Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-745538 → A-9-2023-0253

From
ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
To
A-9-2023-0253 Plenary report of 27 Jul 2023
Changes
Not comparable
Paragraphs
+850 added · −171 removed · 3 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 11 of 20: Paragraphs 542–601

AddedThat person shall be subject to the obligations of the manufacturer set out in Articles 10 and 11(1), (2), (4) and (7), for the part of the product that is affected by the substantial modification or, if the substantial modification has an impact on the cybersecurity of the product with digital elements as a whole, for the entire product.

Added1. Economic operators shall, on request▌, provide to the market surveillance authorities the following information:

Added(a) name and address of any economic operator who has supplied them with a product with digital elements;

Added(b) name and address of any economic operator to whom they have supplied a product with digital elements;

Added2. Economic operators shall be able to present the information referred to in paragraph 1 for ten years after they have been supplied with the product with digital elements and for ten years after they have supplied the product with digital elements.

Added1. In order to create clarity, certainty for, and consistency among the practices of economic operators, the Commission shall prepare and issue guidelines for economic operators, explaining how to apply this Regulation, with a particular focus on how to facilitate compliance by microenterprises, small enterprises and medium-sized enterprises.

Added2. The guidelines shall be published by ... [12 months after the date of entry into force of this Regulation] and shall be updated as necessary, in particular in light of potential amendments to the list of critical products set out in Annex III. They shall contain at least the following elements:

Added(a) a detailed explanation of the scope of this Regulation, with a particular focus on remote data processing solutions and free and open-source software;

Added(b) detailed criteria used to determine how critical products with digital elements are placed in classes I or II as set out in Annex III;

Added(c) the interplay between this Regulation and other Union law, particularly concerning presumptions of conformity and conformity assessments;

Added(d) guidance for manufacturers on how to perform the cybersecurity risk assessment referred to in Article 10(2) and on the applicability of the essential requirements including where available best practices ;

Added(e) guidance for manufacturers on how to determine appropriately the support period for different product categories in accordance with Article 10(6);

Added(f) an explanation of how to handle reporting requirements pursuant to this Regulation or other Union law;

Added(g) a list of the delegated and implementing acts published by the Commission pursuant to this Regulation;

Added(h) guidance for Member States on the non-prosecution of information security researchers;

Added(i) guidance on what constitutes substantial modifications.

Added3. When preparing the guidelines pursuant to this Article, the Commission shall consult the Expert Group.

AddedConformity of the product with digital elements

Added1. Products with digital elements and processes put in place by the manufacturer which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union shall be presumed to be in conformity with the essential requirements covered by those standards or parts thereof, set out in Annex I.

AddedThe Commission shall in accordance with Article 10(1) of Regulation (EU) 1025/2012 request one or more European standardisation organisations to draft harmonised standards for the essential requirements set out in Annex I to this Regulation. When preparing the standardisation request for this Regulation, the Commission shall strive to take into account existing or imminent international standards for cybersecurity in order to simplify the development of harmonised standards.

Added2. Products with digital elements and processes put in place by the manufacturer, which are in conformity with the common specifications referred to in Article 19 shall be presumed to be in conformity with the essential requirements set out in Annex I, to the extent those common specifications cover those requirements.

Added3. Products with digital elements and processes put in place by the manufacturer for which an EU statement of conformity or certificate has been issued under a European cybersecurity certification scheme adopted as per Regulation (EU) 2019/881 and specified as per paragraph 4, shall be presumed to be in conformity with the essential requirements set out in Annex I in so far as the EU statement of conformity or cybersecurity certificate, or parts thereof, cover those requirements.

Added4. The Commission is empowered to adopt, by means of delegated acts in accordance with Article 50, to supplement this Regulation by specifying the European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 that can be used to demonstrate conformity of products with digital elements with the essential requirements or parts thereof as set out in Annex I. Furthermore, the issuance of a cybersecurity certificate issued under such schemes, at assurance level ‘substantial’ or ‘high’ , eliminates the obligation of a manufacturer to carry out a third-party conformity assessment for the corresponding requirements, as set out in Article 24(2)(a), (b), (3)(a) and (b). ▌

Added1. ▌The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by establishing common specifications that cover technical requirements providing a means to comply with the requirements set out in Annex I for products that fall within the scope of this Regulation where the following conditions have been fulfilled:

Added(a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the essential requirements set out in Annex I and the request has not been accepted or the European standardisation deliverables addressing that request is not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012 or European standardisation deliverables do not comply with the request; and

Added(b) no reference to harmonised standards covering the relevant essential requirements set out in Annex I to this Regulation is published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 and no such reference is expected to be published within a reasonable period.

Added2. Before preparing the delegated act, the Commission shall inform the Expert Group that it considers that the conditions in paragraph 1 are fulfilled. In preparing the delegated acts, the Commission shall take into account the opinions of the Expert Group.

Added3. Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the relevant delegated acts referred to in paragraph 1, or the parts thereof which cover the same essential requirements set out in Annex I to this Regulation.

Added1. The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 10(7) and state that the fulfilment of the applicable essential requirements set out in Annex I has been demonstrated.

Added2. The EU declaration of conformity shall have the model structure set out in Annex IV and shall contain the elements specified in the relevant conformity assessment procedures set out in Annex VI. Such a declaration shall be ▌updated as appropriate. It shall be made available in the language or languages required by the Member State in which the product with digital elements is placed on the market or made available.

