Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2023-0253 → TA-9-2024-0130

From
A-9-2023-0253 Plenary report of 27 Jul 2023
To
TA-9-2024-0130 Adopted text of 12 Mar 2024
Changes
Not comparable
Paragraphs
+13 added · −868 removed · 0 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
Cyber Resilience Act

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 7 of 17: Paragraphs 303–362

Removed11. Manufacturers shall either provide the EU declaration of conformity with the product with digital elements or include in the instructions and information set out in Annex II the internet address at which the EU declaration of conformity can be accessed.

Removed12. From the placing on the market and for at least the support period ▌, manufacturers who know or have reason to believe that the product with digital elements or the processes put in place by the manufacturer are not in conformity with the essential requirements set out in Annex I shall immediately take the corrective measures necessary to bring that product with digital elements or the manufacturer’s processes into conformity, to withdraw or to recall the product, as appropriate.

Removed13. Manufacturers shall, further to a reasoned request from a market surveillance authority, provide that authority, in a language which can be easily understood by it, with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements and of the processes put in place by the manufacturer with the essential requirements set out in Annex I. They shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by the product with digital elements, which they have placed on the market.

Removed14. A manufacturer that ceases its operations and, as a result, is not able to comply with the obligations laid down in this Regulation shall inform, before the cease of operation takes effect, the relevant market surveillance authorities about this situation, as well as, by any means available and to the extent possible, the users of the concerned products with digital elements placed on the market.

Removed15. The Commission, after consulting the Expert Group and taking account of international standards, is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by specifying the format and elements of the software bill of materials set out in Section 2, point (1), of Annex I. ▌

Removed1. The manufacturer shall▌notify to ENISA any actively exploited vulnerability contained in the product with digital elements in accordance with paragraph 1a of this Article. ▌ENISA shall, without undue delay, unless for justified cybersecurity risk-related grounds, forward the notification to the CSIRT designated for the purposes of coordinated vulnerability disclosure in accordance with Article 12 of Directive (EU) 2022/2555 of Member States concerned upon receipt and inform the market surveillance authority about the notified vulnerability. Where a notified vulnerability has no corrective or mitigating measures available, ENISA shall ensure that information about the notified vulnerability is shared in line with strict security protocols and on a need-to-know-basis.

Removed1a. Notifications as referred to in paragraph 1 shall be subject to the following procedure:

Removed(a) an early warning, without undue delay and in any event within 24 hours of the manufacturer becoming aware of the existence of an actively exploited vulnerability, including whether any known corrective or recommended risk mitigating measure is available;

Removed(b) a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which, where applicable, updates the general information referred to in point (a), including any corrective or mitigating measures taken and indicates an assessment of extent of the vulnerability, including its severity and impact;

Removed(c) a final report, within one month after the submission of the vulnerability notification under point (b) or when a corrective or mitigating measure is available, including at least the following:

Removed(i) a description of the vulnerability, including its severity and impact;

Removed(ii) where available, information concerning any actor that has exploited or that is exploiting the vulnerability;

Removed(iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.

Removed1b. After a security update is made available or another form of corrective or mitigating measures is put in place, ENISA shall add the notified vulnerability pursuant to paragraph 1 of this Article to the European vulnerability database referred to in Article 12 of Directive (EU) 2022/2555.

Removed2. The manufacturer shall ▌ notify to ENISA any significant incident having impact on the security of the product with digital elements in accordance with paragraph 2b of this Article. ENISA shall, without undue delay, unless for justified cybersecurity risk-related grounds, forward the notifications to the single point of contact designated in accordance with Article 8 of Directive (EU) 2022/2555 of the Member States concerned and inform the market surveillance authority about the notified incidents. The mere act of notification shall not subject the notifying entity to increased liability.

