Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0253 → TA-9-2024-0130
- From
- A-9-2023-0253 Plenary report of 27 Jul 2023
- To
- TA-9-2024-0130 Adopted text of 12 Mar 2024
- Changes
- Not comparable
- Paragraphs
- +13 added · −868 removed · 0 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
- Title (to)
- Cyber Resilience Act
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 5 of 17: Paragraphs 183–242
Removed(15) ‘endpoint’ means any device that is connected to a network and serves as an entry point to that network;
Removed(16) ‘networking or computing resources’ means data or hardware or software functionality that is accessible either locally or through a network or another connected device;
Removed(17) ‘economic operator’ means the manufacturer, the authorised representative, the importer, the distributor, or any other natural or legal person who is subject to obligations laid down by this Regulation;
Removed(18) ‘manufacturer’ means any natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under his or her name or trademark, whether for payment, monetisation or free of charge;
Removed(19) ‘authorised representative’ means any natural or legal person established within the Union who has received a written mandate from a manufacturer to act on his or her behalf in relation to specified tasks;
Removed(20) ‘importer’ means any natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union;
Removed(21) ‘distributor’ means any natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties;
Removed(21a) ‘microenterprises’, ‘small enterprises’ and ‘medium sized enterprises’ means microenterprises, small enterprises and medium-sized enterprises as defined in Commission Recommendation 2003/361/EC;
Removed(21b) 'consumer' means any natural person who, under the circumstances of this Regulation, is acting for purposes which are outside their trade, business, craft or profession;
Removed(21c) ‘support period’ means the period during which the manufacturer ensures that vulnerabilities of the product with digital elements are handled effectively and in accordance with the essential requirements set out in Annex I, Section 2;
Removed(22) ‘placing on the market’ means the first making available of a product with digital elements on the Union market;
Removed(23) ‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
Removed(24) ‘intended purpose’ means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;
Removed(25) ‘reasonably foreseeable use’ means use that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions;
Removed(26) ‘reasonably foreseeable misuse’ means the use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems;
Removed(27) ‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;
Removed(28) ‘conformity assessment’ means the process of verifying whether the essential requirements set out in Annex I have been fulfilled;
Removed(29) ‘conformity assessment body’ means a body defined in Article 2(13) of Regulation (EU) No 765/2008;
Removed(30) ‘notified body’ means a conformity assessment body designated in accordance with Article 33 of this Regulation and other relevant Union harmonisation legislation;
Removed(31) ‘substantial modification’ means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential requirements set out in Section 1 of Annex I or results in a modification to the intended use for which the product with digital elements has been assessed, excluding necessary security updates that aim to mitigate vulnerabilities;
Removed(32) ‘CE marking’ means a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential requirements set out in Annex I and other applicable Union legislation harmonising the conditions for the marketing of products (‘Union harmonisation legislation’) providing for its affixing;
Removed(33) ‘market surveillance authority’ means the authority as defined in Article 3, point (4) of Regulation (EU) 2019/1020;
Removed(34) ‘harmonised standard’ means a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012;
Removed(34a) ‘international standard’ means an international standard as defined in Article 2, point (1)(a) of Regulation (EU) No 1025/2012;
Removed(35) ‘▌risk’ means risk as defined in Article 6, point (9) of Directive (EU) 2022/2555;
Removed(36) ‘significant cybersecurity risk’ means a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption;
Removed(37) ‘software bill of materials’ or ‘SBOM’ means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;
Removed(38) ‘vulnerability’ means a vulnerability as defined in Article 6, point (15) of Directive (EU) 2022/2555;
Removed(39) ‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that execution of malicious code was performed by an actor on a system without permission of the system owner;
Removed(39a) ‘incident’ means an incident as defined in Article 6, point (6) of Directive (EU) 2022/2555;
Removed(39b) ‘near miss’ means a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555;
Removed(39c) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;(40) ‘personal data’ means data as defined in Article 4, point (1), of Regulation (EU) 2016/679.
Removed1. Member States shall not impede, for the matters covered by this Regulation, the making available on the market of products with digital elements which comply with this Regulation.
Removed2. ▌Member States shall not prevent the presentation and use of a prototype product with digital elements which does not comply with this Regulation, provided that the availability of such a product is limited in time and geographical area and is supplied exclusively for testing and, where possible, a visible sign indicating its non-compliance.
Removed3. Member States shall not prevent the making available free of charge of unfinished software which does not comply with this Regulation provided that the software is only made available for a limited period required for testing purposes and that a visible sign clearly indicates that it does not comply with this Regulation and will not be available on the market for purposes other than testing.
Removed3a. Member States, if applicable with the support of ENISA, may establish controlled testing environments for innovative products to facilitate their development. In that context, particular support shall be provided for microenterprises, small and medium-sized enterprises, including start-ups.
