If the U.S. were serious about any of this they'd be funding initiatives for open, verified hardware and software. Other than INRIA, the French research group, and CSIRO, from where seL4 comes, where else is this work being done?
I don't just mean theoretical work. I mean production ready stuff that is useable, like most commercialized solutions are, but also actually secure. Doing both is difficult. seL4 is useable and in fact is being tested in U.S. drones. Why didn't the NSA do something like seL4? Instead we get seLinux which isn't even secure--anything running on Linux is as a practical matter exploitable on the first day it ships.
Our communications and control systems are so fundamentally insecure it hardly matters whether it's sourced from Huawei or not--it's six of one or a half-dozen of the other, except one of those cartons is at least substantially cheaper than the other.
The fact of the matter is that the commercial industry will never develop and deliver secure products on their own. They've never done this well, and are probably fundamentally incapable of doing so because most of the benefits of a secure product inure to the public generally. Commercial vendors can't capture the value provided by secure solutions. It's up to the public--government, academia, open source community, etc--to invest in and develop the fundamental building blocks of secure systems.
Importantly, the entire stack doesn't need to be secure. We can write secure networked systems for the Internet because we presume the network is hostile. There's no reason that cellular radios should be a trusted component of a wireless cellular network. They are because (1) it's just cheaper to do it that way (see above) and (2) the U.S. government spent decades sabotaging cryptography generally and cellular standards specifically, which means even 5G standards are fundamentally broken from a design perspective.
So the whole Huawei controversy deserves a giant eye roll. All of the arguments about why Huawei can't be trusted are irrelevant. Huawei shouldn't be trusted, but neither should Qualcomm or any of these other vendors. Rather, we should set transparency standards and verify that they're being met. But doing so requires a ridiculous amount of work up and down the software and hardware stack, starting from the design stage; work that the U.S. government isn't actually doing but, in fact, still sabotaging!