Brussels — A joint guidance package released this week by the European Union Agency for Cybersecurity (ENISA) and a coalition of major European carriers sets new expectations for zero‑trust controls at cross‑border network interconnects, a move industry observers say could reshape how telecom operators and enterprise cloud providers handle lateral access and supplier relationships.

What the guidance covers

The guidance — presented as a set of operational requirements, recommended architectures and phased compliance timelines — targets three high‑risk areas: inter‑operator peering and transit links, cloud and SaaS connector points, and third‑party maintenance access into network management systems. Key measures include:

  • Network microsegmentation around interconnect points to enforce least‑privilege flows between administrative domains.
  • Mutual strong authentication of control and data plane sessions using cryptographically anchored device identities (hardware or TPM‑backed where available).
  • Continuous authorization: session re‑evaluation based on telemetry and posture signals rather than one‑time authentication.
  • Standardized telemetry schemas and secure telemetry exchange channels, aimed at enabling rapid detection of cross‑domain anomalies.
  • Supplier access constraints requiring ephemeral, policy‑governed access tokens and session recording for all third‑party maintenance and orchestration sessions.

The document frames these controls within a zero‑trust model — "never trust, always verify" — but emphasizes operational practicality for network operators, providing example policy flows, enforcement points and vendor‑neutral reference architectures intended to work with ZTNA gateways, segment firewalls and service mesh technologies where appropriate.

Why cross‑border interconnects now

European operators have faced a growing threat surface as traffic increasingly traverses public cloud fabrics and third‑party IX (Internet Exchange) services. ENISA’s guidance argues that traditional perimeter‑centric protections are ineffective where multi‑jurisdictional routing, outsourced maintenance and aggregated BGP peering introduce lateral risk.

The timing amplifies regulatory pressure: NIS2 implementation across EU member states and recent high‑profile outages tied to misconfigurations at interconnect points have raised scrutiny from national regulators. While the guidance itself is not a binding regulation, ENISA explicitly designed it to inform supervisory expectations under existing and emerging cybersecurity laws.

Phased compliance and practical allowances

Recognizing operational complexity, the guidance proposes a staggered compliance approach. Core carrier backbone interconnects are in the first tranche, with a 12–18 month window for baseline controls such as mutual authentication and segmentation. More operationally disruptive measures — fine‑grained continuous authorization and telemetry federation — move to later tranches with 24–36 month timelines.

ENISA also provides “graded” implementation options: minimal, recommended and stringent profiles, allowing smaller operators and national incumbents with legacy gear to select feasible baselines while setting a path to the stringent profile used by large transit and cloud interconnect providers.

Industry reaction

Responses from across the telecom and security ecosystem were brisk. Several pan‑European carrier groups signaled support, saying the guidance provides much‑needed harmonization for cross‑border risk management. Cloud providers noted the need for better interoperability at the policy and telemetry level but cautioned about the operational cost of retrofitting legacy interconnect systems.

Vendors that supply network orchestration and policy control plane products welcomed the clearer procurement drivers. “Standardized telemetry formats and a focus on cryptographic device identity will accelerate interoperability,” said a senior engineer at a leading network automation firm. “But operators will need transition tooling to avoid service disruption.”

Privacy advocates and civil society groups raised procedural concerns about telemetry sharing between operators across borders, urging strict limits, data minimization and independent oversight of any cross‑operator behavioral analytics.

What this means for zero‑trust networking

The guidance represents a sharpening of zero‑trust expectations from an operator and infrastructure perspective. Historically, zero‑trust conversations have centered on enterprise user access and cloud workloads. This document extends those principles to the network fabric itself: where trust once flowed along perimeter and bilateral peering agreements, the guidance demands explicit, enforceable policy at every interconnect and maintenance interface.

Practically, network teams will need to invest in several areas to align with the guidance:

  • Stronger device identity and attestation capability across router, switch and SD‑WAN endpoints.
  • Policy engines capable of enforcing cross‑domain least‑privilege and handling dynamic context such as device posture and ongoing telemetry.
  • Federated telemetry pipelines and analytics that preserve privacy while enabling cross‑operator anomaly detection.
  • Robust supplier access governance, including ephemeral credentials and recorded, policy‑scoped sessions for maintenance contractors.

Next steps and practical advice

ENISA and the carrier coalition will host a series of workshops and operator‑to‑operator labs over the next quarter to work through interoperability profiles. Network teams should prioritize an inventory of interconnect endpoints and third‑party access channels and conduct risk assessments against the guidance’s baseline controls.

Experts recommend operators treat the guidance as a driver for modernization rather than merely a compliance checklist. Starting with strong device identity, incremental segmentation, and pilot telemetry sharing projects will reduce operational risk and help meet later, more demanding phases without wholesale rip‑and‑replace of critical infrastructure.

For zero‑trust networking practitioners, the guidance signals a clear recognition that zero trust must be embedded in the network’s control plane and operational practices — not just on endpoints or in cloud access proxies. The degree to which operators adopt the stringent profile will determine how resilient cross‑border interconnects become in the coming years.