Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2023-0307 → TA-9-2024-0354
- From
- A-9-2023-0307 Plenary report of 26 Oct 2023
- To
- TA-9-2024-0354 Adopted text of 24 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +15 added · −208 removed · 0 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
- Title (to)
- Managed security services
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 1 of 7: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
RemovedDRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
AddedP9_TA(2024)0354
Removedon the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
AddedManaged security services
Removed(COM(2023)0208 – C90137/2023 – 2023/0108(COD))
AddedCommittee on Industry, Research and Energy
AddedPE752.802
AddedEuropean Parliament legislative resolution of 24 April 2024 on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services (COM(2023)0208 – C9-0137/2023 – 2023/0108(COD))
6 unchanged paragraphs
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2023)0208),
– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90137/2023),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
– having regard to the opinion of the European Economic and Social Committee of 13 July 2023,
Added– having regard to the provisional agreement approved by the committee responsible under Rule 74(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 21 March 2024 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,
4 unchanged paragraphs
– having regard to Rule 59 of its Rules of Procedure,
– having regard to the letter from the Committee on the Internal Market and Consumer Protection,
– having regard to the report of the Committee on Industry, Research and Energy (A9-0307/2023),
1. Adopts its position at first reading hereinafter set out;
Change 1
Added2. Takes note of the statement by the Commission annexed to this resolution, which will be published in the C series of the Official Journal of the European Union;
3. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
4. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 2
RemovedAMENDMENTS BY THE EUROPEAN PARLIAMENT*
AddedP9_TC1-COD(2023)0108
Removedto the Commission proposal
AddedPosition of the European Parliament adopted at first reading on 24 April 2024 with a view to the adoption of Regulation (EU) 2025/… of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
Removed---------------------------------------------------------
Added(As an agreement was reached between Parliament and Council, Parliament's position corresponds to the final legislative act, Regulation (EU) 2025/37.)
Removed2023/0108 (COD)
AddedANNEX TO THE LEGISLATIVE RESOLUTION
RemovedProposal for a
AddedPolitical statement by the Commission on the occasion of the adoption of Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services
RemovedREGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
AddedThis Regulation amending the Cybersecurity Act adds the possibility to develop European certification cybersecurity schemes for managed security services. At the same time, it is acknowledged that a thorough review of the Cybersecurity Act is of utmost importance, including the assessment of the procedures leading to the preparation, adoption and review of European cybersecurity certification schemes. This review should be based on a deep analysis and broad consultation on the impact, effectiveness and efficiency of the functioning of the European cybersecurity certification framework. The analysis carried out as part of the evaluation established in Article 67 of the Cybersecurity Act should include on-going scheme development activities, such as the one concerning European cybersecurity certification scheme for cloud services (EUCS) as well as those of adopted schemes such as the one concerning the European Common Criteria-based cybersecurity certification scheme (EUCC).
Removedamending Regulation (EU) 2019/881 as regards managed security services
AddedIn particular, the review should identify the strengths and weaknesses of the procedures leading to cybersecurity certification schemes and formulate recommendations for future improvements. It should also address aspects relating to stakeholder consultations and transparency of the process.
Removed(Text with EEA relevance)
AddedAccordingly, the Commission, which is responsible for the review of the Cybersecurity Act, shall ensure that the review takes into account as appropriate the necessary elements mentioned in light of Article 67 when presenting the review to the co-legislators.
RemovedTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
RemovedHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
RemovedHaving regard to the proposal from the European Commission,
RemovedAfter transmission of the draft legislative act to the national parliaments,
RemovedHaving regard to the opinion of the European Economic and Social Committee,
RemovedHaving regard to the opinion of the Committee of the Regions;
RemovedActing in accordance with the ordinary legislative procedure,
RemovedWhereas:
Removed(1) Regulation (EU) 2019/881 of the European Parliament and of the Council sets up a framework for the establishment of European cybersecurity certification schemes for the purpose of ensuring an adequate level of cybersecurity for information and communications technology (ICT) products, ICT services and ICT processes in the Union, as well as for the purpose of avoiding the fragmentation of the internal market with regard to cybersecurity certification schemes in the Union.
Removed(1a) In order to ensure the Union’s resilience to cyberattacks and to prevent any vulnerabilities in the Union market, this Regulation is intended to complement the horizontal regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements in accordance with Regulation (EU) .../... of the European Parliament and of the Council (2022/0272(COD)), by setting up essential requirements for cybersecurity managed services, their application and their trustworthiness.
Removed(2) Managed security services, which are services consisting of carrying out, or providing assistance for, activities relating to their customers’ cybersecurity risk management, including detection, response to or recovery from incidents, have gained increasing importance in the prevention and mitigation of cybersecurity incidents. The activities of the providers of managed security services consist of services relating to prevention, identification, protection, detection, analysis, containment, response and recovery, including, but not limited to, cyber threat intelligence provision, real time threat monitoring through proactive techniques, including security-by-design, risk assessment, extended detection, remediation and response. Accordingly, the providers of those services are considered as essential or important entities belonging to a sector of high criticality pursuant to Directive (EU) 2022/2555 of the European Parliament and of the Council. Pursuant to Recital 86 of that Directive, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy, play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and pose a particular risk because of their close integration in the operations of their customers. Essential and important entities within the meaning of Directive (EU) 2022/2555 should therefore exercise increased diligence in selecting a managed security service provider.
