Huawei Passed an Independent Security Audit in 2020. Canada Banned It in 2022.
Two facts that have to be held at the same time
On 24 August 2020 the GSMA announced that "the world's leading mobile network equipment vendors, Ericsson, Huawei, Nokia and ZTE, have successfully completed an assessment of their product development and lifecycle management processes" under its Network Equipment Security Assurance Scheme (GSMA, 2020). The industry body's chief technology officer, Alex Sinclair, said the four vendors had "satisfied the scheme's security requirements via an independent security audit" and called it "this important first step" (GSMA, 2020).
Twenty months later, on 19 May 2022, the Government of Canada published a policy statement prohibiting the use of new 5G equipment and managed services from Huawei and ZTE, requiring existing 5G equipment to be removed by 28 June 2024 and existing 4G equipment by 31 December 2027 (Innovation, Science and Economic Development Canada, 2022). On 13 October 2022 the United Kingdom issued a designation notice categorising Huawei "as a high-risk vendor of 5G network equipment and services", along with a direction to 35 UK operators (Department for Digital, Culture, Media & Sport, 2022).
Both things are true. The audit happened, independently. The exclusions happened, on national-security grounds set out in each government's own notice (Innovation, Science and Economic Development Canada, 2022; Department for Digital, Culture, Media & Sport, 2022). Nothing was falsified; nobody cheated. The audit did not move the outcome by a single day, because no buyer and no regulator had made it the condition of access.
The spine. A certification is a gate only where a named party — a buyer or a regulator — requires it. Everything else is a preference: possibly valuable, occasionally decisive in a tie, but not the thing standing between you and the deal. Apply that one test to 130 admissibility requirements across 20 industry buying systems and the split is 85 gates, every one with a named mandating party, against 45 preferences with none Sagentix GTM Methodology, 2026. SOC 2 Type II and ISO 27001 fall on the preference side in clinical and health delivery, in financial services and insurance, and in enterprise software. Most will read that as certifications are worthless. That is the misread, and it is the expensive one.
An audit that no buyer and no regulator names removes no barrier, however rigorous it is. That is not a reason to skip it — it is a reason to know which budget pays for it before you spend nine to eighteen months earning it.
The test, in one sentence
Write the name of the party that requires it.
Not the category — a name. Our enterprise buyers ask about it names nobody. The content owner's security review requires it names someone Sagentix GTM Methodology, 2026. The test is whether you could email whoever demands it.
If you can write a name, you have a gate: fail it and nobody evaluates you at all. If you cannot, you have a preference — one more thing competing for the same buyer's attention, which must earn its cost the way a feature does.
The distinction matters because the two are bought differently. A gate has no return on investment — it has a threshold. You clear it or you are out of the market. Spending more than the minimum to clear it is waste. A preference has a return curve. It competes against product work, reference customers, pricing, everything else in the budget. Treating a preference as a gate produces the specific failure I see most often in cybersecurity and enterprise software: a founder spends nine to eighteen months plus a six-figure budget on an audit that removes no barrier, while whatever really decides admission in that sector goes untouched.
What the split looks like across twenty industries
Across 20 industry buying systems, the same audit produces this:
Admissibility requirements by whether a named party mandates them
- Gates — a named buyer or regulator requires it85
- Preferences — no mandating party could be named45
Where SOC 2 and ISO 27001 land depends entirely on the industry, and the pattern is not the one most vendors assume:
| Industry buying system | Status | What is actually mandated |
|---|---|---|
| Clinical and health delivery | Preference | SOC 2 Type II or ISO 27001 or HITRUST — choose one, not all |
| Financial services and insurance | Preference | Conditions the market imposes in practice; no regulator names them |
| Enterprise technology and software | Preference | Strong, regionally split — SOC 2 in North America, ISO/IEC 27001 more often in the EU and UK |
| Education and research institutions | Gate | A completed sector vendor-security assessment, mandated by member institutions — SOC 2 Type 2 accepted as a substitute |
| Telecom, media and content | Gate | Content-security assurance, mandated by the content owner's review |
Sagentix GTM Methodology, 2026
Read the education row carefully, because it is the most useful one. SOC 2 counts there — and it still is not the gate. The gate is a sector-specific vendor-security assessment that member institutions require; SOC 2 is accepted in lieu of it. A vendor who holds SOC 2 and stops has satisfied a substitution rule, not a requirement, and will discover the difference the first time an institution declines the substitute.
One hour, this week: list every mark you hold or plan to hold, then write beside each the name of the buyer or regulator that demands it. Every blank line is a preference. You may still want it — but pay for it out of the marketing budget, where it competes honestly, rather than the access budget, where nobody questions it.
Why the misread is the expensive part
The conclusion "certifications are worthless" does not follow, and acting on it would cost more than the error it corrects. Three reasons.
A preference still sells. In enterprise software the underlying analysis records the expectation as bordering on hard: buyers ask, procurement scores it, its absence lengthens a cycle even where it does not end one Sagentix GTM Methodology, 2026. That is a real commercial effect. It is simply not an access effect, and the budgeting follows the difference.
