Text · Opinion parliamentary committee
On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Document ITRE-AD-768157 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)
- Kind
- Opinion parliamentary committee ITRE-AD-768157
- Date
- 19 February 2025
- Committee
- Committee on Industry, Research and Energy
- Rapporteur
- Borys Budka
- Dossier
- 2022-0084
More facts (3)
- Formats
- Official page PDF Word
- Subject matter
- PDON, INST, INFO
- Reference
- COM(2022)0119 – C90121/2022 – 2022/0084(COD)
In short
A summary of the text written by AI; ¶ opens the paragraph it rests on.
AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026
The Committee on Industry, Research and Energy proposes amendments to the proposed regulation on information security in the Union's institutions, bodies, offices and agencies. It replaces 'institutions and bodies' with 'Union entities' throughout, adds common minimum standards and interoperability, and strengthens access to information for Members of the Union institutions. The amendments add rules on personal data protection, transparency, whistle-blower protection, vetting of contractors, and a personal data breach procedure. They also set deadlines for training and for ENISA to establish a list of approved cryptographic products for RESTREINT UE/EU RESTRICTED information.
Position. The Committee on Industry, Research and Energy proposes amendments to the proposed regulation, including replacing 'institutions and bodies' with 'Union entities', adding common minimum standards, strengthening access to information for Members, and introducing rules on personal data protection, transparency, contractor vetting, training deadlines, and cryptographic product lists.
Key points
- Replaces 'institutions and bodies' with 'Union entities' throughout the text, except in Article 3(e) and Articles 42 and 4(a).
- Adds that Members of the Union institutions should have access to all necessary information on the basis of the need-to-know principle to exercise their mandate.
- Requires that any limitation of the right to personal data protection and privacy be necessary and proportionate under Article 52(1) of the Charter, and that information security measures comply with Union data protection law.
- Calls for enhanced transparency, minimisation and time-limiting of confidential documents, safeguards against misuse of classification, and adequate protection of whistle-blowers.
- Requires contractors' personnel to undergo a vetting procedure as part of the tender procedure, taking into account the full supply chain and operational environment.
- Requires Union entities to apply Regulation (EU) 2018/1725 when handling personal data breaches and to adopt a personal data breach handling procedure.
- Requires mandatory training at least once every 5 years for all individuals authorised to access EUCI, with specific training for information security functions, and effective training not later than six months after entry into force.
- Adds end-to-end encryption, in particular when exchanging sensitive non-classified information, and requires information security incidents to be formally recorded and handled under the cybersecurity regulation.
- Requires the Coordination Group to adopt guidance documents on EUCI creation and classification, implementing minimisation and time-limiting, with rules on assessment and justification to increase transparency.
- Requires notification of the originator and competent authorities without undue delay and not later than one week after the Security Authority is informed of a breach.
- Requires a process for identifying and reporting vulnerabilities, including internal and external rewards, complemented by regular audits and penetration tests where appropriate.
- Requires the Council to maintain a list of approved cryptographic products for EUCI, and ENISA to establish and update yearly a list of additional approved products for RESTREINT UE/EU RESTRICTED by 18 months after entry into force.
Who is affected
- Union institutions, bodies, offices and agencies, which would have to apply common information security rules and minimum standards.
- Members of the Union institutions, who would have access to all necessary information under the need-to-know principle.
- Contractors and outsourcing personnel, who would undergo vetting as part of tender procedures.
- The European Union Agency for Cybersecurity (ENISA), which would establish and update a list of approved cryptographic products for RESTREINT UE/EU RESTRICTED.
- The Council, which would maintain a list of approved cryptographic products for EUCI.
Figures and deadlines
- at least once every 5 years for mandatory training for all individuals authorised to access EUCI
- not later than six months after the date of entry into force of this Regulation for effective and appropriate trainings
- not later than one week after the Security Authority has been informed of the breach for informing the originator
- not later than one week after the Security Authority has been informed of the breach for notifying competent authorities
- 18 months after the date of entry into force of this Regulation for ENISA to establish the list of approved cryptographic products
- on a yearly basis for ENISA to update the list of additional approved cryptographic products
- on a yearly basis for the Coordination Group to inform the Council of recommended cryptographic products
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (46)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
- Amendment 34
- Amendment 35
- Amendment 36
- Amendment 37
- Amendment 38
- Amendment 39
- Amendment 40
- Amendment 41
- Amendment 42
- Amendment 43
- Amendment 44
- Amendment 45
- Amendment 46
Short justification
At present, the European Union institutions, bodies, offices and agencies (herein ‘Union entities’) have their own information security rules, that are based on their Rules of procedure or founding act, or they do not have information security rules at all. Small entities in particular might lack any formal information security policies. Simultaneously, the Union entities share increasing amounts of sensitive non-classified and European Union classified information (herein ‘EUCI’) between themselves. Given the evolving cyber and hybrid threat landscape, the European administration is increasingly exposed to attacks. The information handled by Union entities is an attractive target for threats and therefore requires appropriate protection.
