Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-745538 → A-9-2023-0253
- From
- ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
- To
- A-9-2023-0253 Plenary report of 27 Jul 2023
- Changes
- Not comparable
- Paragraphs
- +850 added · −171 removed · 3 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 17 of 20: Paragraphs 902–961
Added8. Secure elements;
Added9. Hardware Security Modules (HSMs);
Added10. Secure cryptoprocessors;
Added11. Smartcards, smartcard readers and tokens;
Added12. Industrial Automation & Control Systems (IACS) intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC) and supervisory control and data acquisition systems (SCADA);
Added13. Industrial Internet of Things devices intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555;
Added▌
Added15. Smart meters.
AddedEU DECLARATION OF CONFORMITY
AddedThe EU declaration of conformity referred to in Article 20, shall contain all of the following information:
Added1. Name and type and any additional information enabling the unique identification of the product with digital elements;
Added2. Name and address of the manufacturer or his authorised representative;
Added3. A statement that the EU declaration of conformity is issued under the sole responsibility of the provider;
Added4. Object of the declaration (identification of the product allowing traceability. It may include a photograph, where appropriate);
Added5. A statement that the object of the declaration described above is in conformity with the relevant Union harmonisation legislation;
Added6. References to any relevant harmonised standards used or any other common specification or cybersecurity certification in relation to which conformity is declared;
Added7. Where applicable, the name and number of the notified body, a description of the conformity assessment procedure performed and identification of the certificate issued;
Added8. Additional information:
AddedSigned for and on behalf of: …………………………………
Added(place and date of issue):
Added(name, function) (signature):
AddedCONTENTS OF THE TECHNICAL DOCUMENTATION
AddedThe technical documentation referred to in Article 23 shall contain at least the following information, as applicable to the relevant product with digital elements:
Added1. a general description of the product with digital elements, including:
Added(a) its intended purpose;
Added(b) versions of software affecting compliance with essential requirements;
Added(c) where the product with digital elements is a hardware product, photographs or illustrations showing external features, marking and internal layout;
Added(d) user information and instructions as set out in Annex II;
Added2. a description of the design, development and production of the product and vulnerability handling processes, including:
Added(a) complete information on the design and development of the product with digital elements, including, where applicable, drawings and schemes and/or a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing;
Added(b) complete information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;
Added(c) complete information and specifications of the production and monitoring processes of the product with digital elements and the validation of these processes.
Added3. an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained as laid down in Article 10 of this Regulation, including how the essential requirements set out in Annex I, Section 1, are applicable;
Added4. a list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union, common specifications as set out in Article 19 of this Regulation or cybersecurity certification schemes under Regulation (EU) 2019/881 pursuant to Article 18(3), and, where those harmonised standards, common specifications or cybersecurity certification schemes have not been applied, descriptions of the solutions adopted to meet the essential requirements set out in Sections 1 and 2 of Annex I, including a list of other relevant technical specifications applied. In the event of partly applied harmonised standards, common specifications or cybersecurity certifications, the technical documentation shall specify the parts which have been applied;
Added5. reports of the tests carried out to verify the conformity of the product and of the vulnerability handling processes with the applicable essential requirements as set out in Sections 1 and 2 of Annex I;
Added6. a copy of the EU declaration of conformity;
Added7. where applicable, the software bill of materials as defined in Article 3, point (36), further to a reasoned request from a market surveillance authority provided that it is necessary in order for this authority to be able to check compliance with the essential requirements set out in Annex I.
AddedCONFORMITY ASSESSMENT PROCEDURES
AddedConformity Assessment procedure based on internal control (based on Module A)
Added1. Internal control is the conformity assessment procedure whereby the manufacturer fulfils the obligations laid down in points 2, 3 and 4, and ensures and declares on its sole responsibility that the products with digital elements satisfy all the essential requirements set out in Section 1 of Annex I and the manufacturer meets the essential requirements set out in Section 2 of Annex I.
Added2. The manufacturer shall draw up the technical documentation described in Annex V.
Added3. Design, development, production and vulnerability handling of products with digital elements
AddedThe manufacturer shall take all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure compliance of the manufactured or developed products with digital elements and of the processes put in place by the manufacturer with the essential requirements set out in sections 1 and 2 of Annex I.
Added4. Conformity marking and declaration of conformity
Added4.1. The manufacturer shall affix the CE to each individual product with digital elements that satisfies the applicable requirements of this Regulation.
Added4.2. The manufacturer shall draw up a written EU declaration of conformity for each product with digital elements in accordance with Article 20 and keep it together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or the support period, whichever is longer. The EU declaration of conformity shall identify the product with digital elements for which it has been drawn up. A copy of the EU declaration of conformity shall be made available to the relevant authorities upon request.
Added5. Authorised representatives
AddedThe manufacturer’s obligations set out in point 4 may be fulfilled by his authorised representative, on his behalf and under his responsibility, provided that they are specified in the mandate.
AddedEU-type examination (based on Module B)
Added1. EU-type examination is the part of a conformity assessment procedure in which a notified body examines the technical design and development of a product and the vulnerability handling processes put in place by the manufacturer, and attests that a product with digital elements meets the essential requirements set out in Section 1 of Annex I and that the manufacturer meets the essential requirements set out in Section 2 of Annex I.
Added2. EU-type examination shall be carried out by assessment of the adequacy of the technical design and development of the product through examination of the technical documentation and supporting evidence referred to in point 3, plus examination of specimens of one or more critical parts of the product (combination of production type and design type).
Added3. The manufacturer shall lodge an application for EU-type examination with a single notified body of his choice.
AddedThe application shall include:
Added– the name and address of the manufacturer and, if the application is lodged by the authorised representative, his name and address as well;
Added– a written declaration that the same application has not been lodged with any other notified body;
Added– the technical documentation, which shall make it possible to assess the product's conformity with the applicable essential requirements as set out in Section 1 of Annex I and the manufacturer's vulnerability handling processes set out in Section 2 of Annex I, and shall include an adequate analysis and assessment of the risk(s). The technical documentation shall specify the applicable requirements and cover, as far as relevant for the assessment, the design, manufacture and operation of the product. The technical documentation shall contain, wherever applicable, at least the elements set out in Annex V;
Added– the supporting evidence for the adequacy of the technical design and development solutions and vulnerability handling processes. This supporting evidence shall mention any documents that have been used, in particular where the relevant harmonised standards and/or technical specifications have not been applied in full. The supporting evidence shall include, where necessary, the results of tests carried out by the appropriate laboratory of the manufacturer, or by another testing laboratory on his behalf and under his responsibility.
Added4. The notified body shall:
Added4.1. examine the technical documentation and supporting evidence to assess the adequacy of the technical design and development of the product with the essential requirements set out in Section 1 of Annex I and of the vulnerability handling processes put in place by the manufacturer with the essential requirements set out in Section 2 of Annex I;
Added4.2. verify that the specimen(s) have been developed or manufactured in conformity with the technical documentation, and identify the elements which have been designed and developed in accordance with the applicable provisions of the relevant harmonised standards and/or technical specifications, as well as the elements which have been designed and developed without applying the relevant provisions of those standards;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=17
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 28 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=17 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
year = {2023},
date = {2023-07-27},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=17}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=17},
urldate = {2026-09-28},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}