Text · Opinion parliamentary committee draft
On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Document AFCO-PA-730186 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)
- Kind
- Opinion parliamentary committee draft AFCO-PA-730186
- Date
- 30 September 2022
- Committee
- Committee on Constitutional Affairs
- Rapporteur
- Pascal Durand
- Dossier
- 2022-0084
More facts (2)
- Formats
- Official page PDF Word
- Reference
- COM(2022)0119 – C90121/2022 – 2022/0084(COD)
In short
A summary of the text written by AI; ¶ opens the paragraph it rests on.
AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026
The Committee on Constitutional Affairs gives its draft opinion on the Commission proposal for a regulation on information security in the Union institutions and bodies. It welcomes the proposal and proposes amendments to strengthen common minimum rules, an interinstitutional approach and protection against foreign interference. The amendments would set common minimum information security rules for all Union institutions and bodies, require an interinstitutional approach to sharing EUCI and sensitive non-classified information, and simplify procedures for sharing with member states. They would require institutions and bodies to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, including vetting of third parties and clearance of staff. They would give the Interinstitutional Coordination Group a role in monitoring compliance through a yearly evaluation report and require Security Authorities to monitor compliance with the regulation and the group's guidance documents.
Position. The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible, to take into account its amendments. The amendments strengthen common minimum rules, an interinstitutional approach, monitoring by the Coordination Group and protection against foreign interference.
Key points
- The rapporteur welcomes the proposal, part of the EU Security Union Strategy adopted by the Commission on 24 July 2020, to streamline information security rules across Union institutions and bodies.
- The amendments would require an interinstitutional approach to sharing EUCI and sensitive non-classified information, with common categories and key handling principles, and simplified procedures for sharing with member states.
- They would require effective rules ensuring a common level of information security in all Union institutions and bodies, with equivalence of basic principles and common minimum standards.
- They would require the regulation to take account of new working practices, including electronic processing and exchanges of information.
- They would require the regulation to contribute to an efficient, independent and resilient administration and not to prevent institutions and bodies from fulfilling their missions or disproportionately limit their institutional autonomy.
- They would set up an Interinstitutional Coordination Group, with all Security Authorities represented, to enhance coherence and harmonise information security procedures and tools; the group could set up subgroups with specific tasks.
- They would require each institution and body to adopt specific security measures based on an internal risk assessment, while meeting common minimum requirements, and to adapt technical means to their needs and specificities.
- They would allow institutions and bodies to maintain their own marking system for internal purposes, and require common provisions for contractors' personnel, including vetting in tender procedures and termination of relationships posing a risk to democratic processes.
- They would require security measures for premises to build on an evaluation of security infrastructure and services, taking into account the supply chain and the economic and political environment of suppliers.
- They would make it imperative that all institutions and bodies use a single standard of accreditation of communication and information systems handling EUCI, to contribute to a common minimum level of protection.
- They would require institutions and bodies to safeguard the integrity of EU democratic processes and adopt provisions in tender procedures to curb foreign interference, covering security infrastructure, vetting of third parties and clearance of staff.
- They would require the Coordination Group to monitor compliance through a yearly evaluation report, and Security Authorities to monitor compliance with the regulation and the group's guidance documents; breaches would be notified no later than 1 week after the Security Authority is informed.
Who is affected
- All Union institutions and bodies, which would have to apply common minimum information security rules and monitor compliance.
- Contractors and third parties, which would face vetting in tender procedures and possible termination of relationships posing risks.
- Member states, which would benefit from simplified procedures for sharing EUCI and sensitive non-classified information.
- Security Authorities of institutions and bodies, which would monitor compliance and report breaches.
