Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0253 → TA-9-2024-0130

From
A-9-2023-0253 Plenary report of 27 Jul 2023
To
TA-9-2024-0130 Adopted text of 12 Mar 2024
Changes
Not comparable
Paragraphs
+13 added · −868 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
Cyber Resilience Act

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 4 of 17: Paragraphs 123–182

Removed(52) Since notified bodies may offer their services throughout the Union, it is appropriate to give the other Member States and the Commission the opportunity to raise objections concerning a notified body. It is therefore important to provide for a period during which any doubts or concerns as to the competence of conformity assessment bodies can be clarified before they start operating as notified bodies.

Removed(53) In the interests of competitiveness, it is crucial that notified bodies apply the conformity assessment procedures without creating unnecessary burden for economic operators, in particular for microenterprises and small and medium-sized enterprises. In this regard, Member States, with the support of the Commission, should ensure that there is an adequate availability of skilled professionals in order to ensure that notified bodies can carry out their activities efficiently, thus minimising possible impediments, avoiding bottlenecks and facilitating economic operators' compliance with this Regulation. For the same reason, and to ensure equal treatment of economic operators, consistency in the technical application of the conformity assessment procedures needs to be ensured. That should be best achieved through appropriate coordination and cooperation between notified bodies.

Removed(53a) In order to increase efficiency and transparency, Member States should ensure, before the date of application of this Regulation, that there is a sufficient number of notified bodies in the Union to carry out conformity assessments. The Commission should monitor market developments and assist Member States in this endeavour, in order to avoid bottlenecks and hindrances to market entry.

Removed(54) Market surveillance is an essential instrument in ensuring the proper and uniform application of Union legislation. It is therefore appropriate to put in place a legal framework within which market surveillance can be carried out in an appropriate manner. Rules on Union market surveillance and control of products entering the Union market provided for in Regulation (EU) 2019/1020 of the European Parliament and of the Council apply to products with digital elements covered by this Regulation.

Removed(55) In accordance with Regulation (EU) 2019/1020, market surveillance authorities carry out market surveillance in the territory of that Member State. This Regulation should not prevent Member States from choosing the competent authorities to carry out those tasks. Each Member State should designate one or more market surveillance authorities in its territory. Member States may choose to designate any existing or new authority to act as market surveillance authority, including national competent authorities referred to in ▌Directive [(EU) 2022/2555 or designated national cybersecurity certification authorities referred to in Article 58 of Regulation (EU) 2019/881. Economic operators should fully cooperate with market surveillance authorities and other competent authorities. Each Member State should inform the Commission and the other Member States of its market surveillance authorities and the areas of competence of each of those authorities and should ensure the necessary resources and skills to carry out the surveillance tasks relating to this Regulation. As per Article 10(2) and (3) of Regulation (EU) 2019/1020, each Member State should appoint a single liaison office that should be responsible, among others, for representing the coordinated position of the market surveillance authorities and assisting in the cooperation between market surveillance authorities in different Member States.

Removed(56) A dedicated administrative cooperation group (ADCO) for the cyber resilience of products with digital elements should be established for the uniform application of this Regulation, pursuant to Article 30(2) of Regulation (EU) 2019/1020. This ADCO should be composed of representatives of the designated market surveillance authorities and, if appropriate, representatives of the single liaison offices. The Commission should support and encourage cooperation between market surveillance authorities through the Union Product Compliance Network, established on the basis of Article 29 of Regulation (EU) 2019/1020 and comprising representatives from each Member State, including a representative of each single liaison office referred to in Article 10 of Regulation (EU) 2019/1020 and an optional national expert, the chairs of ADCOs, and representatives from the Commission. The Commission should participate in the meetings of the Network, its sub-groups and this respective ADCO. It should also assist this ADCO by means of an executive secretariat that provides technical and logistic support.

Removed(57) In order to ensure timely, proportionate and effective measures in relation to products with digital elements presenting a significant cybersecurity risk, a Union safeguard procedure should be provided under which interested parties are informed of measures intended to be taken with regard to such products. This should also allow market surveillance authorities, in cooperation with the relevant economic operators, to act at an earlier stage where necessary. Where the Member States and the Commission agree as to the justification of a measure taken by a Member State, no further involvement of the Commission should be required, except where non-compliance can be attributed to shortcomings of a harmonised standard.