The Rapporteur welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission in July 2020. Due to the variety of different information security rules across the Union entities and the constantly evolving cyber and threat landscape that they are in, modernizing and streamlining the internal legal frameworks for information security in all Union entities by means of a Regulation is justified. Cooperation on information security between Union entities is advantageous for all actors in order to create an information security culture.
The fair processing of information is crucial for the European industry, in particular regarding trade secrets. Therefore, the rules regarding the processing of information in particular must be elevated to an adequate standard.
By virtue of their mandate, the Members of Union institutions should have access to all necessary information to carry out their tasks, on the basis of a need-to-know principle, which denotes that only those for whom access to that information is necessary to carry out their task effectively have access to it. Moreover, it is crucial to ensure that the Members of the European Parliament are given access to any type of information that is necessary in order to effectively exercise their mandate.
The Committee on Industry, Research and Energy submits the following to the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible:
| Text proposed by the Commission | Amendment |
|---|---|
| (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. | (1) Union entities currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union entity invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. |
| (This amendment applies throughout the text except for article 3 (e) and art 42, 4(a). Adopting it will necessitate corresponding changes throughout.) |
| Text proposed by the Commission | Amendment |
|---|---|
| (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States. | (2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union entities. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information, common key handling principles and where appropriate, common information system infrastructure on which information is handled, stored and transmitted by Union entities. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union entities and with Member States. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, relevant rules ensuring a common level of information security in all Union entities should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) Members of the Union institutions should have access by virtue of their mandate to all necessary information on the basis of the ‘need-to-know principle’ in order to exercise the powers vested to them by the Treaties. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3b) When developing information security rules, Union entities should ensure efficiency and choose the best solutions, in particular as regards return on investments, appropriate levels of flexibility, decrease of administrative burden, minimisation of risks, higher levels of transparency and improvement of the work environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3c) In the context of information security, Union entities should increase organisational interoperability and act together to ensure the protection of networks and information systems, data and the assets employed to capture, store, process and transmit the information. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) This Regulation should ensure that any limitation of the right to the protection of personal data and privacy is necessary and proportionate, in accordance with Article 52(1) of the Charter of Fundamental Rights of the European Union. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5b) All information security measures involving processing of personal data should be compliant with the relevant Union data protection and privacy law. Union entities should provide relevant technical and organisational safeguards to ensure compliance in an accountable and transparent manner. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5c) When implementing this Regulation, Union entities should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against use of classification that would prevent Union entities to fulfil their mission and ensure that whistle-blowers are adequately protected, while ensuring a high level of protection of information in line with Union law and best practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. | (6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817, Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18, Regulation (EC) No 1049/2001 of the European Parliament and of the Council19, Regulation (EU) 2018/1725 of the European Parliament and of the Council20, including the rules on international transfers of personal data, Council Regulation (EEC, EURATOM) No 354/8321, Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. |
| 17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). | 17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). |
| 18 OJ 45, 14.6.1962, p. 1385. | 18 OJ 45, 14.6.1962, p. 1385. |
| 19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43). | 19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43). |
| 20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). | 20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). |
| 21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1). | 21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1). |
| 22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1). | 22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1). |
| 23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149). | 23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149). |
| 24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted | 24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common structure for cooperation between Union entities in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body. | (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union entity. While the common minimum requirements laid down in this Regulation must be met, each Union entity should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each Union entity. However, the specific security measures should not constitute an impediment for the activity of other institutions and legal access to information, such as for example unduly limiting the access of the Members of the European Parliament to the information produced or held by the Commission. |
| Text proposed by the Commission | Amendment |
|---|---|
| (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | (14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure and terminal devices used for connecting to the Union entity’s remote access services should be protected by adequate security measures. |
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union entities frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include a requirement to undergo a vetting procedure as part of the tender procedure. That procedure should take into account the full supply chain and the operational environment of the third party contractors. |
| Text proposed by the Commission | Amendment |
|---|---|
| (17a) The Union entities should apply Regulation (EU) 2018/1725 of the European Parliament and of the Council1a (EUDPR) when dealing with personal data breaches in their procedures for information security incident management. Therefore, the Union entities should adopt a personal data breach handling procedure. | |
| 1a Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018). |
