Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-745538 → A-9-2023-0253
- From
- ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
- To
- A-9-2023-0253 Plenary report of 27 Jul 2023
- Changes
- Not comparable
- Paragraphs
- +850 added · −171 removed · 3 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 15 of 20: Paragraphs 782–841
Added1. Member States shall lay down the rules on penalties applicable to infringements by economic operators of this Regulation and shall take all measures necessary to ensure that they are enforced. The penalties provided for shall be effective, proportionate and dissuasive. Member States shall ensure that those rules take into account the financial capabilities of microenterprises and small and medium-sized enterprises.
Added2. Member States shall, without delay, notify the Commission of those rules and of those measures and shall notify it without delay of any subsequent amendment affecting them. The Commission shall ensure that those rules and measures are applied in a uniform and consistent manner across the Union.
Added3. The non-compliance with the essential cybersecurity requirements laid down in Annex I and the obligations set out in Articles 10 and 11 shall be subject to administrative fines of up to 15 000 000 EUR or, if the offender is an undertaking, up to 2.5 % of the its total worldwide annual turnover for the preceding financial year, whichever is higher.
Added4. The non-compliance with any other obligations under this Regulation shall be subject to administrative fines of up to 10 000 000 EUR or, if the offender is an undertaking, up to 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Added5. The supply of incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request shall be subject to administrative fines of up to 5 000 000 EUR or, if the offender is an undertaking, up to 1 % of its total worldwide annual turnover for the preceding financial year, whichever is higher.
Added6. When deciding on the amount of the administrative fine in each individual case, all relevant circumstances of the specific situation shall be taken into account and due regard shall be given to the following:
Added(a) the nature, gravity and duration of the infringement and of its consequences;
Added(aa) whether the infringement is unintentional;
Added(b) whether administrative fines have been already applied by the same or other market surveillance authorities to the same operator for a similar infringement;
Added(c) the size, in particular with regard to microenterprises, small and medium sized-enterprises, including start-ups, and market share of the operator committing the infringement.
Added7. Market surveillance authorities that apply administrative fines shall share this information with the market surveillance authorities of other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.
Added8. Each Member State shall lay down rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
Added9. Depending on the legal system of the Member States, the rules on administrative fines may be applied in such a manner that the fines are imposed by competent national courts or other bodies according to the competences established at national level in those Member States. The application of such rules in those Member States shall have an equivalent effect.
Added10. Administrative fines may be imposed, depending on the circumstances of each individual case, in addition to any other corrective or restrictive measures applied by the market surveillance authorities for the same infringement.
AddedMember States shall allocate the revenues from the penalties referred to in Article 53(1) to projects raising the level of cybersecurity within the Union. Those projects shall aim at least to one of the following:
Added(a) increase the number of skilled professionals in the field of cybersecurity, notably women;
Added(b) increase capacity-building for microenterprises and small and medium-sized enterprises in order to facilitate their compliance with this Regulation;
Added(c) improve public awareness of cyber threats, with particular regard to their prevention and management;
Added(d) develop tools to increase the resilience of Union undertakings to cyber-enabled intellectual property theft.
AddedTRANSITIONAL AND FINAL PROVISIONS
AddedIn Annex I to Regulation (EU) 2019/1020 the following point is added:
Added‘71. [Regulation XXX] [Cyber Resilience Act]’.
AddedIn Annex I to Directive (EU) 2020/1828 of the European Parliament and of the Council the following point is added:
Added‘67. [Regulation XXX] [Cyber Resilience Act]’.
Added1. EU type-examination certificates and approval decisions issued regarding cybersecurity requirements for products with digital elements that are subject to other Union harmonisation legislation shall remain valid until [42 months after the date of entry into force of this Regulation], unless they expire before that date, or unless otherwise specified in other Union legislation, in which case they shall remain valid as referred to in that Union legislation.
Added2. Products with digital elements that have been placed on the market before [date of application of this Regulation referred to in Article 57], shall be subject to requirements of this Regulation only if, from that date, those products are subject to substantial modifications in their design or intended purpose.
Added3. By way of derogation from paragraph 2, the obligations laid down in Article 11 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before [date of application of this Regulation referred to in Article 57].
Added3a. Until the date of application of this Regulation, manufacturers may comply with the requirements of this Regulation on a voluntary basis. Where manufacturers comply with this Regulation with regard to their products with digital elements, they shall be considered also to comply with Delegated Regulation (EU) 2022/30.
AddedThe Commission shall repeal Delegated Regulation (EU) 2022/30 on the same date of application of this Regulation.
Added1. By [36 months after the date of application of this Regulation] and every four years thereafter, the Commission shall submit a report on the evaluation and review of this Regulation to the European Parliament and to the Council. The reports shall be made public.
Added2. Every year when presenting the Draft Budget for the following year, the Commission shall submit a detailed assessment of ENISA's tasks under this Regulation as set out in Annex VIa and other relevant Union law and shall detail the financial and human resources needed to fulfil those tasks.
AddedThis Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
AddedIt shall apply from [36 months after the date of entry into force of this Regulation]. However Article 11 shall apply from [18 months after the date of entry into force of this Regulation].
AddedThis Regulation shall be binding in its entirety and directly applicable in all Member States.
AddedDone at …▌,
AddedFor the European Parliament For the Council
AddedThe President The President
AddedESSENTIAL CYBERSECURITY REQUIREMENTS
Added1. Security requirements relating to the properties of products with digital elements
Added(1) Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks;
Added▌
Added(3) On the basis of the cybersecurity risk assessment referred to in Article 10(2) and where applicable, products with digital elements shall:
Added(-a) be made available without known exploitable vulnerabilities;
Added(a) be made available with a secure by default configuration, unless otherwise agreed between the parties in a business-to-business context, including the possibility to reset the product to its original state while retaining all installed security updates;
Added(aa) where technically feasible, be made available on the market with functional separation of security updates from functionality update;
Added(ab) ensure automatic security updates with a clear and easy-to-use opt-out mechanism and the notification of available updates to users;
Added(b) ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems;
Added(c) protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means;
Added(d) protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, as well as report on corruptions or possible unauthorised access;
Added(e) process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended use of the product (‘minimisation of data’);
Added(f) protect the availability of essential and basic functions, also after an incident, including with backup management, and the resilience and mitigation measures against denial of service attacks;
Added(g) minimise their own negative impact on the availability of services provided by other devices or networks;
Added(h) be designed, developed and produced to limit attack surfaces, including external interfaces;
Added(i) be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques;
Added(j) provide security related information by recording and/or monitoring capabilities for relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user;
Added▌
Added(ka) enable users to securely withdraw and remove their data on a permanent basis.
Added2. Vulnerability handling requirements
AddedManufacturers of the products with digital elements shall:
Added(1) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the product;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=15
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 28 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=15 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
year = {2023},
date = {2023-07-27},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=15}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=15},
urldate = {2026-09-28},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}