Removed(58) In certain cases, a product with digital elements which complies with this Regulation, may nonetheless present a significant cybersecurity risk or pose a risk to the health or safety of persons, to compliance with obligations under Union or national law intended to protect fundamental rights, the availability, authenticity, integrity or confidentiality of services offered using an electronic information system by essential entities of the type referred to in ▌Directive (EU) 2022/2555 or to other aspects of public interest protection. Therefore it is necessary to establish rules which ensure mitigation of those risks. As a result, market surveillance authorities should take measures to require the economic operator to ensure that the product no longer presents that risk, to recall it or to withdraw it, depending on the risk. As soon as a market surveillance authority restricts or forbids the free movement of a product in such way, the Member State should notify without delay the Commission and the other Member States of the provisional measures, indicating the reasons and justification for the decision. Where a market surveillance authority adopts such measures against products presenting a risk, the Commission should enter into consultation with the Member States and the relevant economic operator or operators without delay and should evaluate the national measure. On the basis of the results of this evaluation, the Commission should decide whether the national measure is justified or not. The Commission should address its decision to all Member States and immediately communicate it to them and the relevant economic operator or operators. If the measure is considered justified, the Commission may also consider adopting proposals to revise the respective Union legislation.

Removed(59) For products with digital elements presenting a significant cybersecurity risk, and where there is reason to believe that these are not compliant with this Regulation, or for products that are compliant with this Regulation, but that present other important risks, such as risks to the health or safety of persons, fundamental rights or the provision of the services by essential entities of the type referred to in ▌Directive (EU) 2022/2555, the Commission may request ENISA to carry out an evaluation. Based on that evaluation, the Commission may adopt, through implementing acts, corrective or restrictive measures at Union level, including ordering withdrawal from the market, or recalling of the respective products, within a reasonable period, commensurate with the nature of the risk. The Commission may have recourse to such intervention only in exceptional circumstances that justify an immediate intervention to preserve the good functioning of the internal market, and only where no effective measures have been taken by surveillance authorities to remedy the situation. Such exceptional circumstances may be emergency situations where, for example, a non-compliant product is widely made available by the manufacturer throughout several Member States, used also in key sectors by entities that fall within the scope of Directive (EU) 2022/2555, while containing known vulnerabilities that are being exploited by malicious actors and for which the manufacturer does not provide available patches. The Commission may intervene in such emergency situations only for the duration of the exceptional circumstances and if the non-compliance with this Regulation or the important risks presented persist.

Removed(60) In cases where there are indications of non-compliance with this Regulation in several Member States, market surveillance authorities should be able to carry out joint activities with other authorities, with a view to verifying compliance and identifying cybersecurity risks of products with digital elements.

Removed(61) Simultaneous coordinated control actions (‘sweeps’) are specific enforcement actions by market surveillance authorities that can further enhance product security. Sweeps should, in particular, be conducted where market trends, consumer complaints or other indications suggest that certain product categories are often found to present cybersecurity risks. ENISA should submit proposals for categories of products for which sweeps should be organised to the market surveillance authorities, based, among others, on the notifications of product vulnerabilities and incidents it receives. The Commission should also coordinate maket surveillance authorities in the regular inspections of products with digital elements that might present a security risk for the Union, including in light of the non-technical risk factor.

Removed(62) In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 of the Treaty should be delegated to the Commission in respect of updates to the list of critical products in Annex III and specifying the definitions of the these product categories. Power to adopt acts in accordance with that Article should be delegated to the Commission to identify products with digital elements covered by other Union rules which achieve the same level of protection as this Regulation, specifying whether a limitation or exclusion from the scope of this Regulation would be necessary as well as the scope of that limitation, if applicable. Power to adopt acts in accordance with that Article should also be delegated to the Commission in respect of specifying the European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 that can be used to demonstrate conformity with the essential requirements or parts therefore as set out in Annex I of this Regulation, the potential mandating of certification of certain highly critical products with digital elements based on criticality crieria set out in this Regulation, as well as for specifying the minimum content of the EU declaration of conformity and supplementing the elements to be included in the technical documentation. Powers to adopt delegated acts should also be delegated to the Commission to specify the format and elements of the software bill of materials, specify further the format and procedure of the notifications on actively exploited vulnerabilities and significant incidents submitted to ENISA by the manufacturers. Where necessary, the Commission should be empowered to adopt delegated acts to adopt common specifications in respect of the essential requirements set out in Annex I. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Inter-institutional Agreement of 13 April 2016 on Better Law-Making. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. For the purpose of developing delegated acts pursuant to this Regulation, the Commission should consult the cyber resilience Expert Group. The Commission should also conduct regular structural dialogue with economic operators and carry out public consultations, inter alia for the purposes of evaluating the scope of this Regulation and whether certain categories of products should be included or excluded.

