Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

CONT-PR-753527 → A-9-2024-0134

From
CONT-PR-753527 report parliamentary committee draft of 16 Jan 2024
To
A-9-2024-0134 Plenary report of 19 Mar 2024
Changes
26 changes to the text
Paragraphs
+5 added · −1 removed · 28 changed
More facts (2)
Title (from)
on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022
Title (to)
on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 3 of 3: 3. MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

3. MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION

6 unchanged paragraphs

with observations forming an integral part of the decision on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022

(2023/2159(DEC))

The European Parliament,

– having regard to its decision on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022,

– having regard to Rule 100 of and Annex V to its Rules of Procedure,

– having regard to the Special Report No 05/2022 of the Court of Auditors;

Changed– having regard to the report of the Committee on Budgetary Control (A90000/2024),(A9-0134/2024),

Change 3

ChangedA. whereas, according to its statement of revenue and expenditure, the final budget of the European Union Agency for Cybersecurity (ENISA)ENISA (the ‘Agency’) for the financial year 2022 was EUR 39 207 625 representing an increase of 67,03 % compared to 2021; whereas the increase in the Agency’s budget is mainly explained by additional tasks related to the pilot implementation of the Cybersecurity Support Action programme; whereas the budget of the Agency derives mainly from the Union budget;

B. whereas the Court of Auditors (the ‘Court’), in its report on the Agency’s annual accounts for the financial year 2022 (the ‘Court’s report’), states that it has obtained reasonable assurance that the Agency’s annual accounts are reliable and that the underlying transactions are legal and regular;

Budget and financial management

1. Notes with appreciation that the budget monitoring efforts during the financial year 2022 resulted in a budget implementation of current year commitment appropriations rate of 99,93 %, representing an increase of 0,42 % compared to 2021; notes furthermore that the current year payment appropriations execution rate was 52,02 % representing a decrease of 25,38 % compared to 2021;

Change 4

Changed2. Highlights that the amount of the Agency’s final budget is the result of an amendment of EUR 15 000 000 adopted by the Managementmanagement Boardboard on 5 August 2022 due to the implementation of a cybersecurity support action aiming to strengthen the Agency’s response in supporting Member States in accordance with its mandate; notes that the majority of the commitments under the cybersecurity support action were signed late in the year, which explains the relatively low payment rate (and the subsequent large carry-forward);

Performance

Change 5

Changed3. Commends that the Agency for having implemented 100 % of its work programme in 2022; welcomes that the Agency uses Keykey Performanceperformance Indicatorsindicators (KPIs) to assess its activities and the results towardsin itsrespect of the objectives of the work programme; observes that certain outputs did not achieve their objectives in full due to the reprioritisation of resources in order to provide the cybersecurity support action in response to the illegal and unprovoked invasion of Russia against Ukraine; notes that some of the outputs that are more affected due to thethat beforereprioritisation mentionedwere, reprioritisationinter werealia, outputs 4.2 “Develop and enhance standard operating policies, procedures, methodologies and tools for cyber crisis”,andcrisis”, and 5.3 “Initiate the development of a trusted network of vendors/suppliers” among others;vendors/suppliers”;

Change 6

Changed4. Is aware that the illegal and unprovoked Russian invasion of Russia against Ukraine dominated the EU’sUnion’s security agenda in 2022; notes with satisfaction that the Agency stepped up its coordination and preparedness, and contributed to the EU’sUnion’s shared situational awareness by providing regular situational reports of cyber activity; noteshighlights that there was also intensified coordination and exchange of information with cybersecurity networks, such as the European cyber crisis liaison organisation network (EU-CyCLONe) –(EU-CyCLONe), which consists of national cybersecurity crisis management authorities –authorities, and numerous sectorial communities supported by the Agency; welcomes the efforts realisedcarried out by the Agency to ensure channels of communication between political, operational and technical levels, and enhanced cooperation with the computer security incident response teams’ network;

Change 7

Changed5. Notes with satisfaction that in 2022 the agencyAgency piloted the Union heat map, which aimed to provide a quick overview of cyberincidentscyber incidents and cybereventscyber affectingevents theaffecting EU’sUnion’s critical sectors as a result of the cyberactivitycyber activity related to the Russian war of aggression against Ukraine; notes that thesethose sectors contributed to the integrated situational awareness and analysis report from the Commission, with 52 updates on the current situation and incidents in regard to the Russian war of aggression against Ukraine, contributing to the Union’s Crisiscrisis Managementmanagement Mechanism;mechanism;