Removed2a. An incident shall be considered to be significant as referred to in paragraph 2, where:

Removed(a) it has caused or is capable of causing severe operational disruption of the production or the services for the manufacturer concerned, which would impact the security of a product; or

Removed(b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

Removed2b. Notifications as referred to in paragraph 2 shall be subject to the following procedure:

Removed(a) an early warning, without undue delay and in any event within 24 hours of the manufacturer becoming aware of the significant incident, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;

Removed(b) an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the significant incident, which, where applicable, shall update the information referred to in point (a) and indicates an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;

Removed(c) a final report, within one month after the submission of the incident notification under point (b), including at least the following:

Removed(i) a detailed description of the incident, including its severity and impact;

Removed(ii) the type of threat or root cause that is likely to have triggered the incident;

Removed(iii) applied and ongoing mitigation measures;

Removed(iv) where applicable, the cross-border impact of the incident;

RemovedIn the event of an ongoing incident at the time of the submission of the final report referred to in point (d) of this paragraph, Member States shall ensure that the manufacturer concerned provides a progress report at that time and a final report within one month of their handling of the incident.

Removed2c. Manufacturers that have notified significant incidents according to this Regulation and that are also identified as essential entities or important entities under the Directive (EU) 2022/2555 shall be deemed compliant with the requirements under Article 23 of Directive (EU) 2022/2555. ENISA shall forward the notifications received pursuant to this Regulation to the responsible CSIRT according to Directive (EU) 2022/2555. An entity may only be fined once for non-compliance with overlapping requirements.

Removed2d. Where necessary, ENISA or the relevant CSIRT may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or significant incident.

Removed2e. Manufacturers that qualify as microenterprises or as small or medium-sized enterprises shall be exempt from paragraph 1a, point (a) and paragraph 2b, point (a).

Removed3. ENISA shall submit to the European cyber crisis liaison organisation network (EU-CyCLONe) established by Article 16 of Directive (EU) 2022/2555 information notified pursuant to paragraphs 1 and 2 if such information is relevant for the coordinated management of large-scale cybersecurity incidents and crises at an operational level.

Removed4. The manufacturer shall inform, without undue delay and after becoming aware, the impacted users of the product with digital elements , and where appropriate all users, about the significant incident and, where necessary, about risk mitigation and any corrective measures that the user can deploy to mitigate the impact of the significant incident.

Removed4a. ENISA shall ensure that notifications pursuant to paragraphs 1 and 2 are submitted via channels of communication and stored on servers that ensure the highest possible levels of cybersecurity and protection from malicious actors.

Removed4b Where public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or where disclosure of the significant incident is otherwise in the public interest, ENISA and, where appropriate, the CSIRTs or the competent authorities of the relevant Member States, may, after consulting the manufacturer concerned, inform the public about the significant incident or require the manufacturer to do so.

Removed5. The Commission shall adopt delegated acts in accordance with Article 50 to supplement this Regulation by specifying further the ▌format and procedure of the notifications submitted pursuant to paragraphs 1 and 2. Those delegated acts shall be adopted by ... [12 months after the date of entry into force of this Regulation].

Removed6. ENISA, on the basis of the notifications received pursuant to paragraphs 1 and 2, shall prepare a biennial technical report on emerging trends regarding cybersecurity risks in products with digital elements and submit it to the Cooperation Group referred to in Article 14 of Directive (EU) 2022/2555. The first such report shall be submitted within 24 months after the obligations laid down in paragraphs 1 and 2 start applying. ENISA shall include relevant information from its technical reports in its report on the state of cybersecurity in the Union pursuant to Article 18 of Directive (EU) 2022/2555.

Removed6a. ENISA shall establish a secure digital reporting mechanism, after having consulted the Expert Group, in order to simplify reporting obligations of manufacturers. This mechanism shall serve as a single entry point for reporting obligations established under this Regulation and, where possible, other Union law.