Removed(63) In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission to: ▌lay down technical specifications for labelling schemes, including harmonised labels, pictograms or any other marks related to the security of the products with digital elements, and mechanisms to promote their use, decide on corrective or restrictive measures at Union level in exceptional circumstances which justify an immediate intervention to preserve the good functioning of the internal market. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council.

Removed(64) In order to ensure trustful and constructive cooperation of market surveillance authorities at Union and national level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in carrying out their tasks.

Removed(65) In order to ensure effective enforcement of the obligations laid down in this Regulation, each market surveillance authority should have the power to impose or request the imposition of administrative fines. Maximum levels for administrative fines to be provided for in national laws for non-compliance with the obligations laid down in this Regulation should therefore be established. When deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation should be taken into account and as a minimum those explicitly established in this Regulation, including whether the manufacturer is a microenterprise, a small or medium-sized entreprise or a start-up and administrative fines have been already applied by other market surveillance authorities to the same operator for similar infringements. Such circumstances can be either aggravating, in situations where the infringement by the same operator persists on the territory of other Member States than the one where an administrative fine has already been applied, or mitigating, in ensuring that any other administrative fine considered by another market surveillance authority for the same economic operator or the same type of breach should already take account, along with other relevant specific circumstances, of a penalty and the quantum thereof imposed in other Member States. In all such cases, the cumulative administrative fine that could be applied by market surveillance authorities of several Member States to the same economic operator for the same type of infringement should ensure the respect of the principle of proportionality.

Removed(66) Where administrative fines are imposed on persons that are not an undertaking, the competent authority should take account of the general level of income in the Member State as well as the economic situation of the person when considering the appropriate amount of the fine. It should be for the Member States to determine whether and to what extent public authorities should be subject to administrative fines.

Removed(66a) The revenues generated from the payments of penalties should be used to strengthen the level of cybersecurity within the Union, including by developing capacity and skills related to cybersecurity, improving economic operators' cyber resilience, in particular of microenterprises and of small and medium-sized enterprises and more in general fostering public awareness of cyber security issues.

Removed(67) In its relationships with third countries, the EU endeavours to promote international trade in regulated products. A broad variety of measures can be applied in order to facilitate trade, including several legal instruments such as bilateral (inter-governmental) Mutual Recognition Agreements (MRAs) for conformity assessment and marking of regulated products. MRAs are established between the Union and third countries, which are on a comparable level of technical development and have a compatible approach concerning conformity assessment. These agreements are based on the mutual acceptance of certificates, marks of conformity and test reports issued by the conformity assessment bodies of either party in conformity with the legislation of the other party. Currently MRAs are in place for several countries. The agreements are concluded in a number of specific sectors, which might vary from one country to another. In order to further facilitate trade, and recognising that supply chains of products with digital elements are global, MRAs concerning conformity assessment may be concluded for products regulated under this Regulation by the Union in accordance with Article 218 TFEU. Cooperation with partner countries is also important, in order to strengthen cyber resilience globally, as in the long term this will contribute to a strengthened cybersecurity framework both within and outside of the EU.

Removed(68) The Commission should periodically review this Regulation, in consultation with the Expert Group and other interested parties, in particular with a view to determining the need for modification in the light of changes to societal, political, technological or market conditions.

Removed(69) Economic operators should be provided with a sufficient time to adapt to the requirements of this Regulation. This Regulation should apply [36 months] from its entry into force, with the exception of the reporting obligations concerning actively exploited vulnerabilities and incidents, which should apply [18 months] from the entry into force of this Regulation.

Removed(69a) This Regulation will generate additional costs for microenterprises and small and medium-sized enterprises, including start-ups. In order to support these enterprises, the Commission should establish financial and technical support that enable these enterprises to contribute to the growth of the European economy and the European cybersecurity landscape, including by streamlining the financial support from the Digital Europe Programme and other relevant Union programmes as well as supporting companies and public sector organisations through European Digital Innovation Hubs. Furthermore, Member States should consider all possible complementary actions aiming to providing guidance and support for microenterprises and for small and medium-sized enterprises, including via the establishment of regulatory sandboxes, cybersecurity hubs and start-up accelerators.