Figures and deadlines
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (30)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
Short justification
Union institutions and bodies need to share between themselves ever-increasing amounts of sensitive non-classified and European Union classified information (‘EUCI’) in a landscape of dramatically increasing threat levels. As a result, the European administration is exposed to attack in all its areas of activity. The information handled by the Union institutions and bodies is very attractive for the threat actors and needs to be swiftly and appropriately protected. Currently, the Union institutions and bodies either have their own information security rules, based on their Rules of procedure or founding act, or they do not have information security rules at all.
The rapporteur thus welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission on 24 July 2020 and which is aimed at streamlining the internal legal frameworks for information security in all Union institutions and bodies so as to protect our societies from the ever evolving threats targeting the information handled by institutions and bodies.
An efficient and independent administration relies on the security of its information. With a view to achieving their mission, the Union institutions and bodies shall benefit from a secure environment for the information they handle and store on a daily basis. In addition, providing a common baseline of standards mandatory for all would guarantee a high level of security, reduce the risk of weak links in supporting interoperability among institutions and bodies and leverage synergies thus enhancing the administration’s resilience facing evolving threats.
The Committee on Constitutional Affairs calls on the Committee on Civil Liberties, Justice and Home Affairs as the committee responsible, to take into account the following amendments:
| Text proposed by the Commission | Amendment |
|---|---|
| (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. An interinstitutional approach to the sharing of EUCI and sensitive non-classified information should be set up, with common categories of information and common key handling principles. Procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States should be simplified. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, it is high time that effective rules ensuring a common level of information security in all Union institutions and bodies be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards. |
| Text proposed by the Commission | Amendment |
|---|---|
| (4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | (4) Many procedures that were still at least partly paper-based were in recent years adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient and independent administration in carrying out their missions. At the same time, each Union institution and body retains its autonomy in determining how to implement the rules laid down in this Regulation, in line with its own security needs. This Regulation shall in no case prevent Union institutions and bodies to fulfil their mission, as entrusted by the EU legislation, or encroach on their institutional autonomy. | (5) By creating a minimum common level of protection for EUCI and non-classified information, this Regulation contributes to ensuring that the Union institutions and bodies have the support of an efficient, independent and resilient administration in carrying out their missions. This Regulation shall under no circumstances prevent Union institutions and bodies from fulfilling their mission, as entrusted by the EU legislation, or disproportionately limit their institutional autonomy. |
| Text proposed by the Commission | Amendment |
|---|---|
| (7) In order to preserve the specific nature of the European Atomic Energy Community activities regulated by Regulation 3/1958 of the Council of the European Atomic Energy Community25 , this Regulation should not apply to Euratom Classified Information. However, all information related to other Euratom activities not covered by Regulation 3/1958 should fall within the scope of this Regulation. | deleted |
| 25 EAEC Council: Regulation No 3 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. The Coordination Group should enhance the coherence of policies in the field of information security and contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, thematic sub-groups should be therefore established. Moreover, where needed, the Coordination Group should be able to set up other subgroups with specific tasks. | (9) The Coordination Group’s work needs the support of experts in different areas of information security: categorisation and marking, communication and information systems, accreditation, physical security and sharing EUCI and exchanging classified information. In order to prevent duplication of effort across the Union institutions and bodies, the Coordination Group should be able to set up subgroups with specific tasks. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body. | (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the common minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the needs and specificities of each institution and body. |
| Text proposed by the Commission | Amendment |
|---|---|
| (13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes or in the exchange of information with their particular counterparts from other institutions and bodies or from the Member States. | (13) Given the diversity of categories of non-classified information that the Union institutions and bodies have developed based on their own security information rules and in order to avoid delay in the implementation of this Regulation, Union institutions or bodies should be able to maintain their own marking system for internal purposes. |
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include, inter alia, a requirement in the tender procedures to undergo thorough vetting, taking into account the full range of the supply chain and economic and political environment in which the third parties operate. Where the relationships with third parties pose a risk to the integrity of democratic processes in the EU, they should be terminated without undue delay. |
