a higher value than other constitutional treaty provisions” (Hartley and Tridimas, The Foundations of European Union Law OUP 2026, 373).
The third question concerns the legal nature of the authorisation regime and asks whether a national measure requiring prior authorisation for the use of hardware and software should be regarded as a condition for the provision of electronic communications networks and services, or instead as a restriction on the freedom to provide such networks and services under Article 12(1) of the EECC (para. 65). Through its interpretation of Article 12(1), the Advocate General explains that the provision reflects both negative and positive integration: it prohibits obstacles to the freedom to provide electronic communications networks and services, while simultaneously harmonising the objective of ensuring security as a condition for the provision of electronic communications networks and services (paras. 67-70). In this regard, although security itself constitutes a condition under the EECC, the specific national measures adopted to ensure that security, such as the prior authorisation requirement at issue, do not qualify as conditions for the provision of networks and services, but may instead amount to restrictions that can be justified on the grounds set out in Article 52(1) TFEU (paras. 76-81).
In reply to the fourth question, the Advocate General concludes that a national measure requiring prior authorisation for the use of hardware and software in electronic communications networks constitutes a restriction under Article 12(1) of EECC and should therefore be notified to the Commission. However, unlike the notification procedure under the TRIS Directive, failure to notify such a measure under Article 12(1) EECC does not render the national rules inapplicable, because Article 12(1) does not make the applicability of national measures conditional upon prior Commission approval or the expiry of a minimum time period (para. 93).
2.2 The Role of Soft Law in Judicial Review and the Risk Assessment in 5G Technology
In addressing the fifth question, the Advocate General reformulates the issue in light of the applicability of the EECC and examines whether a prior authorisation regime restricting the use of telecommunications hardware and software can be justified under Article 12(1) EECC read together with Article 52(1) TFEU. She recognises that the security of electronic communications networks constitutes a legitimate objective linked to public and national security and may therefore justify restrictions on the freedom to provide electronic communications networks and services. Furthermore, she notes that, “it is not disputed that security of communications networks is of considerable importance in contemporary democratic societies: a secure and trustworthy telecommunications infrastructure is not only necessary for the effective exercise of a number of EU values and fundamental rights, including the value of democracy and the freedom of expression, it also ensures social stability given that the influence over, or the disruption to, a Member States’ telecommunications infrastructure may affect other sectors of the economy and everyday life of EU citizens more generally.” (para. 104).
However, such restrictions are compatible with EU law only where the competent national authorities conduct a specific assessment of the risks posed by the hardware and software at issue: “that analysis may involve, for example, risks related to the type of equipment at issue, the manufacturer of that equipment, or the State within which that manufacturer is established” (para. 110).
In this respect, the Advocate General emphasises that the assessment of risks linked to a specific manufacturer, its equipment, or the use of that equipment involves complex technical, political, and security considerations that cannot themselves be carried out by the EU Courts. Nevertheless, where national courts review measures prohibiting the use of certain hardware and software on national security grounds, the competent authorities must still provide reasonable explanations supporting their finding of a genuine risk and, where necessary, courts may rely on different judicial techniques in order to examine sensitive security information (para. 114).
In this regard, she observes that the Estonian Government relied on several EU soft law instruments, including the Commission’s 2019 Cybersecurity Recommendation, the Coordinated Risk Assessments and 5G Toolbox by the NIS Cooperation Group, and the Commission’s Communication on the implementation of the 5G Toolbox. Although non-binding, those instruments were considered relevant because they reflected a coordinated EU-level assessment identifying suppliers such as Huawei as presenting materially higher risks to the security of 5G networks (paras. 116-117).
2.3 Limitation Regime of the Right to Property and the Proportionality Assessment
In response to the sixth question, the Advocate General concludes that the contested measures do not amount to a deprivation of property under Article 17(1) of the Charter, since there was no interference with the essence of the applicant’s property rights. Rather, the measures constitute a limitation on the use of property justified by the general interest within the meaning of the third sentence of Article 17(1) of the Charter (para 129). She further explains that the proportionality assessment requires the referring court to consider several factors. First, the court must determine whether the applicant was given sufficient time to adapt to the new legal framework. This assessment should take into account the entire period available to the applicant, beginning when the ESS amendments were first proposed and ending with the final deadline for the use of the hardware and software at issue. If that period was insufficient, the court should consider whether reasonable compensation is required (paras 133-135). Second, the referring court must also assess whether the interference with the applicant’s property rights was proportionate to the objective pursued, taking into account network security interests and the market risks that a prudent operator could reasonably have anticipated. If the burden was disproportionately heavy, reasonable compensation may be appropriate (paras 136-137).
- Concluding Remarks
The Advocate General’s Opinion is particularly significant for four reasons. First, it demonstrates that meaningful judicial engagement with disputes concerning advanced technologies such as 5G infrastructure requires at least a basic understanding of the underlying technology itself. In this sense, the Opinion demonstrates that technological context is a necessary starting point. Second, the Opinion clarifies the constitutional limits of Member States’ reliance on Article 4(2) TEU by reaffirming that, although national security remains the sole responsibility of the Member States, national security measures do not thereby escape the application of EU law. Furthermore, the Opinion recognises the exceptional importance of telecommunications infrastructure for modern democratic societies, emphasising that secure communications networks are essential not only for economic stability but also for the protection of democratic values and fundamental rights.
Third, it highlights the growing practical importance of EU soft law instruments, especially the 5G Toolbox framework and coordinated cybersecurity assessments, in shaping national risk assessments and judicial review. Finally, with its guidance on the proportionality assessment, it clarifies the limitation regime of the right to property within the meaning of the third sentence of Article 17(1) of EU Charter. The Opinion therefore sits at the intersection of EU internal market law, national security, and constitutional principles concerning fundamental rights and judicial review. More broadly, it also enhances the culture of justification in EU telecommunications law. National security is not treated as a jurisdictional escape route capable of removing national measures from the reach of EU law or judicial review. Instead, even where a Member State invokes security concerns in relation to 5G Infrastructure, it must explain why the measure is necessary, how the identified risk is genuine, and why the restriction imposed on a fundamental right is proportionate.