Real point here

"We have no real (at least not this in depth) assurance that products from rival vendors are more secure"

If, and it seems a good idea, that critical infrastructure needs to be secure against both back doors and crap code, then it should be a requirement that the alternative suppliers are similarly audited to show they actually do better. After all, it is not that Cisco have no history of both back doors and serious bugs needing fixed either...