Gates are frequently the boring artefact. Across the 85 mandated requirements, what the named party demands is more often a registration, a place on a purchasing vehicle, a sector assessment or that buyer's own internal review than a marquee certification Sagentix GTM Methodology, 2026. Those cost less than an audit, take less time, yet they are what lets you in.
The status changes at a border. ISO/IEC 27001 is the more commonly expected mark in the EU and UK where SOC 2 dominates North America. The same product sold into the same industry in two jurisdictions can face two different preferences, and a vendor holding only one is rarely blocked outright; it argues from behind Sagentix GTM Methodology, 2026.
Where this fits, and what I do not do
I advise cybersecurity and enterprise software companies on go-to-market. Sagentix does not perform SOC 2 or ISO 27001 audits, does not issue certifications, and is not an assessor or certification body for any of the schemes named in this article. What I do is work out which requirements in a target sector are actually demanded, and by whom, before a client commits budget to one — which is a market-intelligence question rather than a compliance one Sagentix Phase 01 Market Intelligence, 2026.
That analysis is part of a delivery system that runs 6–8 weeks, draws on 1,412 curated artifacts, and is priced from CA$4,500 for Phase 1 to CA$45,000 for a full go-to-market build, depending on scope — with a Phase 1 money-back guarantee (subject to terms). The test itself, though, is one sentence long and you should run it yourself first.
What I could not verify
The internal analysis this draws on also asserted that Huawei and ZTE were excluded from networks in "ten EU member states." I could not confirm a member-state-by-member-state count at a primary source on 8 September 2026, so it is not in this article. Canada and the United Kingdom are here because both actions are published, dated and directly readable at the issuing government's own URL.
The same caution applies to the audit's currency. What is verified is that the four vendors completed the NESAS assessment announced in August 2020, and that the GSMA described it as covering development and lifecycle processes and as a first step, with product-level evaluation to follow (GSMA, 2020). Whether any of those vendors holds a current NESAS status today is a separate question I have not tested, and the argument does not need it: the audit's existence in 2020 and the exclusions in 2022 are enough.
Across 20 industry buying systems, 85 of 130 requirements name the party that imposes them; 45 name nobody Sagentix GTM Methodology, 2026. What really gates your sector is more often a form you file, a vehicle you join, or a review one buyer runs — cheaper than an audit, faster, and the thing that decides whether anyone looks at you.
Three ways to act on this
Run the naming test on your own roadmap this week. List every certification, attestation and assessment you hold or plan to hold. Beside each, write the name of the buyer or regulator that requires it. Every blank line is a preference. You may still want it — but move it out of the access budget and into the marketing budget, where it competes honestly against other spending. This takes an hour.
Find the gate you are not addressing. For your top target sector, ask three current or prospective buyers what a vendor must have before evaluation begins, and listen for the boring answer — a vendor registration, a place on a standing offer, a sector assessment, a named internal review. The famous certification is rarely the first thing named, and the first thing named is the one with no workaround.
Bring in a structured market-access pass when the commitment is large — when an audit would consume a quarter of the year's engineering time, when a board is being asked to fund a compliance programme as a growth investment, or when you are entering a second jurisdiction and do not know whether the requirement travels. That is a Phase 01 engagement, and I would take it last of the three, because the first two cost an afternoon and a few conversations.
Huawei's auditors did their job. So did the officials in Ottawa and London. The vendors' mistake, if there was one, was not in the audit — it was in believing that clearing a bar someone was willing to certify meant clearing the bar that someone was willing to enforce.
Which certification on your roadmap can you name the mandating party for — and what happens to your budget if you cannot?
References
- Department for Digital, Culture, Media & Sport. (2022, October 13). Huawei legal notices issued. Government of the United Kingdom.
- GSMA. (2020, August 24). GSMA announces progress on Network Equipment Security Assurance Scheme. GSM Association.
- Innovation, Science and Economic Development Canada. (2022, May 19). Policy statement — Securing Canada's telecommunications system. Government of Canada.
Subscribe + get the workbook
The Bottom-Up TAM / SAM / SOM Workbook — free with your subscription
An 11-page tactical workbook with fillable worksheets — NAICS lookup, three-filter SAM test, Bull/Base/Bear SOM, and the diligence cross-checks. Not published anywhere else. Then get evidence-backed analysis every other Tuesday. No spam. Unsubscribe anytime. See past issues.

Stéphane Raby, CISSP, CMC, P.Eng., MBA
Founder & Principal — Sagentix Advisors
CMC | CISSP | P.Eng. | uOttawa Telfer Executive MBA — ranked #1 globally by CEO Magazine, 2023. 25+ years in technology strategy, cybersecurity, and management consulting.
Want This Evidence Applied to Your Market?
Phase 1 Market Intelligence starts at CA$4,500 with a money-back guarantee.