Removed(3) Managed security services providers also play an important role in the EU Cybersecurity Reserve whose gradual set-up is supported by Regulation (EU) …/…. [laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents]. The EU Cybersecurity Reserve is to be used to support response and immediate recovery actions in case of significant and large-scale cybersecurity incidents. Regulation (EU) …/…[laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents] lays down a selection process for the providers forming the EU Cybersecurity Reserve, which should, inter alia, take into account whether the provider concerned has obtained a European or national cybersecurity certification. The relevant services provided by trusted providers according to Regulation (EU) …./…..[laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents] correspond to managed security services in accordance with this Regulation.
Removed(4) Certification of managed security services is not only relevant in the selection process for the EU Cybersecurity Reserve but it is also an essential quality indicator for private and public entities that intend to purchase such services. In light of the criticality of the managed security services and the sensitivity of the data they process, certification could provide potential customers with important guidance and assurance about the trustworthiness of these services. European certification schemes for managed security services contribute to avoiding fragmentation of the single market. This Regulation therefore aims at enhancing the functioning of the internal market.
Removed(4a) European certification schemes for managed security services should lead to the uptake of those services and to increased competition in the field, taking into account the specific needs of both providers and beneficiaries. Those schemes should, therefore, strike a balance between the their objective and the potential regulatory, administrative and financial burden that providers, especially microenterprises or small and medium-sized enterprises (SMEs), could encounter. Additionally, the schemes should encourage the use of certified managed security services by contributing to the accessibility thereof, especially for smaller actors, such as microenterprises and SMEs, as well as local and regional authorities which have limited capacity and resources, but which are more prone to cybersecurity breaches with financial, legal, reputational, and operational implications.
Removed(4b) The Union certification scheme for managed security services should ensure the availability of secure and high-quality services which guarantee a safe digital transition and contribute to the achievement of targets set up in the Digital Decade Policy Programme, especially with regard to the goal that 75% of Union undertakings start using Cloud, AI or Big Data, that more than 90% of microenterprises and SMEs reach at least a basic level of digital intensity and that key public services are offered online.
Removed(4c) In the current fast evolving digital and technological landscape, the offer of educational resources and formal trainings differ and knowledge can be acquired in various ways, both formal, for example through university or courses and non-formal, for example through on the job trainings or longstanding work experience in the relevant field.
Removed(5) In addition to the deployment of ICT products, ICT services or ICT processes, managed security services often provide additional service features that rely on the competences, expertise and experience of their personnel. A very high level of these competences, expertise and experience as well as appropriate internal procedures should be part of the security objectives in order to ensure a very high quality of the managed security services provided. In order to ensure that all aspects of a managed security service can be covered by a dedicated certification scheme, it is therefore necessary to amend Regulation (EU) 2019/881. The development of certification schemes established pursuant to this Regulation should take into account the results and recommendations of the evaluation and review provided for in this Regulation.
Removed(5a) With a view to facilitating the growth of a reliable Union market, whilst also creating partnerships with likeminded third countries, including in light of the provisions of the Regulation (EU) .../... of the European Parliament and of the Council (2023/0109(COD)) with regard to the access to the EU Cybersecurity Reserve, the certification process established within the framework established by this Regulation should be streamlined to ensure international recognition and alignment with international standards.
Removed(5b) With the aim of ensuring the development of a trustworthy Union market for managed security services, the providers thereof and Member States should collaborate and contribute to the collection of data on the situation and the evolution of the cybersecurity labour market.
Removed(5c) A Union-wide coordinated approach to strengthening the resilience of critical infrastructure is based on the Member States’ capacity building. However, the Union is faced with a talent gap, characterised by a shortage of skilled professionals, and a rapidly evolving threat landscape as acknowledged in the Commission communication of 18 April 2023 on the Cybersecurity Skills Academy. Therefore, in order to facilitate the emergence of high-quality, essential managed security services and to have a better overview of the composition of the Union cybersecurity workforce, cooperation between Member States, the Commission, ENISA and stakeholders, including the private sector and academia, should be strengthened through the development of public-private partnerships, support of research and innovation initiatives, the development and mutual recognition of common standards and certification of cybersecurity skills, including through the European Cyber Security Skills Framework. This should also facilitate the mobility of cybersecurity professionals within the Union as well as the integration of cybersecurity knowledge and training in educational programmes, while ensuring access to apprenticeships and traineeships for young people, including persons living in disadvantaged regions, such as islands, sparsely populated, rural and remote areas. Those measures should also aim to attract more women and girls in the field and contribute towards addressing the gender gap in science, technology, engineering, and mathematics. The private sector should also aim to deliver on-the-job training addressing the most in-demand skills, involving public administration and start-ups, as well as microenterprises and SMEs.
Removed(5d) Appropriate funding and resources should be ensured for the purpose of the additional tasks entrusted to ENISA by the amendments to Regulation (EU) 2019/881 introduced by this Regulation.
Removed(5e) In order to supplement certain non-essential elements of this Regulation, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission to provide for a European cybersecurity certification scheme for ICT products, ICT services, ICT processes and managed security services. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making . In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2023-0307 and TA-9-2024-0354”. Text, 24 April 2024. from A-9-2023-0307, to TA-9-2024-0354. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0307/compare/TA-9-2024-0354?all=1 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-24,
author = {{European Parliament}},
title = {{Changes between A-9-2023-0307 and TA-9-2024-0354}},
year = {2024},
date = {2024-04-24},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0307/compare/TA-9-2024-0354?all=1}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2023-0307/compare/TA-9-2024-0354?all=1},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2023-0307, to TA-9-2024-0354. Data: European Parliament Open Data (CC BY 4.0)}
}