Text · Opinion parliamentary committee draft
On the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Full title
On the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Document ITRE-PA-738558 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)
- Kind
- Opinion parliamentary committee draft ITRE-PA-738558
- Date
- 10 November 2022
- Committee
- Committee on Industry, Research and Energy
- Rapporteur
- Henna Virkkunen
- Dossier
- 2022-0084
More facts (2)
- Formats
- Official page PDF Word
- Reference
- COM(2022)0119 – C90121/2022 – 2022/0084(COD)
In short
A summary of the text written by AI; ¶ opens the paragraph it rests on.
AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026
The Committee on Industry, Research and Energy gives its draft opinion on the proposed regulation on information security in the Union's institutions, bodies, offices and agencies. The rapporteur welcomes the proposal and proposes amendments to streamline information security rules across all Union entities. The amendments add a need-to-know principle giving Members of Union institutions access to all necessary information for their mandate. They require vetting of contractors' personnel and evaluation of security infrastructure, including the full supply chain. They set deadlines for notifying breaches, change the Coordination Group's voting to simple majority, and adjust rules on cryptographic products and EUCI sharing.
Position. The Committee on Industry, Research and Energy calls on the Committee on Civil Liberties, Justice and Home Affairs to take into account 19 amendments to the proposed regulation, covering definitions, access to information, contractor vetting, breach notification deadlines, cryptographic products and the Coordination Group's voting.
Key points
- The rapporteur welcomes the proposal as part of the EU Security Union Strategy and supports modernising and streamlining information security rules for all Union entities.
- The amendments replace 'Union institutions and bodies' with 'Union entities' throughout the text, covering institutions, bodies, offices and agencies.
- A new recital and article state that Members of Union institutions should have access to all necessary information by virtue of their mandate, on a need-to-know principle.
- The amendments require contractors' personnel to undergo a vetting procedure as part of the tender procedure, taking into account the full supply chain and operational environment.
- A thorough evaluation of security infrastructure, including services, should be conducted, taking into account the full supply chain and operative environment.
- The Coordination Group should act by simple majority instead of consent, to streamline its work.
- Each Union entity shall be appropriately represented in the Coordination Group and in the thematic sub-groups.
- Security Authorities must inform the originator and notify competent authorities of a breach without undue delay and no later than one week after being informed.
- The Council maintains the list of approved cryptographic products for EUCI, while ENISA establishes and updates yearly a list of additional approved products for RESTREINT UE/EU RESTRICTED information.
- The Coordination Group shall inform the Council yearly of cryptographic products it recommends for evaluation by a Crypto Authority Approval of a member state or ENISA.
- The sub-group on EUCI sharing and exchange of classified information shall include the European Parliament alongside the Commission, Council and European External Action Service, working by consensus.
- A new ground for exception is added where there is a legal obligation under Union law or an interinstitutional agreement between Union institutions.
Who is affected
- Union entities: would be covered by common information security rules and represented in the Coordination Group.
- Members of Union institutions: would have access to all necessary information under a need-to-know principle.
- Contractors and third parties: their personnel would undergo vetting as part of tender procedures.
- European industry: fair processing of information, especially trade secrets, would be elevated to an adequate standard.
- ENISA: would establish and update yearly a list of additional approved cryptographic products for RESTREINT UE/EU RESTRICTED information.
Figures and deadlines
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (19)
Short justification
At present, the European Union institutions, bodies, offices and agencies (herein ‘Union entities’) have their own information security rules, that are based on their Rules of procedure or founding act, or they do not have information security rules at all. Small entities in particular might lack any formal information security policies. Simultaneously, the Union entities share increasing amounts of sensitive non-classified and European Union classified information (herein ‘EUCI’) between themselves. Given the evolving cyber and hybrid threat landscape, the European administration is increasingly exposed to attacks. The information handled by Union entities is an attractive target for threats and therefore requires appropriate protection.
The Rapporteur welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission in July 2020. Due to the variety of different information security rules across the Union entities and the constantly evolving cyber and threat landscape that they are in, modernizing and streamlining the internal legal frameworks for information security in all Union entities by means of a Regulation is justified. Cooperation on information security between Union entities is advantageous for all actors in order to create an information security culture.
