Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0253 → TA-9-2024-0130

From
A-9-2023-0253 Plenary report of 27 Jul 2023
To
TA-9-2024-0130 Adopted text of 12 Mar 2024
Changes
Not comparable
Paragraphs
+13 added · −868 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
Cyber Resilience Act

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 14 of 17: Paragraphs 723–782

Removed14. Mobile device management software;

Removed15. Physical and virtual network interfaces;

Removed16. Operating systems not covered by class II;

Removed17. Firewalls, intrusion detection and/or prevention systems not covered by class II;

Removed19. General purpose microprocessors and microprocessors not covered by class II;

Removed20. Microcontrollers;

Removed21. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) intended for the use by essential entities of the type referred to in Article 3 of Directive(EU) 2022/2555;

Removed22. Industrial Automation & Control Systems (IACS) not covered by class II, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC), industrial robots and their control systems and supervisory control and data acquisition systems (SCADA);

Removed23. Industrial Internet of Things not covered by class II;

Removed23a. Home automation systems, including smart home servers and virtual assistants;

Removed23b. Security devices, including smart door locks, cameras and alarm systems;

Removed23c. Smart toys;

Removed23d. Personal health appliances and wearables.

RemovedClass II

Removed1. Operating systems for servers, desktops, and mobile devices;

Removed2. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments;

Removed3. Public key infrastructure and digital certificate issuers;

Removed4. Firewalls, intrusion detection and/or prevention systems intended for industrial use;

Removed▌

Removed6. Microprocessors intended for integration in programmable logic controllers and secure elements;

Removed7. Routers, modems intended for the connection to the internet, and switches ▌;

Removed8. Secure elements;

Removed9. Hardware Security Modules (HSMs);

Removed10. Secure cryptoprocessors;

Removed11. Smartcards, smartcard readers and tokens;

Removed12. Industrial Automation & Control Systems (IACS) intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC) and supervisory control and data acquisition systems (SCADA);

Removed13. Industrial Internet of Things devices intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555;

Removed▌

Removed15. Smart meters.

RemovedEU DECLARATION OF CONFORMITY

RemovedThe EU declaration of conformity referred to in Article 20, shall contain all of the following information:

Removed1. Name and type and any additional information enabling the unique identification of the product with digital elements;

Removed2. Name and address of the manufacturer or his authorised representative;

Removed3. A statement that the EU declaration of conformity is issued under the sole responsibility of the provider;

Removed4. Object of the declaration (identification of the product allowing traceability. It may include a photograph, where appropriate);

Removed5. A statement that the object of the declaration described above is in conformity with the relevant Union harmonisation legislation;

Removed6. References to any relevant harmonised standards used or any other common specification or cybersecurity certification in relation to which conformity is declared;

Removed7. Where applicable, the name and number of the notified body, a description of the conformity assessment procedure performed and identification of the certificate issued;

Removed8. Additional information:

RemovedSigned for and on behalf of: …………………………………

Removed(place and date of issue):

Removed(name, function) (signature):

RemovedCONTENTS OF THE TECHNICAL DOCUMENTATION

RemovedThe technical documentation referred to in Article 23 shall contain at least the following information, as applicable to the relevant product with digital elements:

Removed1. a general description of the product with digital elements, including:

Removed(a) its intended purpose;

Removed(b) versions of software affecting compliance with essential requirements;

Removed(c) where the product with digital elements is a hardware product, photographs or illustrations showing external features, marking and internal layout;

Removed(d) user information and instructions as set out in Annex II;

Removed2. a description of the design, development and production of the product and vulnerability handling processes, including:

Removed(a) complete information on the design and development of the product with digital elements, including, where applicable, drawings and schemes and/or a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing;

Removed(b) complete information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;

Removed(c) complete information and specifications of the production and monitoring processes of the product with digital elements and the validation of these processes.

Removed3. an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained as laid down in Article 10 of this Regulation, including how the essential requirements set out in Annex I, Section 1, are applicable;

Removed4. a list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union, common specifications as set out in Article 19 of this Regulation or cybersecurity certification schemes under Regulation (EU) 2019/881 pursuant to Article 18(3), and, where those harmonised standards, common specifications or cybersecurity certification schemes have not been applied, descriptions of the solutions adopted to meet the essential requirements set out in Sections 1 and 2 of Annex I, including a list of other relevant technical specifications applied. In the event of partly applied harmonised standards, common specifications or cybersecurity certifications, the technical documentation shall specify the parts which have been applied;

Removed5. reports of the tests carried out to verify the conformity of the product and of the vulnerability handling processes with the applicable essential requirements as set out in Sections 1 and 2 of Annex I;

Removed6. a copy of the EU declaration of conformity;

Removed7. where applicable, the software bill of materials as defined in Article 3, point (36), further to a reasoned request from a market surveillance authority provided that it is necessary in order for this authority to be able to check compliance with the essential requirements set out in Annex I.

RemovedCONFORMITY ASSESSMENT PROCEDURES

RemovedConformity Assessment procedure based on internal control (based on Module A)

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=14 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
  year = {2024},
  date = {2024-03-12},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=14}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=14},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}