Change 8

Changed6. Takes note thatof the fact that, according to the Court Special ReportCourt’s Specialspecial report 05/2022: “Cybersecurity of EU institutions, bodies and agencies”, the number of cyberattacks on EU bodies is increasing sharply and the level of cybersecurity preparedness within EUUnion bodies varies and is overall not commensurate with the growing threats; observes that since EUUnion bodies are strongly interconnected, a weakness in one can expose others to security threats; highlights that the Court recommends that the Agency together with CERT-EUComputer Emergency Response Team for the Union should increase their focus on those EUUnion bodies that have less experience in managing cybersecurity by: (a) identifying priority areas where EUUnion institutions, bodies and agencies need most support, for example through maturity assessments, and (b) implementing capacity-building actions, in line with their Memorandummemorandum of Understanding;understanding; calls on the Agency to address the issues raised by the Court and report back to the discharge authority on any measures taken on this matter;

Change 9

Changed7. Takes note of the fact that the Agency conducted various activities in 2022 to fulfil its role in supporting the European Union; notes that while the Agency was able to offer its support to several policy files, such as Networknetwork and Information Security Directives (NISD2), Cyberinformation Resiliencesecurity, Actcyber (CRA)resilience and Digital Operational Resiliencedigital Actoperational (DORA),resilience, resource constraints prevented the Agency from actively supporting policy files with cybersecurity provisions, such as the European Healthhealth Datadata Space,space, and other key policy files, such as the Digital Marketsdigital Actmarkets and the Digital Servicesdigital Act;services; notes that other activities included informing policymakers about the effectiveness of existing cybersecurity frameworks and providing support to critical sectors; notes furthermore that the adoption of newDirective Network(EU) 2022/2555 of the European Parliament and Informationof Securitythe DirectivesCouncil (NISD2)(NIS 2 Directive) stands out as a measure to address challenges and harmonizeharmonise policies across the EU;Union; understands that the lack of harmonizationharmonisation in NIS1Dthe NIS 1 Directive implementation led to a fragmented policy landscape, addressed by NISD2;the NIS 2 Directive; is aware that the latter expands its scope introducing new horizontal tasks for the Agency, such as the EUUnion register for digital entities; highlights that the Agency adjusted its services and resources with a new strategy to meet the evolving demands of the cybersecurity landscape;

Efficiency and gains

8. Notes that the Agency sought to increase its use of services shared with other agencies and/or the Commission, including, for example, through interagency and interinstitutional procurement processes, and sharing services with European Centre for the Development of Vocational Training (Cedefop) and the European Cybersecurity Competence Centre (ECCC); notes furthermore that in 2022, the Agency signed a service-level agreement with the newly established European Cybersecurity Industrial, Technology and Research Competence Centre, for the provision to the centre of data protection officer and accountant services, to be implemented in 2023;

9. Takes note of the steps taken by the Agency to move away from the traditional headcount methodology to a strategic workforce planning to anticipating and addressing staffing gaps in order to build an agile workforce and allocate resources to priority areas;

Change 10

Changed10. Welcomes the Agency’s contribution to the promotion of shared services among agencies through several networks in the areas of procurement, HR,human resources, ICT, risk management, performance management, data protection, information security and accounting; points out the horizontal benefits of working together and adapting best practices and that joint initiatives bring together diverse perspectives, reduce duplication of effort, enhance learning and strengthen relationships between the participants; encourages the Agency to find internal procedures that could be streamlined via new IT tools;

Change 11

Changed11. Notes with satisfaction the involvement of the Agency in the pilot exercise within the EU Agencies Network intended to support EUUnion agencies to increase their preparedness for the upcoming new cybersecurity regulation;

Change 12

Added12. Recalls the importance of increasing the digitalisation of the agency in terms of internal operation and management but also in order to speed up the digitalisation of procedures; stresses the need for the agency to continue to be proactive in this regard in order to avoid a digital gap between the agencies;

Staff policy

13. Notes that on 31 December 2022, the establishment plan was 89,02 % implemented, with 73 temporary agents appointed out of 82 authorised under the Union budget (compared to 76 authorised posts in 2021); notes that, in addition, 27 contract agents, 10 seconded national experts, 10 interim staff and 16 contractors worked for the Agency in 2022;