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union entities where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union entities to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out. That evaluation should take into account the full supply chain and the operative environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. | (21) Union entities have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union entities. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21a) The information held by the Union entities is also exchanged through the ICT environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes as well as any network and information system whether owned and operated by a Union entity, or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness of a Union institution or body should be assessed before they handle and store a specified level of EUCI. | (24) The close cooperation between Union entities as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the capabilities of the Union entities to handle, store and transmit EUCI should be assessed before they handle and store a specified level of EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| (29) The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 of the European Parliament and of the Council27 and delivered an opinion on ... | (29) The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 and delivered an opinion on ... |
| 27 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018). |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | 1. This Regulation lays down common information security rules for all Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) ‘Union institutions and bodies’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act; | (e) ‘Union entities’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act; |
| Text proposed by the Commission | Amendment |
|---|---|
| (s) ‘zero trust’ means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy based on an acknowledgement of the existence of threats inside and outside traditional network boundaries; | (s) ‘zero trust’ means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy based on an acknowledgement of the existence of threats inside and outside traditional network boundaries and 'never trust, always verify' concept; |
| Text proposed by the Commission | Amendment |
|---|---|
| (aea) ‘standard’ means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012; |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. The Members of the Union institutions shall have access to all necessary information on the basis of the need-to- know principle for the effective exercise of their mandate in accordance with the Treaties. |
| Text proposed by the Commission | Amendment |
|---|---|
| Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | Union entities handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union entities concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entities shall design and implement effective and appropriate trainings commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI not later than ...[six months after the date of entry into force of this Regulation]. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) integrity, availability and resilience of processing systems and services. |
| Text proposed by the Commission | Amendment |
|---|---|
| (-a) the risks for the rights and freedoms of natural persons; |
| Text proposed by the Commission | Amendment |
|---|---|
| (f) business continuity and disaster recovery; | (f) business continuity, such as back up management, disaster recovery and crisis management; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Acting by consent and in the common interest of all Union institutions and bodies, the Coordination Group shall: | 2. Acting by simple majority and in the common interest of all Union entities, the Coordination Group shall: |
| Text proposed by the Commission | Amendment |
|---|---|
| (c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate; | (c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the Union entities, where appropriate; |
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) strengthening cooperation and coordination with CERT-EU. |
| Text proposed by the Commission | Amendment |
|---|---|
| (da) end-to-end encryption, in particular when exchanging sensitive non-classified information; |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) information security incidents shall be formally recorded and followed up, in accordance with Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. | (d) information security incidents shall be formally recorded and handled, in accordance with Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. | 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification, implementing the principle of minimisation of the use of classification and limiting in time the duration of such a classification. |
| Those guidance documents shall include rules on assessment of and justification for information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3a. This Article is without prejudice to Regulation (EC) No 1049/2001. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach; |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach. |
| Text proposed by the Commission | Amendment |
|---|---|
| (fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards, as appropriate; that process shall be complemented by regular audits and penetration tests where appropriate. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means. The list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities. | 1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. For all information and material classified as EUCI, a list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. For information and material classified as RESTREINT UE/EU RESTRICTED, a list of additional approved cryptographic products shall be established, maintained and updated on a yearly basis by the European Union Agency for Cybersecurity (‘ENISA’). When establishing and updating that list ENISA shall take into account the latest technological and market developments as well as the specific needs of Union entities. By ... [18 months after the date of entry into force of this Regulation] ENISA shall establish the list. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State on the basis of a survey carried out in the Union institutions and bodies. | 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State, or by ENISA, on the basis of a survey carried out in the Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That sub-group shall ensure synergy with Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure. |
| Text proposed by the Commission | Amendment |
|---|---|
| (-a) there is a legal obligation under Union law or an Interinstitutional agreement concluded between Union institutions; or |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. The conditions referred to in paragraph 1, point (a) are considered to be fulfilled when access to EUCI is required to fulfil the Union entity mandate or mission, as entrusted by the Union law, otherwise they could encroach on their institutional autonomy. |
Back matter, 1
Parts that accompany the text rather than belong to it: explanatory statement, annexes, opinions appended by other committees. Collapsed.
Annex: entities or persons from whom the rapporteur has received input 1 block
Procedure pages and committee votes
How the committees handled the text and how their members voted on it. Collapsed.