Added3. Where a product with digital elements is subject to more than one Union act requiring an EU declaration of conformity, a single EU declaration of conformity shall be drawn up in respect of all such Union acts. That declaration shall contain the identification of the Union acts concerned, including their publication references.

Added4. By drawing up the EU declaration of conformity, the manufacturer shall assume responsibility for the compliance of the product.

Added5. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by adding elements to the minimum content of the EU declaration of conformity set out in Annex IV to take account of technological developments.

AddedThe CE marking as defined in Article 3(32) shall be subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008.

Added1. The CE marking shall be affixed visibly, legibly and indelibly to the product with digital elements. Where that is not possible or not warranted on account of the nature of the product with digital elements, it shall be affixed to the packaging and to the EU declaration of conformity referred to in Article 20 accompanying the product with digital elements. For products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 20 or on the website accompanying the software product. In the latter case, the relevant section of the website shall be easily and directly accessible to consumers.

Added2. On account of the nature of the product with digital elements, the height of the CE marking affixed to the product with digital elements may be lower than 5 mm, provided that it remains visible and legible.

Added3. The CE marking shall be affixed before the product with digital elements is placed on the market. It may be followed by a pictogram or any other mark indicating a special risk or use set out in implementing acts referred to in paragraph 6.

Added4. The CE marking shall be followed by the identification number of the notified body, where that body is involved in the conformity assessment procedure based on full quality assurance (based on module H) referred to in Article 24.

AddedThe identification number of the notified body shall be affixed by the body itself or, under its instructions, by the manufacturer or the manufacturer’s authorised representative.

Added5. Member States shall build upon existing mechanisms to ensure correct application of the regime governing the CE marking and shall take appropriate action in the event of improper use of that marking. Where the product with digital elements is subject to other Union legislation which also provides for the affixing of the CE marking, the CE marking shall indicate that the product also fulfils the requirements of that other legislation.

Added6. After consulting the Expert Group, the dedicated administrative cooperation group (ADCO) and, where necessary, other relevant stakeholders, the Commission may, by means of implementing acts, lay down technical specifications for labelling schemes, including harmonised labels, pictograms or any other marks related to the security of the products with digital elements, their support period and mechanisms to promote their use among businesses and consumers and to increase public awareness about the security of products with digital elements. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 51(2).

Added1. The technical documentation shall contain all relevant data or details of the means used by the manufacturer to ensure that the product with digital elements and the processes put in place by the manufacturer comply with the essential requirements set out in Annex I. It shall at least contain the elements set out in Annex V.

Added2. The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, during at least the support period▌.

Added3. For products with digital elements referred to in Articles 8 and 24(4) that are also subject to other Union acts, one single technical documentation shall be drawn up containing the information referred to in Annex V of this Regulation and the information required by those respective Union acts.

Added4. The technical documentation and correspondence relating to any conformity assessment procedure shall be drawn up in an official language of the Member State in which the notified body is established or in a language acceptable to that body.

Added5. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by the elements to be included in the technical documentation set out in Annex V to take account of technological developments, as well as developments encountered in the implementation process of this Regulation. The Commission shall ensure that the administrative burden on microenterprises and small and medium-sized enterprises is proportionate.

Added1. The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential requirements set out in Annex I are met. The manufacturer or the manufacturer’s authorised representative shall demonstrate conformity with the essential requirements by using one of the following procedures:

Added(a) the internal control procedure (based on module A) set out in Annex VI; or

Added(b) the EU-type examination procedure (based on module B) set out in Annex VI followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VI; or

Added(c) conformity assessment based on full quality assurance (based on module H) set out in Annex VI;

Added(ca) a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881 in accordance with Article 18(4).

Added2. Where, in assessing the compliance of the critical product with digital elements of class I as set out in Annex III and the processes put in place by its manufacturer with the essential requirements set out in Annex I, the manufacturer or the manufacturer’s authorised representative has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level ‘substantial’ or “high’ as referred to in Article 18, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential requirements to either of the following procedures:

Added(a) EU-type examination procedure (based on module B) provided for in Annex VI followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VI; or

Added(b) conformity assessment based on full quality assurance (based on module H) set out in Annex VI.

Added2a. Harmonised standards, common specifications or European cybersecurity certification schemes shall be in place for six months before the conformity assessment procedure referred to in paragraph 2 of this Article applies. In the six months prior to the application of paragraph 2 of this Article, or where, harmonised standards, common specifications or European cybersecurity certification schemes do not exist, manufacturers shall demonstrate the conformity of the critical product with digital elements of class I as set out in Annex III by means of the procedure referred to in paragraph 1 of this Article.

Added3. Where the product is a critical product with digital elements of class II as set out in Annex III, the manufacturer or the manufacturer’s authorised representative shall demonstrate conformity with the essential requirements set out in Annex I by using one of the following procedures:

Added(-a) a European cybersecurity certificate, under a European cybersecurity certification scheme at assurance level ‘substantial’ or ‘high’ pursuant to Regulation (EU) 2019/881;

Added(a) EU-type examination procedure (based on module B) set out in Annex VI followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VI; or

Added(b) conformity assessment based on full quality assurance (based on module H) set out in Annex VI.

Added3a. The Commission shall request ENISA to prepare the missing candidate schemes in accordance with Article 48 of Regulation (EU) 2019/881.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
30 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=11 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
  year = {2023},
  date = {2023-07-27},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=11}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=11},
  urldate = {2026-09-30},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}