Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0038 → TA-9-2024-0117

From
A-9-2023-0038 Plenary report of 3 Mar 2023
To
TA-9-2024-0117 Adopted text of 29 Feb 2024
Changes
Not comparable
Paragraphs
+19 added · −631 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity
Title (to)
European Digital Identity Framework

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 8 of 12: Paragraphs 421–480

Removed(f) the following paragraph 6 is inserted:

Removed‘6. The Commission shall be empowered to adopt delegated acts in accordance with Article 47, supplementing this Regulation with regard to the additional measures referred to in paragraph 2(fa) of this Article.’;

Removed(26) In Article 28, paragraph 6 is replaced by the following:

Removed‘6. Within 12 months after the entry into force of this Regulation, the Commission shall, by means of implementing acts, establish reference numbers of standards for qualified certificates for electronic signature. Compliance with the requirements laid down in Annex I shall be presumed where a qualified certificate for electronic signature meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(27) In Article 29, the following new paragraph 1a is added:

Removed‘1a. Generating, managing and duplicating qualified electronic signature creation data on behalf of the signatory may only be done by a qualified trust service provider providing a qualified trust service for the management of a remote electronic qualified signature creation device.’;

Removed(28) the following Article ▌ is inserted:

Removed‘Article 29a

RemovedRequirements for a qualified service for the management of remote electronic signature creation devices

Removed1. The management of remote qualified electronic signature creation devices as a qualified service may only be carried out by a qualified trust service provider that:

Removed(a) generates or manages electronic signature creation data on behalf of the signatory;

Removed(b) notwithstanding point (1)(d) of Annex II, duplicates the electronic signature creation data only for back-up purposes provided the following requirements are met:

Removed(i) the security of the duplicated datasets must be at the same level as for the original datasets;

Removed(ii) the number of duplicated datasets shall not exceed the minimum needed to ensure continuity of the service.

Removed(c) complies with any requirements identified in the certification report of the specific remote qualified signature creation device issued pursuant to Article 30.

Removed2. By ... [12 months after the entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish technical specifications and reference numbers of standards for the purposes of paragraph 1.’;

Removed(29) In Article 30, the following paragraph 3a is inserted:

Removed‘3a. The certification referred to in paragraph 1 shall be valid for 5 years, conditional upon a regular 2 year vulnerabilities assessment. Where vulnerabilities are identified and not remedied, the certification shall be withdrawn.’;

Removed(30) In Article 31, paragraph 3 is replaced by the following:

Removed‘3. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, define formats and procedures applicable for the purpose of paragraph 1. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(31) Article 32 is amended as follows:

Removed(a) in paragraph 1, the following sub-paragraph is added:

Removed‘Compliance with the requirements laid down in the first sub-paragraph shall be presumed where the validation of qualified electronic signatures meet the standards referred to in paragraph 3.’;

Removed(b) paragraph 3 is replaced by the following:

Removed‘3. By .... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for the validation of qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(32) Article 34 is replaced by the following:

Removed‘Article 34

RemovedQualified preservation service for qualified electronic signatures

Removed1. A qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider that uses procedures and technologies capable of extending the trustworthiness of the qualified electronic signature beyond the technological validity period.

Removed2. Compliance with the requirements laid down in the paragraph 1 shall be presumed where the arrangements for the qualified preservation service for qualified electronic signatures meet the standards referred to in paragraph 3.

Removed3. By .... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for the qualified preservation service for qualified electronic signatures. Those implementing acts shall be adopted in accordance with the examination procedure referred to In Article 48(2).’;

Removed(33) Article 37 is amended as follows:

Removed(a) the following paragraph 2a is inserted:

Removed‘2a. Compliance with the requirements for advanced electronic seals referred to in Article 36 and in paragraph 5 of this Article shall be presumed where an advanced electronic seal meets the standards referred to in paragraph 4.’;

Removed(b) paragraph 4 is replaced by the following:

Removed‘4. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for advanced electronic seals. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(34) Article 38 is amended as follows:

Removed(a) paragraph 1 is replaced by the following:

Removed‘1. Qualified certificates for electronic seals shall meet the requirements laid down in Annex III. Compliance with the requirements laid down in Annex III shall be presumed where a qualified certificate for electronic seal meets the standards referred to in paragraph 6.’;

Removed(b) paragraph 6 is replaced by the following:

Removed‘6. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for qualified certificates for electronic seals. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(35) the following Article ▌ is inserted:

Removed‘Article 39a

RemovedRequirements for a qualified service for the management of remote electronic seal creation devices

RemovedArticle 29a shall apply mutatis mutandis to a qualified service for the management of remote electronic seal creation devices.’;

Removed(36) Article 42 is amended as follows:

Removed(a) the following new paragraph 1a is inserted:

Removed‘1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the binding of date and time to data and the accurate time source meet the standards referred to in paragraph 2.’;

Removed(b) paragraph 2 is replaced by the following

Removed‘2. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for the binding of date and time to data and for accurate time sources. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(37) Article 44 is amended as follows:

Removed(a) the following paragraph 1a is inserted:

Removed‘1a. Compliance with the requirements laid down in paragraph 1 shall be presumed where the process for sending and receiving data meets the standards referred to in paragraph 2.’;

Removed(b) paragraph 2 is replaced by the following:

Removed‘2. By ... [12 months after the date of entry into force of this amending Regulation], the Commission shall, by means of implementing acts, establish reference numbers of standards for processes for sending and receiving data. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).’;

Removed(38) Article 45 is replaced by the following:

Removed‘Article 45

RemovedRequirements for qualified certificates for website authentication

Removed1. Qualified certificates for website authentication shall allow the authentication and identification of the natural or legal person to whom the certificate was issued with a high level of assurance. Qualified certificates for website authentication shall also meet the requirements laid down in Annex IV. Qualified certificates for website authentication shall be deemed compliant with this paragraph and the requirements laid down in Annex IV where they meet the standards referred to in paragraph 3.

Removed2. Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. Web browsers shall not be prevented from taking measures that are both necessary and proportionate to address substantiated risks of breaches of security, user’s privacy and loss of integrity of certificates provided such measures are duly reasoned. In such a case, the web browser shall notify the Commission, ENISA and the qualified trust service provider that issued that certificate or set of certificates without delay of any measure taken. Such recognition means that web-browsers shall ensure that the relevant identity data and electronic attestation of attributes provided is displayed in a user friendly manner, where possible, consistent manner, that reflects the state-of-the-art regarding accessibility, user awareness and cybersecurity according to best industry standards. Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0038 and TA-9-2024-0117”. Text, 29 February 2024. from A-9-2023-0038, to TA-9-2024-0117. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=8 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-29,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0038 and TA-9-2024-0117}},
  year = {2024},
  date = {2024-02-29},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=8}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0038/compare/TA-9-2024-0117?all=1&part=8},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0038, to TA-9-2024-0117. Data: European Parliament Open Data (CC BY 4.0)}
}