Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-745538 → A-9-2023-0253

From
ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
To
A-9-2023-0253 Plenary report of 27 Jul 2023
Changes
Not comparable
Paragraphs
+850 added · −171 removed · 3 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 16 of 20: Paragraphs 842–901

Added(2) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates installed automatically where applicable in accordance with Section I;

Added(3) apply effective and regular tests and reviews of the security of the product with digital elements;

Added(4) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities in a controlled way, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities;

Added(5) put in place and enforce a policy on coordinated vulnerability disclosure;

Added(6) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements;

Added(7) provide for mechanisms to securely distribute security updates for products with digital elements to ensure that exploitable vulnerabilities are fixed or mitigated in a timely manner;

Added(8) ensure that, where security patches or updates are available to address identified security issues, they are disseminated without delay and unless otherwise agreed between the parties in a business-to-business context, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken;

Added(8a) where possible and applicable, notify the user of the end of the support period.

AddedINFORMATION AND INSTRUCTIONS TO THE USER

AddedAs a minimum, the product with digital elements shall be accompanied by:

Added1. the name, registered trade name or registered trade mark of the manufacturer, and the postal address and the email address and where available the website at which the manufacturer can be contacted, on the product or ▌ on its packaging or in a document accompanying the product;

Added2. the point of single contact where information about cybersecurity vulnerabilities of the product can be reported and received and the manufactuer’s policy on coordinated vulnerabilities and where it can be found;

Added3. the correct identification of the type, batch, version or serial number or other element allowing the identification of the product and the corresponding instructions and user information;

Added4. the intended use, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties;

Added5. any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks;

Added6. if and, where applicable, where the software bill of materials can be accessed by the competent authorities in accordance with non-disclosure conditions set out in Article 52;

Added7. where applicable, the internet address at which the EU declaration of conformity can be accessed;

Added8. the type of technical security support offered by the manufacturer and the support period during which users can expect vulnerabilities to be handled and to receive security updates;

Added9. detailed instructions or an internet address referring to such detailed instructions and information on:

Added(a) the necessary measures during initial commissioning and throughout the lifetime of the product to ensure its secure use;

Added(b) how changes to the product can affect the security of data;

Added(c) how security-relevant updates can be installed;

Added(d) the secure decommissioning of the product, including information on how user data can be securely removed.

AddedCRITICAL PRODUCTS WITH DIGITAL ELEMENTS

AddedClass I

Added1. Identity management systems software and privileged access management software;

Added2. Standalone and embedded browsers;

Added3. Password managers;

Added3a. Biometric readers;

Added4. Software that searches for, removes, or quarantines malicious software;

Added5. Products with digital elements with the function of virtual private network (VPN);

Added6. Network management systems;

Added7. Network configuration management tools;

Added8. Network traffic monitoring systems;

Added9. Management of network resources;

Added10. Security information and event management (SIEM) systems;

Added11. Update/patch management, including boot managers;

Added12. Application configuration management systems;

Added13. Remote access ▌ software;

Added14. Mobile device management software;

Added15. Physical and virtual network interfaces;

Added16. Operating systems not covered by class II;

Added17. Firewalls, intrusion detection and/or prevention systems not covered by class II;

Added19. General purpose microprocessors and microprocessors not covered by class II;

Added20. Microcontrollers;

Added21. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) intended for the use by essential entities of the type referred to in Article 3 of Directive(EU) 2022/2555;

Added22. Industrial Automation & Control Systems (IACS) not covered by class II, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC), industrial robots and their control systems and supervisory control and data acquisition systems (SCADA);

Added23. Industrial Internet of Things not covered by class II;

Added23a. Home automation systems, including smart home servers and virtual assistants;

Added23b. Security devices, including smart door locks, cameras and alarm systems;

Added23c. Smart toys;

Added23d. Personal health appliances and wearables.

AddedClass II

Added1. Operating systems for servers, desktops, and mobile devices;

Added2. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments;

Added3. Public key infrastructure and digital certificate issuers;

Added4. Firewalls, intrusion detection and/or prevention systems intended for industrial use;

Added▌

Added6. Microprocessors intended for integration in programmable logic controllers and secure elements;

Added7. Routers, modems intended for the connection to the internet, and switches ▌;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=16 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
  year = {2023},
  date = {2023-07-27},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=16}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=16},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}