May 2023 — China's Cybersecurity Review Concluded: Micron Failed
In May 2023, China's cybersecurity review concluded that US chipmaker Micron had failed its security review. The finding: Micron's products posed "major security risks to China's critical information infrastructure supply chain" and affected national security.
Who was told to stop buying? Not everyone. Only operators of critical information infrastructure — government agencies, large data centres, state-owned enterprises, and telecom operators. Ordinary consumers were not banned.
Same legal form, same effect — all use security exceptions to exclude foreign vendors
China used cybersecurity review. Other countries use similar mechanisms — US FCC orders against Huawei, UK telecom security rules. All frame the measure as a security decision, not trade policy.
All exclude specific foreign vendors from the domestic market. Whether it's Micron in China or Huawei/ZTE in the US and UK, the outcome is the same: foreign suppliers are locked out of critical domestic procurement.
The legal vehicle may differ, but the economic result is identical — market exclusion justified by national security.
| Dimension | China → Micron (2023) | Other Vendor Bans | Verdict |
|---|---|---|---|
| Legal Form | Cybersecurity Review (CAC) | US FCC orders against Huawei, UK telecom security rules — all framed as security, not trade policy | Same |
| Effect | Excludes Micron from CII procurement | Excludes specific foreign vendors from domestic market | Same |
Scope and basis — China's ban is narrower and product-specific, others are broader and entity-based
China's ban covers only critical infrastructure operators — a narrow category. Government agencies, large data centres, SOEs, and telecom operators must comply. Ordinary consumers and businesses are not affected.
Other bans apply to the entire market — imports and sales are prohibited outright. No distinction between sensitive and ordinary buyers.
China's ban was product-based — the review found specific technical problems in Micron's products. The finding targeted the product, not the company as an entity.
Other bans are often company-based — the firm itself is listed as a threat, regardless of whether a specific product has been proven risky. One is product-specific; the other is entity-based.
| Dimension | China → Micron (2023) | Other Vendor Bans | Verdict |
|---|---|---|---|
| Scope | CII operators only — narrow category, not general consumers | Entire market — imports and sales prohibited outright | Different |
| Basis | Product-based — specific technical problems found in Micron's products | Company-based — firm itself listed as threat, regardless of product-level proof | Different |
How to tell genuine security from market protection? Three things a government must publish.
Not just "it's risky" — what exactly is the risk? What vulnerability was found? Without specifics, the decision is unverifiable.
Which law was applied? How was the review conducted? Was there due process? Without procedural transparency, security claims are indistinguishable from protectionism.
Who must comply? What exactly is prohibited? If a government cannot publish these, the decision is a black box. We have reason to doubt whether it is genuinely about security.
The Micron decision and other vendor bans are the same play run in different directions.
All use security exceptions to restrict foreign vendors. The differences lie in scope, basis, and transparency.
The ultimate test is not what the measure calls itself —
but whether it can be justified with evidence.
Thank you.