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. Those security measures should among others build on a thorough evaluation of the relevant security infrastructure and services, taking into account the full range of the supply chain and economic and political environment in which their suppliers operate. |
| Text proposed by the Commission | Amendment |
|---|---|
| (22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is recommended that all of them use that standard in order to contribute to a general level of EUCI protection. However, as regards organisational autonomy, the decision remains with the competent authority of each institution or body. | (22) With the objective of achieving a single standard of accreditation of CISs handling and storing EUCI, the Union institutions and bodies should work together in a group set up for that purpose. It is imperative that all of them use that standard in order to contribute to a common minimum level of EUCI protection. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | This Regulation lays down common minimum information security rules for all Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community, other than Euratom Classified Information. | 1. This Regulation shall apply to all information handled and stored by the Union institutions and bodies, including information related to activities of the European Atomic Energy Community. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. These levels are based on the damage that unauthorised disclosure may cause to the legitimate private and public interests, including those of the Union, Union institutions and bodies and Member States or other stakeholders, so that the appropriate protective measures can be applied. | 3. These levels are based on the damage that unauthorised disclosure may cause to the private and public interests of the Union, Union institutions and bodies or one or more of the Member States, so that the appropriate protective measures can be applied. |
| Text proposed by the Commission | Amendment |
|---|---|
| General principles | General principles and provisions |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. | 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation. Each Union institution and body shall also take into account the coherence and interoperability of their document security framework with that of other relevant Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) integrity: the fact that the information is complete and completeness of information is unaltered; | (d) integrity: the fact that the information is complete and completeness of information is unaltered and the fact that the technical infrastructure used to share information is protected from any foreign interference. |
| Text proposed by the Commission | Amendment |
|---|---|
| 6a. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of EU democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions should at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and the clearance of staff. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report, which shall compile input from the relevant sub-groups. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and, where applicable, by its internal security rules. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. | 1. Each Union institution and body shall designate a Security Authority to assume the responsibilities assigned by this Regulation and monitor and ensure compliance by each Union institution or body concerned with the guidance documents adopted by the Coordination Group. In performing its tasks, each Security Authority shall have the support of the department or officer entrusted with Information Security tasks. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) it establishes rules and procedures in accordance with this Regulation, ensuring the protection of information for a given classification level; and | (a) it establishes rules and procedures in accordance with this Regulation and the guidance documents adopted by the Coordination Group, ensuring the protection of information for a given classification level; and |
| Text proposed by the Commission | Amendment |
|---|---|
| (b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation and where applicable, any other relevant rules and procedures. | (b) it has undergone an assessment visit in accordance with Article 53, and it has been subsequently certified that it can protect EUCI in accordance with this Regulation, the guidance documents adopted by the Coordination Group, and where applicable, any other relevant rules and procedures. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any case no later than 1 week after the Security Authority is informed of the breach; |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any case no later than 1 week after the Security Authority is informed of the breach. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 be observed. |
| Text proposed by the Commission | Amendment |
|---|---|
| (da) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body. | 1. Union institutions and bodies shall record, file, preserve and eventually eliminate, sample or transfer their EUCI documents to the relevant archives in accordance with retention policy and rules specific to the files of each Union institution and body, while taking into account the retention policy and rules of other relevant Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) monitoring compliance by Union institutions and bodies with the relevant provisions of this Regulation as well as with the guidance documents adopted by the Coordination Group. |
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2022). “DRAFT OPINION on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 30 September 2022. docId AFCO-PA-730186. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/AFCO-PA-730186 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/AFCO-PA-730186 (CC BY 4.0).
BibTeX
@misc{epw-text-afco-pa-730186,
author = {{European Parliament}},
title = {{DRAFT OPINION on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
year = {2022},
date = {2022-09-30},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/AFCO-PA-730186}},
url = {https://news.eu-parl.st-solutions.dev/texts/AFCO-PA-730186},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId AFCO-PA-730186. Data: EP Open Data API: document record (CC BY 4.0)}
}