RemovedProducts with digital elements shall only be made available on the market where:
Removed(1) they meet the essential requirements set out in Section 1 of Annex I, under the condition that they are properly installed, maintained, used for their intended purpose or under conditions which can reasonably be foreseen, and, where applicable, provided with the necessary security and functionality updates, and
Removed(2) the processes put in place by the manufacturer comply with the essential requirements set out in Section 2 of Annex I.
Removed1. Products with digital elements that belong to a category which is listed in Annex III shall be considered critical products with digital elements. Products which have the core functionality of a category that is listed in Annex III to this Regulation shall be considered as falling into that category. Categories of critical products with digital elements shall be divided into class I and class II as set out in Annex III, reflecting the level of cybersecurity risk related to these products.
RemovedThe integration of a product of higher class of criticality does not change the level of criticality for the product into which it is integrated.
Removed2. The Commission is empowered to adopt delegated acts in accordance with Article 50 to amend Annex III by including in the list of categories of critical products with digital elements a new category or withdrawing an existing one from that list. The first such delegated act may be adopted no earlier than two years after the date of entry into force of this Regulation. Any subsequent delegated act may be adopted at the earliest two years thereafter. When assessing the need to amend the list in Annex III, the Commission shall take into account the level of cybersecurity risk related to the category of products with digital elements. In determining the level of cybersecurity risk, one or several of the following criteria shall be taken into account:
Removed(a) the cybersecurity-related functionality of the product with digital elements, and whether the product with digital elements has at least one of following attributes:
Removed(i) it is designed to run with elevated privilege or manage privileges;
Removed(ii) it has direct or privileged access to networking or computing resources;
Removed(iii) it is designed to control access to data or operational technology;
Removed(iv) it performs a function critical to trust, in particular security functions such as network control, endpoint security, and network protection.
Removed(b) the intended use in sensitive environments, including in industrial settings or by essential entities of the type referred to in the Article 3 of Directive (EU) 2022/2555;
Removed(c) the intended use of performing critical or sensitive functions, such as processing of personal data;
Removed(d) the potential extent of an adverse impact, in particular in terms of its intensity and its ability to affect a plurality of persons;
Removed(e) the extent to which the use of products with digital elements has already caused material or non-material loss or disruption or has given rise to significant concerns in relation to the materialisation of an adverse impact.
Removed3. The Commission is empowered to adopt a delegated act in accordance with Article 50 to supplement this Regulation by specifying the definitions of the product categories under class I and class II as set out in Annex III. The delegated act shall be adopted by ... [▌ 6 months after the entry into force of this Regulation].
Removed4. Critical products with digital elements shall be subject to the conformity assessment procedures referred to in Article 24(2) and (3).
RemovedWhere a new category of critical products with digital elements is added to class I or II as set out in Annex III by means of a delegated act pursuant to paragraph 2 of this Article, it shall be subject to the relevant conformity assessment procedures referred to in Article 24(2) and (3) of this Regulation within 12 months of the date of adoption of the delegated act concerned.
Removed5. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by specifying categories of highly critical products with digital elements for which the manufacturers shall be required to obtain a European cybersecurity certificate under a European cybersecurity certification scheme at assurance level ‘high’ pursuant to Regulation (EU) 2019/881 to demonstrate conformity with the essential requirements set out in Annex I, or parts thereof. The obligation to obtain a European cybersecurity certificate shall apply within 12 months of the adoption of the relevant delegated act. When determining such categories of highly critical products with digital elements, the Commission shall take into account the level of cybersecurity risk related to the category of products with digital elements, in light of one or several of the criteria listed in paragraph 2, as well as in view of the assessment of whether that category of products is:
Removed(a) used or relied upon by the essential entities of the type referred to in Article 3 of ▌Directive (EU) 2022/2555 or will have potential future significance for the activities of these entities; or
Removed(b) relevant for the resilience of the overall supply chain of products with digital elements against disruptive events.
Removed5a. The Commission is empowered to adopt the delegated acts referred to in paragraph 5 of this Article no earlier than 12 months after the adoption of the relevant European cybersecurity certification scheme pursuant to Regulation (EU) 2019/881.
Removed1. By ... [6 months after the date of entry into force of this Regulation], the Commission shall establish an expert group on cyber resilience (the ‘Expert Group’). The Expert Group shall be appointed for a renewable three-year term by the Commission. The composition of the Expert Group shall aim to be gender and geographically balanced and shall include the following:
Removed(a) representatives of each of the following:
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=5
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 28 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=5 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
year = {2024},
date = {2024-03-12},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=5}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=5},
urldate = {2026-09-28},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}