Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0253 → TA-9-2024-0130
- From
- A-9-2023-0253 Plenary report of 27 Jul 2023
- To
- TA-9-2024-0130 Adopted text of 12 Mar 2024
- Changes
- Not comparable
- Paragraphs
- +13 added · −868 removed · 0 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
- Title (to)
- Cyber Resilience Act
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 13 of 17: Paragraphs 663–722
Removed(1) Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks;
Removed▌
Removed(3) On the basis of the cybersecurity risk assessment referred to in Article 10(2) and where applicable, products with digital elements shall:
Removed(-a) be made available without known exploitable vulnerabilities;
Removed(a) be made available with a secure by default configuration, unless otherwise agreed between the parties in a business-to-business context, including the possibility to reset the product to its original state while retaining all installed security updates;
Removed(aa) where technically feasible, be made available on the market with functional separation of security updates from functionality update;
Removed(ab) ensure automatic security updates with a clear and easy-to-use opt-out mechanism and the notification of available updates to users;
Removed(b) ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems;
Removed(c) protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means;
Removed(d) protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, as well as report on corruptions or possible unauthorised access;
Removed(e) process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended use of the product (‘minimisation of data’);
Removed(f) protect the availability of essential and basic functions, also after an incident, including with backup management, and the resilience and mitigation measures against denial of service attacks;
Removed(g) minimise their own negative impact on the availability of services provided by other devices or networks;
Removed(h) be designed, developed and produced to limit attack surfaces, including external interfaces;
Removed(i) be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques;
Removed(j) provide security related information by recording and/or monitoring capabilities for relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user;
Removed▌
Removed(ka) enable users to securely withdraw and remove their data on a permanent basis.
Removed2. Vulnerability handling requirements
RemovedManufacturers of the products with digital elements shall:
Removed(1) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the product;
Removed(2) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates installed automatically where applicable in accordance with Section I;
Removed(3) apply effective and regular tests and reviews of the security of the product with digital elements;
Removed(4) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities in a controlled way, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities;
Removed(5) put in place and enforce a policy on coordinated vulnerability disclosure;
Removed(6) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements;
Removed(7) provide for mechanisms to securely distribute security updates for products with digital elements to ensure that exploitable vulnerabilities are fixed or mitigated in a timely manner;
Removed(8) ensure that, where security patches or updates are available to address identified security issues, they are disseminated without delay and unless otherwise agreed between the parties in a business-to-business context, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken;
Removed(8a) where possible and applicable, notify the user of the end of the support period.
RemovedINFORMATION AND INSTRUCTIONS TO THE USER
RemovedAs a minimum, the product with digital elements shall be accompanied by:
Removed1. the name, registered trade name or registered trade mark of the manufacturer, and the postal address and the email address and where available the website at which the manufacturer can be contacted, on the product or ▌ on its packaging or in a document accompanying the product;
Removed2. the point of single contact where information about cybersecurity vulnerabilities of the product can be reported and received and the manufactuer’s policy on coordinated vulnerabilities and where it can be found;
Removed3. the correct identification of the type, batch, version or serial number or other element allowing the identification of the product and the corresponding instructions and user information;
Removed4. the intended use, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties;
Removed5. any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks;
Removed6. if and, where applicable, where the software bill of materials can be accessed by the competent authorities in accordance with non-disclosure conditions set out in Article 52;
Removed7. where applicable, the internet address at which the EU declaration of conformity can be accessed;
Removed8. the type of technical security support offered by the manufacturer and the support period during which users can expect vulnerabilities to be handled and to receive security updates;
Removed9. detailed instructions or an internet address referring to such detailed instructions and information on:
Removed(a) the necessary measures during initial commissioning and throughout the lifetime of the product to ensure its secure use;
Removed(b) how changes to the product can affect the security of data;
Removed(c) how security-relevant updates can be installed;
Removed(d) the secure decommissioning of the product, including information on how user data can be securely removed.
RemovedCRITICAL PRODUCTS WITH DIGITAL ELEMENTS
RemovedClass I
Removed1. Identity management systems software and privileged access management software;
Removed2. Standalone and embedded browsers;
Removed3. Password managers;
Removed3a. Biometric readers;
Removed4. Software that searches for, removes, or quarantines malicious software;
Removed5. Products with digital elements with the function of virtual private network (VPN);
Removed6. Network management systems;
Removed7. Network configuration management tools;
Removed8. Network traffic monitoring systems;
Removed9. Management of network resources;
Removed10. Security information and event management (SIEM) systems;
Removed11. Update/patch management, including boot managers;
Removed12. Application configuration management systems;
Removed13. Remote access ▌ software;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=13
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 29 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=13 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
year = {2024},
date = {2024-03-12},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=13}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=13},
urldate = {2026-09-29},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}