Change 13

Changed13.14. Notes with concern the lack of gender balance within the Agency’s senior and middle management with 12 out of 17 being men (71 %)%); considers that the gender balance within the Agency’s senior and middle management needs to be improved; recalls the importance of ensuring gender balance and calls on the Agency to take this aspect into consideration with regard to future appointments within its senior and middle management; takes note of the gender distribution within the Agency’s management board, with 41 out of 55 (75 %) being men; however, understandsacknowledges that the gender balancecomposition of the management board depends to a large extent on theMember factState thatnominations; itsinsists membersthat arethe secondedCommission byand the Member States;furtherStates take into account the importance of ensuring gender balance when nominating their members to the Agency’s management board; notes the balanced gender distribution within the Agency’s staff overall, with 57 men (52%)(52 %) and 4853 women (53%); takes(48 note%); ofnotes the steps taken by the Agency with the aim to tackle issues within relation to gender balance which includes the revision of its recruitment policy with a view to encourageencouraging applications from women; notes furthermore that the Agency has planned in its Corporatecorporate Strategystrategy to obtain EU Agency’s Network Certificate of Excellence in Diversity and Inclusion by the end of 2025;

Change 14

Removed14. Notes with concern that during the development of the 2023 work program, the Agency identified a resource shortfall of EUR 734 000 and two FTEs in operations, and EUR 2,5 million in corporate services; notes furthermore that a thorough evaluation of human resource needs for 2023-2025 revealed a significant gap, particularly in critical activities and without additional posts, the Agency may need to prioritize and adjust future work programs to offset the resource shortfall; takes note that the Management Board has also expressed the need to increase staffing posts for the Agency to be able to fully deliver its mandate in a sustainable manner;

Added15. Notes that the Agency has a policy on protecting the dignity of the person and preventing psychological and sexual harassment, and that the Agency is part of the interagency task force of confidential counsellors; looks forward to receiving their report and recommendations; notes that there were no reported cases of harassment in 2022 and encourages the Agency to continue and develop the work to prevent cases in the future as well;

Added16. Raises concerns about the geographical imbalance within the Agency’s senior and middle management and other staff, with a 40,9 % representation of Greek nationals; insists that improvements have to be made; asks the Agency to report back on this to the discharge authority;

Added17. Notes with concern that during the development of the 2023 work programme, the Agency identified a resource shortfall of EUR 734 000 and two FTEs in operations, and EUR 2,5 million in corporate services; notes furthermore that a thorough evaluation of human resource needs for 2023-2025 revealed a significant gap, particularly in critical areas of activity and without additional posts, the Agency may need to prioritise and adjust future work programs to offset the resource shortfall; takes note of the fact that the Agency’s management board has also expressed the need to increase staffing posts for the Agency to be able to fully deliver its mandate in a sustainable manner;

18. Welcomes the Agency’s efforts to integrate persons with disabilities setting accessible infrastructure and support services;

Change 15

Changed16.19. Notes that the Agency in 2022 the Agency continued with its complementary support to staff in vouchers, internet reimbursement and fit@work programme and developed its code of conduct, outlining Agency’s expectation regarding staffmembers members’of staff behaviour and conduct;

Procurement

Change 16

Changed17.20. NotesNotes, with concern, that the Court found two cases where the Agency had awarded low-value contracts (below EUR 15 000) without issuing an evaluation report and an award decision duly approved and signed by the authorising officer which contravenes points 30.3 and 30.4 of Annex I to the Financial Regulation; recalls in this regard that the Court made a similar observation in their 2021 report and the Agency’s reply stating that it had already taken the necessary steps to address this concern; insists on the importance to implementing procedures to ensure full compliance with the Financial Regulation; calls on the Agency to address the issues raised by the Court and report backany developments in that regard to the discharge authority;

Change 17

Changed18.21. Takes note that according to the Court, during 2022 ,2022, the Agency offered its managers a professional appraisal performed by an external provider, designated by the Agency; notes that in three cases, the Agency paid the provider directly for these services, while in the remaining 23 cases, it reimbursed its managers, who had paid the provider themselves; observes that the total amount paid by the Agency for the 26 appraisals was EUR 120 276; regrets that the Agency selected the provider without launching an open procurement procedure, and for this reason the Court concluded that thesethose payments were irregular; calls on the Agency to address the issues raised by the Court and report back to the discharge authority on any measures taken on this matter;

22. Insists that the objective of public procurement rules is to enable procuring entities to obtain the goods and services they need at best price, while ensuring fair competition between tenderers and compliance with the principles of transparency, proportionality, equal treatment and non-discrimination; calls on the Agency to further improve its public procurement procedures, ensuring full compliance with the applicable rules, so that they achieve the best possible value for money;

