In January 2026, the European Commission unveiled its plan to overhaul the EU's Cybersecurity Act, a proposal now known as CSA2. It's the natural next step in a story that began years earlier with the EU's 2020 "5G Security Toolbox" - a set of voluntary recommendations encouraging Member States to be cautious about certain telecom suppliers. That voluntary approach produced patchy results: by most accounts, fewer than half of EU countries had actually acted on those recommendations. It is worth asking whether the adoption levels were however a failure of design, or a reflection of Member States reaching different conclusions about their risk exposures.