The latest news and insights
The Real Cost of Rip-and-Replace Isn't the Removal. It's What You Replace It With
New GSMA research puts the price of removing high-risk vendors from European networks higher than earlier projections. It's a number worth sitting with — and it points to something operators may want to weigh carefully: much of the cost depends less on taking the old equipment out than on how the new equipment goes back in.
A bigger bill than anyone budgeted for
For years, the European conversation about high-risk vendors has been framed almost entirely around security and sovereignty. The EU 5G Toolbox and the NIS2 Directive gave member states a framework to assess supply-chain risk and, where necessary, phase out equipment from vendors deemed high-risk. The logic was about trust: who builds the most sensitive parts of the network, and under whose laws do they operate.
Recent GSMA Intelligence research adds a second dimension to that conversation — the price tag. According to the industry body, removing and replacing high-risk vendor equipment across European networks could cost in the region of €30–40 billion, above the roughly €10–13 billion the EU had projected. Most of that falls on mobile networks, with further billions across fixed and transport layers. It moves the debate from principle to practicality, and gives operators a clearer basis for planning.
The research also points to a second-order effect that is easy to overlook: as the vendor landscape shifts, the pool of remaining suppliers narrows — and less competition can mean higher prices. The GSMA estimates this could add billions more over the rest of the decade — a factor worth carrying into any modernisation plan.
That is a significant figure. And read carefully, it points somewhere useful — not just to how much replacement costs, but to how replacement is usually done.
Why the number is so large
A rip-and-replace programme is expensive for reasons that go well beyond the hardware itself. When core network functions are removed, everything that touched them has to be re-integrated, re-tested, and re-certified. If the incumbent equipment was part of a large, tightly coupled, single-vendor stack, that entanglement is precisely what makes untangling it so costly — you cannot lift out one piece without disturbing the rest.
And this is where the GSMA's figures are telling. If an operator responds to that entanglement by swapping one monolithic, single-vendor platform for another monolithic, single-vendor platform, it may spend a great deal to arrive close to where it started: locked in, dependent on one supplier's roadmap and pricing, and exposed to exactly the market concentration the GSMA points to. The security question may be answered. The structural one — the entanglement that made the removal so costly in the first place — can quietly re-emerge under a new logo.
The high cost of rip-and-replace, in other words, is not an argument against doing it. It's an argument for doing it differently.
Modularity changes the arithmetic
If the expense comes from tightly coupled, all-or-nothing architectures, then the way to reduce it is to stop replacing networks in all-or-nothing terms.
A modular core lets an operator address high-risk vendor exposure one function at a time, in the order that risk and budget dictate — rather than as a single, network-wide forklift event. The most exposed elements can be replaced first; the rest can follow at a pace the operator controls. Each component is standards-based and interworking-ready, so it integrates with what is already in place instead of demanding that everything around it change at once. The removal still happens, but it happens as a sequence of contained, testable steps rather than one enormous, high-risk migration.
This speaks directly to both parts of the cost picture the GSMA describes. The integration burden falls, because functions are swapped in isolation rather than as an entangled whole. And the operator is no longer at the mercy of a narrowing vendor pool, because a modular approach doesn't require betting the network on a single replacement supplier. Choosing where each function comes from is exactly what preserves the operator's leverage as the market consolidates.
The independence that matters twice
There is a reason this argument lands with particular force for European operators.
The GSMA's point about reduced competition is, at heart, a point about dependence: the fewer suppliers there are, the more weight each one carries over price and roadmap. An operator that replaces a high-risk vendor with a large, integrated Western vendor has addressed the sovereignty concern but not the dependence concern. It is still tied to a single supplier in a consolidating market.
A modular, European, independent specialist answers both at once. It is HRV-free and operates under European jurisdiction, with ISO/IEC 27001:2022 certification — which is what the regulation asks for. And because it slots into a multi-vendor architecture rather than replacing one lock-in with another, it keeps the operator's options open precisely as the market grows more concentrated. Independence, in this reading, isn't only about where a vendor is headquartered. It's about whether choosing that vendor leaves you with more freedom or less.
The takeaway
The GSMA's €30–40 billion figure will be read by many as a reason to hesitate. It is better read as a specification for how to proceed. The cost of rip-and-replace is real, but most of it is a cost of method — of treating a security-driven transition as a monolithic swap rather than a modular, self-paced evolution.
Operators facing high-risk vendor decisions don't have to choose between an expensive, disruptive migration and living with unacceptable risk. The third option is to modernise the way the architecture should have been allowed all along: component by component, at the network's own pace, without trading one dependence for another. Done that way, addressing high-risk vendors stops being a bill to dread and becomes a chance to build a network that is not only compliant, but genuinely harder to lock in ever again.
Summa Networks is a European, independent provider of modular, cloud-native core network solutions for Mobile, IoT, and Private Networks, certified to ISO/IEC 27001:2022 — built for operators modernising legacy and high-risk vendor infrastructure at their own pace, without vendor lock-in.
Explore our approach to rip-and-replace
Source: GSMA Intelligence, The cost of removing designated third-country vendors from EU telecoms networks (July 2026; full report available via registration). Figures also reported by Politico Europe and Mobile World Live.
Latest Blog
The Pre-Activated Advantage: Why You Shouldn't Pay Full Price for Inactive Subscribers