Prevention and management of conflicts of interest and transparency

23. Notes the Agency’s existing measures and ongoing efforts to secure transparency, prevention and management of conflicts of interest, and notes that the CVs of the members of the management board, and their declaration of commitment and declarations of interests are being published on its website, although some of the CVs are missing;

Change 18

Changed21.24. Notes that the Agency has not reported any cases of conflict of interest in 2022; further notes the Agency’s adoption of theits Managementmanagement Boardboard Decision 15/2021 on the prevention of conflictconflicts of interest and the update of the templates for the declarations; insists on the importance of having procedures in place for monitoring compliance with the rules related to ‘revolving door’doors’ and actively monitoring the professional activity of their senior staff members (includingof the staff, including those thatwho have left the agency within the last two years)years, in order to be able to detect undeclared ‘revolving door’doors’ situations;

Change 19

Changed22.25. Takes note that the calendar of the meetings between the Agency's Managementmanagement and external stakeholders is publicly available on its website;

Change 20

Added26. Recalls the importance for the Agency to develop greater visibility in the media, internet, and social media in order to make its work known to the citizens;

Internal control

Change 21

Changed23.27. Notes that the IASinternal audit service conducted in 2021 an audit on strategic planning programming and performance management and issued its final audit report in April 2022, with three important recommendations notes further the Agency’s agreement with the audit observations and having taken the necessary steps to address thesethose concerns;

Change 22

Changed24.28. Observes that according to the Court the Agency has no pre-determined model assessmentassessment, (i.e.namely guidelines)guidelines, to help the evaluation committee to assess the tenders; notes that this entails the risk that the tenders may not be evaluated consistently by each member of the evaluation committee; calls on the Agency to address this issue raised by the Court and report back to the discharge authority;

Change 23

Changed25.29. Takes note that in 2022, the Agency performed ex post controls of financial transactions made during 2021 financial year as per Article 45(8) and (9) of theCommission ENISADelegated financialRegulation regulation;(EU) 2019/715; draws attention to the fact that three weaknesses were identified, leading to three recommendations on financial transactions, none of which was deemed critical; observes that to address the main weakness, weekly monitoring of time to payment was introduced in 2022 to alert the relevant financial staff to urgent transactions remaining to be processed, to comply with the legal framework on payment time limits;

Change 24

Changed26.30. Notes that in 2022, the assessment of the effectiveness of the internal control systems of the Agency was based on the indicators of the framework, and also additional information from specific (risk) assessment reports, audit findings and other relevant sources; observes that the assessment of the Agency's internal controls indicates reasonable assurance in facilitating effective and efficient operations, ensuring quality reporting, and compliance with regulations but some improvements are needed in relation to certain principles to increase effectiveness and ensure proper implementation of the internal controls; calls on the Agency to report back to the discharge Authorityauthority on theits followfollow-up upaction on the improvements assessment;

Other comments

Change 25

Changed27.31. Notes that the Agency has implemented important measures in order to increase cyber security protection, such as secure email solution (SECEM2), red team exercise and follow-up fixes &and hardening, decommissioning of legacy systems, update of internal cybersecurity policy framework, among others;framework;

Change 26

Changed28.32. Welcomes that the Management Boardfact ofthat the AgencyAgency’s management board added to the Agency's Single Programming Document 2022-2024 the goal for the Agency to achieve climate neutrality across all its operations by 2030; notes that with the adoption of ENISA’sthe Agency’s corporate strategy, the EMAS certification and green public procurement are key objectives of the Agency; takes note of the fact that the certification process is expected to be completed in the course of 2024;

°

° °

33. Refers, for other observations of a cross-cutting nature accompanying its decision on discharge, to its resolution of ... on the performance, financial management and control of the agencies.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
26 September 2026

Cite as

European Parliament (2024). “Changes between CONT-PR-753527 and A-9-2024-0134”. Text, 19 March 2024. from CONT-PR-753527, to A-9-2024-0134. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/CONT-PR-753527/compare/A-9-2024-0134?all=1&part=3 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-03-19,
  author = {{European Parliament}},
  title = {{Changes between CONT-PR-753527 and A-9-2024-0134}},
  year = {2024},
  date = {2024-03-19},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/CONT-PR-753527/compare/A-9-2024-0134?all=1&part=3}},
  url = {https://news.eu-parl.st-solutions.dev/texts/CONT-PR-753527/compare/A-9-2024-0134?all=1&part=3},
  urldate = {2026-09-26},
  publisher = {EU Parl Watch Research},
  note = {Text. from CONT-PR-753527, to A-9-2024-0134. Data: European Parliament Open Data (CC BY 4.0)}
}