Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0253 → TA-9-2024-0130

From
A-9-2023-0253 Plenary report of 27 Jul 2023
To
TA-9-2024-0130 Adopted text of 12 Mar 2024
Changes
Not comparable
Paragraphs
+13 added · −868 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
Cyber Resilience Act

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 12 of 17: Paragraphs 603–662

Removed4. When conducting sweeps, the market surveillance authorities involved may use the investigation powers set out in Articles 41 to 47 and any other powers conferred upon them by national law.

Removed5. Market surveillance authorities shall invite Commission officials, and other accompanying persons authorised by the Commission, to participate in sweeps.

RemovedDELEGATED POWERS AND COMMITTEE PROCEDURE

Removed1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

Removed2. The power to adopt delegated acts referred to in Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 18(4), Article 19(1), Article 20(5) and Article 23(5) shall be conferred on the Commission.

Removed3. The delegation of power referred to in Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 18(4), Article 19(1), Article 20(5) and Article 23(5) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

Removed4. Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with principles laid down in the Inter-institutional Agreement of 13 April 2016 on Better Law-Making.

Removed5. As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.

Removed6. A delegated act adopted pursuant to Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 18(4), Article 19(1), Article 20(5) or Article 23(5) shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.

Removed1. The Commission shall be assisted by a committee. That committee shall be a committee within the meaning of Regulation (EU) No 182/2011.

Removed2. Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.

Removed3. Where the opinion of the committee is to be obtained by written procedure, that procedure shall be terminated without result when, within the time-limit for delivery of the opinion, the chair of the committee so decides or a committee member so requests.

RemovedCONFIDENTIALITY AND PENALTIES

Removed1. All parties involved in the application of this Regulation shall respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular:

Removed(a) intellectual property rights, and confidential business information or trade secrets of a natural or legal person, including source code, except the cases referred to in Article 5 of Directive 2016/943 of the European Parliament and of the Council;

Removed(b) the effective implementation of this Regulation, in particular for the purpose of inspections, investigations or audits;

Removed(c) public and national security interests;

Removed(d) integrity of criminal or administrative proceedings.

Removed2. Without prejudice to paragraph 1, information exchanged on a confidential basis between the market surveillance authorities and between market surveillance authorities and the Commission shall not be disclosed without the prior agreement of the originating market surveillance authority.

Removed3. Paragraphs 1 and 2 shall not affect the rights and obligations of the Commission, Member States and notified bodies with regard to the exchange of information and the dissemination of warnings, nor the obligations of the persons concerned to provide information under criminal law of the Member States.

Removed4. The Commission and Member States may exchange, where necessary, sensitive information with relevant authorities of third countries with which they have concluded bilateral or multilateral confidentiality arrangements guaranteeing an adequate level of protection.

Removed1. Member States shall lay down the rules on penalties applicable to infringements by economic operators of this Regulation and shall take all measures necessary to ensure that they are enforced. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall ensure that those rules take into account the financial capabilities of microenterprises and small and medium-sized enterprises.

Removed2. Member States shall, without delay, notify the Commission of those rules and of those measures and shall notify it without delay of any subsequent amendment affecting them. The Commission shall ensure that those rules and measures are applied in a uniform and consistent manner across the Union.

Removed3. The non-compliance with the essential cybersecurity requirements laid down in Annex I and the obligations set out in Articles 10 and 11 shall be subject to administrative fines of up to 15 000 000 EUR or, if the offender is an undertaking, up to 2.5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.

Removed4. The non-compliance with any other obligations under this Regulation shall be subject to administrative fines of up to 10 000 000 EUR or, if the offender is an undertaking, up to 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.

Removed5. The supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request shall be subject to administrative fines of up to 5 000 000 EUR or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.

Removed6. When deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following:

Removed(a) the nature, gravity and duration of the infringement and of its consequences;

Removed(aa) whether the infringement is unintentional;

Removed(b) whether administrative fines have been already applied by the same or other market surveillance authorities to the same operator for a similar infringement;

Removed(c) the size, in particular with regard to microenterprises, small and medium sized-enterprises, including start-ups, and market share of the operator committing the infringement.

Removed7. Market surveillance authorities that apply administrative fines shall share this information with the market surveillance authorities of other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.

Removed8. Each Member State shall lay down rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.

Removed9. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or other bodies according to the competences established at national level in those Member States. The application of such rules in those Member States shall have an equivalent effect.

Removed10. Administrative fines may be imposed, depending on the circumstances of each individual case, in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement.

RemovedMember States shall allocate the revenues from the penalties referred to in Article 53(1) to projects raising the level of cybersecurity within the Union. Those projects shall aim at least to one of the following:

Removed(a) increase the number of skilled professionals in the field of cybersecurity, notably women;

Removed(b) increase capacity-building for microenterprises and small and medium-sized enterprises in order to facilitate their compliance with this Regulation;

Removed(c) improve public awareness of cyber threats, with particular regard to their prevention and management;

Removed(d) develop tools to increase the resilience of Union undertakings to cyber-enabled intellectual property theft.

RemovedTRANSITIONAL AND FINAL PROVISIONS

RemovedIn Annex I to Regulation (EU) 2019/1020 the following point is added:

Removed‘71. [Regulation XXX] [Cyber Resilience Act]’.

RemovedIn Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council the following point is added:

Removed‘67. [Regulation XXX] [Cyber Resilience Act]’.

Removed1. EU type-examination certificates and approval decisions issued regarding cybersecurity requirements for products with digital elements that are subject to other Union harmonisation legislation shall remain valid until [42 months after the date of entry into force of this Regulation], unless they expire before that date, or unless otherwise specified in other Union legislation, in which case they shall remain valid as referred to in that Union legislation.

Removed2. Products with digital elements that have been placed on the market before [date of application of this Regulation referred to in Article 57], shall be subject to requirements of this Regulation only if, from that date, those products are subject to substantial modifications in their design or intended purpose.

Removed3. By way of derogation from paragraph 2, the obligations laid down in Article 11 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before [date of application of this Regulation referred to in Article 57].

Removed3a. Until the date of application of this Regulation, manufacturers may comply with the requirements of this Regulation on a voluntary basis. Where manufacturers comply with this Regulation with regard to their products with digital elements, they shall be considered also to comply with Delegated Regulation (EU) 2022/30.

RemovedThe Commission shall repeal Delegated Regulation (EU) 2022/30 on the same date of application of this Regulation.

Removed1. By [36 months after the date of application of this Regulation] and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The reports shall be made public.

Removed2. Every year when presenting the Draft Budget for the following year, the Commission shall submit a detailed assessment of ENISA's tasks under this Regulation as set out in Annex VIa and other relevant Union law and shall detail the financial and human resources needed to fulfil those tasks.

RemovedThis Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

RemovedIt shall apply from [36 months after the date of entry into force of this Regulation]. However Article 11 shall apply from [18 months after the date of entry into force of this Regulation].

RemovedThis Regulation shall be binding in its entirety and directly applicable in all Member States.

RemovedDone at …▌,

RemovedFor the European Parliament For the Council

RemovedThe President The President

RemovedESSENTIAL CYBERSECURITY REQUIREMENTS

Removed1. Security requirements relating to the properties of products with digital elements

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=12 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
  year = {2024},
  date = {2024-03-12},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=12}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=12},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}