Procedure – committee asked for opinion 1 block
| Title | Information security in the institutions, bodies, offices and agencies of the Union | |
| References | COM(2022)0119 – C9-0121/2022 – 2022/0084(COD) | |
| Committee(s) responsible | LIBE | |
| Opinion by Date announced in plenary | ITRE 4.4.2022 | |
| Rapporteur for the opinion Date appointed | Borys Budka 29.1.2025 | |
| Simplified procedure - date of decision | 29.1.2025 | |
| Date adopted | 19.2.2025 | |
| Result of final vote | +: –: 0: | 72 0 10 |
| Members present for the final vote | Oihane Agirregoitia Martínez, Wouter Beke, Hildegard Bentele, Tom Berendsen, Paolo Borchia, Markus Buchheit, João Cotrim De Figueiredo, Giovanni Crosetto, Raúl de la Hoz Quintano, Pilar del Castillo Vera, Elena Donazzan, Sofie Eriksson, Jan Farský, Sigrid Friis, Lina Gálvez, Alexandra Geese, Jens Geier, Nicolás González Casares, Giorgio Gori, Bart Groothuis, Christophe Grudler, Elisabetta Gualmini, Niels Flemming Hansen, Eero Heinäluoma, Ivars Ijabs, Fernand Kartheiser, Seán Kelly, Rudi Kennes, Michał Kobosko, Ondřej Krutílek, Eszter Lakos, Morten Løkkegaard, Sara Matthieu, Eva Maydell, Marina Mesure, Jana Nagyová, Dan Nica, Angelika Niebler, Ville Niinistö, Mirosława Nykiel, Daniel Obajtek, Thomas Pellerin-Carlin, Tsvetelina Penkova, Pascale Piera, Virgil-Daniel Popescu, Jüri Ratas, Aura Salla, Elena Sancho Murillo, Paulius Saudargas, Benedetta Scuderi, Anthony Smith, Nicolae Ştefănuță, Anna Stürgkh, Beata Szydło, Dario Tamburrano, Bruno Tobback, Matej Tonin, Yvan Verougstraete, Mariateresa Vivaldini, Andrea Wechsler, Angelika Winzig, Nicola Zingaretti | |
| Substitutes present for the final vote | Christophe Bay, Carlo Ciccioli, Kamila Gasiuk-Pihowicz, Krzysztof Hetman, Radan Kanev, Marion Maréchal, Dario Nardella, João Oliveira, René Repasi, Virginijus Sinkevičius, Zala Tomašič, Francesco Torselli | |
| Members under Rule 216(7) present for the final vote | Arno Bausemer, Marie-Luce Brasier-Clain, Valérie Deloge, Angéline Furet, Catherine Griset, Pär Holmgren, Milan Mazurek, Malika Sorel |
Final vote by roll call by the committee asked for opinion 3 blocks
72 · For
- ESN
- Arno Bausemer, Markus Buchheit, Milan Mazurek
- EPP
- Wouter Beke, Hildegard Bentele, Tom Berendsen, Pilar del Castillo Vera, Raúl de la Hoz Quintano, Jan Farský, Kamila Gasiuk-Pihowicz, Niels Flemming Hansen, Krzysztof Hetman, Radan Kanev, Seán Kelly, Eszter Lakos, Eva Maydell, Angelika Niebler, Mirosława Nykiel, Virgil-Daniel Popescu, Jüri Ratas, Aura Salla, Paulius Saudargas, Zala Tomašič, Matej Tonin, Andrea Wechsler, Angelika Winzig
- Patriots
- Christophe Bay, Paolo Borchia, Marie-Luce Brasier-Clain, Valérie Deloge, Angéline Furet, Catherine Griset, Jana Nagyová, Pascale Piera, Malika Sorel
- Renew
- Oihane Agirregoitia Martínez, João Cotrim De Figueiredo, Sigrid Friis, Bart Groothuis, Christophe Grudler, Ivars Ijabs, Michał Kobosko, Morten Løkkegaard, Anna Stürgkh, Yvan Verougstraete
- S&D
- Sofie Eriksson, Lina Gálvez, Jens Geier, Nicolás González Casares, Giorgio Gori, Elisabetta Gualmini, Eero Heinäluoma, Dario Nardella, Dan Nica, Thomas Pellerin-Carlin, Tsvetelina Penkova, René Repasi, Elena Sancho Murillo, Bruno Tobback, Nicola Zingaretti
- The Left
- Rudi Kennes, Marina Mesure, João Oliveira, Anthony Smith, Dario Tamburrano
- Greens
- Alexandra Geese, Pär Holmgren, Sara Matthieu, Ville Niinistö, Benedetta Scuderi, Virginijus Sinkevičius, Nicolae Ştefănuță
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2025). “OPINION on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 19 February 2025. docId ITRE-AD-768157. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-768157 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/ITRE-AD-768157 (CC BY 4.0).
BibTeX
@misc{epw-text-itre-ad-768157,
author = {{European Parliament}},
title = {{OPINION on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
year = {2025},
date = {2025-02-19},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-768157}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-768157},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId ITRE-AD-768157. Data: EP Open Data API: document record (CC BY 4.0)}
}