Removed▌Article 11a Voluntary notification

Removed1. In addition to the notification obligations set out in Article 11, notifications may be submitted to ENISA on a voluntary basis by the following:

Removed(a) manufacturers, with regard to incidents, cyber threats and near misses;

Removed(b) entities other than those referred to in point (a), regardless of whether they fall within the scope of this Regulation, with regard to significant and non-significant incidents, cyber threats and near misses;

Removed(c) any actor with regard to vulnerabilities which may be included in the European vulnerability database referred to in Article 12 of Regulation 2022/2555.

Removed2. ENISA shall process the notifications referred to in paragraph 1, point (a) of this Article in accordance with the procedure laid down in Article 11. ENISA may prioritise the processing of mandatory notifications over voluntary notifications.

Removed3. In order to simplify the voluntary notifications, it shall be possible to notify these through the secure digital reporting mechanism referred to in Article 11(6a).

Removed4. Where appropriate, ENISA shall ensure the confidentiality and appropriate protection of the information provided by the notifying entity. Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, voluntary reporting shall not result in the imposition of any additional obligations upon the notifying entity to which it would not have been subject had it not submitted the notification.

Removed1. In order to facilitate reporting on the security of products, manufacturers shall designate a point of single contact to enable users to communicate directly and rapidly with them, where applicable by electronic means and in a user-friendly manner, including by allowing users of the product to choose the means of communication set out in point 1 of Annex II, which shall not solely rely on automated tools.

Removed2. In addition to the obligations provided under Directive 2000/31/EC of the European Parliament and of the Council , manufacturers shall make public the information necessary for the end users in order to easily identify and communicate with their points of single contact. That information shall be easily accessible and shall be kept up to date.

Removed1. A manufacturer may appoint an authorised representative by a written mandate.

Removed2. The obligations laid down in Article 10(1) to (7) first indent and (9) shall not form part of the authorised representative's mandate.

Removed3. An authorised representative shall perform the tasks specified in the mandate received from the manufacturer. It shall provide a copy of the mandate to the market surveillance authorities upon request. The mandate shall allow the authorised representative to do at least the following:

Removed(a) keep the EU declaration of conformity referred to in Article 20 and the technical documentation referred to in Article 23 at the disposal of the market surveillance authorities for ten years after the product with digital elements has been placed on the market;

Removed(aa) where the authorised representative has a reason to believe that a product with digital elements in question presents a cybersecurity risk, inform the manufacturer;

Removed(b) further to a reasoned request from a market surveillance authority, provide that authority with all the information and documentation necessary to demonstrate the conformity of the product with digital elements;

Removed(c) cooperate with the market surveillance authorities, at their request, on any action taken to effectively eliminate the risks posed by a product with digital elements covered by the authorised representative's mandate.

Removed1. Importers shall only place on the market products with digital elements that comply with the essential requirements set out in Section 1 of Annex I and where the processes put in place by the manufacturer are compliant with the essential requirements set out in Section 2 of Annex I.

Removed2. Before placing a product with digital elements on the market, importers shall ensure that:

Removed(a) the appropriate conformity assessment procedures referred to in Article 24 have been carried out by the manufacturer;

Removed(b) the manufacturer has drawn up the technical documentation;

Removed(c) the product with digital elements bears the CE marking referred to in Article 22, the EU declaration of conformity is available and the product is accompanied by the information and instructions for use as set out in Annex II;

Removed(ca) all the documents proving the fulfilment of the requirements set out in this Article have been received from the manufacturer.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2023-0253 and TA-9-2024-0130”. Text, 12 March 2024. from A-9-2023-0253, to TA-9-2024-0130. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=7 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-12,
  author = {{European Parliament}},
  title = {{Changes between A-9-2023-0253 and TA-9-2024-0130}},
  year = {2024},
  date = {2024-03-12},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=7}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0253/compare/TA-9-2024-0130?all=1&part=7},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2023-0253, to TA-9-2024-0130. Data: European Parliament Open Data (CC BY 4.0)}
}