The fair processing of information is crucial for the European industry, in particular regarding trade secrets. Therefore, the rules regarding the processing of information in particular must be elevated to an adequate standard.
By virtue of their mandate, the Members of Union institutions should have access to all necessary information to carry out their tasks, on the basis of a need-to-know principle, which denotes that only those for whom access to that information is necessary to carry out their task effectively have access to it. Moreover, it is crucial to ensure that the Members of the European Parliament are given access to any type of information that is necessary in order to effectively exercise their mandate.
The Committee on Industry, Research and Energy calls on the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible, to take into account the following amendments:
| Text proposed by the Commission | Amendment |
|---|---|
| (3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards. | (3) Therefore, relevant rules ensuring a common level of information security in all Union entities should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) The Treaties attribute powers to the Union institutions. For those powers to be exercised effectively, Members of Union institutions should have access by virtue of their mandate to all necessary information on the basis of a need-to-know principle. |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common structure for cooperation between Union entities in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union entities’ Security Authorities are represented. Without having decision-making powers, the Coordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body. | (12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union entity. While the common minimum requirements laid down in this Regulation must be met, each Union entity should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each entity. |
| Text proposed by the Commission | Amendment |
|---|---|
| (15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. | (15) Since Union entities frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should entail a requirement to undergo a vetting procedure as part of the tender procedure. That procedure should take into account the full supply chain and the operational environment of the third party contractors. |
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union entities where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union entities to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be conducted, which would take into account the full supply chain and the operative environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | 1. This Regulation lays down common information security rules for all Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) ‘Union institutions and bodies’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act; | (e) ‘Union entities’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act; |
| (This amendment applies throughout the text. Adopting it will necessitate corresponding changes throughout.) |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. The Members of the Union institutions shall have access to all types of information on the basis of a need-to-know principle for the effective exercise of their mandate in accordance with the Treaties. |
'Need-to-know' is a principle or policy used in the context of confidential information to denote that only those for whom access to that information is necessary to carry out their task effectively have access to it. The purpose of this principle is to strike the right balance between the protection of the confidential information and the need for this information to be known for those who have to take well-informed decisions, for which access to this information might be critical.
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Acting by consent and in the common interest of all Union institutions and bodies, the Coordination Group shall: | 2. Acting by simple majority and in the common interest of all Union entities, the Coordination Group shall: |
The requirement of simple majority would streamline the work of the Interinstitutional Information Security Coordination Group.
| Text proposed by the Commission | Amendment |
|---|---|
| 6. Each Union institution or body shall be appropriately represented in the Coordination Group and where applicable, in the thematic sub-groups. | 6. Each Union entity shall be appropriately represented in the Coordination Group and in the thematic sub-groups. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any event no later than one week after the Security Authority has been informed of the breach; |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event no later than one week after the Security Authority has been informed of the breach. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means. The list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities. | 1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1a. For all information and material classified as EUCI, a list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4a. For information and material classified as RESTREINT UE/EU RESTRICTED, a list of additional approved cryptographic products shall be established, maintained and updated on a yearly basis by ENISA. When establishing and updating the list ENISA shall take into account the latest technological and market developments as well as the particular needs of Union institutions and bodies. ENISA shall establish the first list by ... [18months after the date of entry into force of this Regulation]. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State on the basis of a survey carried out in the Union institutions and bodies. | 5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State, or ENISA, on the basis of a survey carried out in the Union entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the European Parliament, the Council and the European External Action Service and shall work by consensus. |
| Text proposed by the Commission | Amendment |
|---|---|
| (aa) there is a legal obligation pursuant to the Union law or an Interinstitutional agreement concluded between Union institutions; |
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2022). “DRAFT OPINION on the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 10 November 2022. docId ITRE-PA-738558. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PA-738558 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/ITRE-PA-738558 (CC BY 4.0).
BibTeX
@misc{epw-text-itre-pa-738558,
author = {{European Parliament}},
title = {{DRAFT OPINION on the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
year = {2022},
date = {2022-11-10},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PA-738558}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PA-738558},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId ITRE-PA-738558. Data: EP Open Data API: document record (CC BY 4.0)}
}