Removed(70) Since the objective of this Regulation cannot be sufficiently achieved by the Member States but can rather, by reason of the effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.

Removed(71) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and delivered its opinion on 9 November 2022.

Removed(71a) The Commission should amend the legislative financial statement accompanying this Regulation by providing ENISA with nine additional full-time equivalent and corresponding additional appropriations in order to fulfil its additional tasks provided for in this Regulation,

RemovedHAVE ADOPTED THIS REGULATION:

RemovedGENERAL PROVISIONS

RemovedThis Regulation lays down:

Removed(a) rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;

Removed(b) essential requirements for the design, development and production of products with digital elements, and obligations for economic operators in relation to these products with respect to cybersecurity;

Removed(c) essential requirements for the vulnerability handling processes put in place by manufacturers to ensure the cybersecurity of products with digital elements during the whole life cycle, and obligations for economic operators in relation to these processes;

Removed(d) rules on market monitoring, surveillance and enforcement of the above-mentioned rules and requirements.

Removed1. This Regulation applies to products with digital elements made available on the market that can have a direct or indirect ▌data connection to a device or network.

Removed2. This Regulation does not apply to products with digital elements to which the following Union legislative acts apply:

Removed(a) Regulation (EU) 2017/745;

Removed(b) Regulation (EU) 2017/746;

Removed(c) Regulation (EU) 2019/2144.

Removed3. This Regulation does not apply to products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139.

Removed3a. This Regulation applies to free and open-source software only where such software is made available on the market in the course of a commercial activity.

Removed4. The application of this Regulation to products with digital elements covered by other Union rules laying down requirements that address all or some of the risks covered by the essential requirements set out in Annex I may be limited or excluded, where:

Removed(a) such limitation or exclusion is consistent with the overall regulatory framework applying to those products; and

Removed(b) the sectoral rules achieve the same level of protection as the one provided for by this Regulation.

RemovedThe Commission is empowered to adopt delegated acts in accordance with Article 50 to amend this Regulation specifying whether such limitation or exclusion is necessary, the concerned products and rules, as well as the scope of the limitation, if relevant.

Removed4a. This Regulation does not apply to spare parts that are exclusively manufactured to replace identical parts and that are supplied by the manufacturer of the original products with digital elements.

Removed5. This Regulation does not apply to products with digital elements developed exclusively for national security or military purposes or to products specifically designed to process classified information.

RemovedFor the purposes of this Regulation, the following definitions apply:

Removed(1) ‘product with digital elements’ means any software or hardware product and its remote data processing solutions, including software or hardware components to be placed on the market separately;

Removed(2) ‘remote data processing’ means any data processing at a distance for which the software is designed and developed by or on behalf of the manufacturer▌, and the absence of which would prevent the product with digital elements from performing one of its functions;

Removed(3) ‘critical product with digital elements’ means a product with digital elements that presents a cybersecurity risk in accordance with the criteria laid down in Article 6(2) and whose core functionality is set out in Annex III;

Removed(4) ‘highly critical product with digital elements’ means a product with digital elements that presents a cybersecurity risk in accordance with the criteria laid down in Article 6(5);

Removed(4a) ‘cybersecurity’ means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881;

Removed(5) ‘operational technology’ means programmable digital systems or devices that interact with the physical environment or manage devices that interact with the physical environment;

Removed(6) ‘software’ means the part of an electronic information system which consists of computer code;

Removed(7) ‘hardware’ means a physical electronic information system, or parts thereof capable of processing, storing or transmitting of digital data;

Removed(8) ‘component’ means software or hardware intended for integration into an electronic information system;

Removed(9) ‘electronic information system’ means any system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;

Removed(10) ‘logical connection’ means a virtual representation of a data connection implemented through a software interface;

Removed(11) ‘physical connection’ means any connection between electronic information systems or components implemented using physical means, including through electrical or mechanical interfaces, wires or radio waves;

Removed(12) ‘indirect connection’ means a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network;

Removed(13) ‘privilege’ means an access right granted to particular users or programmes to perform security-relevant operations within an electronic information system;

Removed(14) ‘elevated privilege’ means an access right granted to particular users or programmes to perform an extended set of security-relevant operations within an electronic information system that, if misused or compromised, could allow a malicious actor to gain wider access to the resources of a system or organisation;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=4 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
  year = {2024},
  date = {2024-03-12},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=4}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=4},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}