Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-745538 → A-9-2023-0253

From
ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
To
A-9-2023-0253 Plenary report of 27 Jul 2023
Changes
Not comparable
Paragraphs
+850 added · −171 removed · 3 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 2 of 20: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

9 unchanged paragraphs

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

(COM(2022)0454 – C90308/2022 – 2022/0272(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

– having regard to the Commission proposal to Parliament and the Council (COM(2022)0454),

– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90308/2022),

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to the opinion of the European Economic and Social Committee of 14 December 2022,

– having regard to Rule 59 of its Rules of Procedure,

Changed– having regard to the opinionsopinion of the Committee on Civil Liberties, Justice and Home Affairs and the Committee on the Internal Market and Consumer Protection,

Changed– having regard to the report of the Committee on Industry, Research and Energy (A90000/2023),(A9-0253/2023),

1. Adopts its position at first reading hereinafter set out;

Change 1

Changed2. Requests the Commission to modify the financial statement accompanying the proposal by increasing the establishment plan of the European Union Agency for Cybersecurity (ENISA) by 8,59.0 additional full-time postsandposts and by providing corresponding additional appropriations in order to ensure that the obligations of ENISA under this Regulation can be fulfilled and not to compromise existing obligations of the Agency under other Union legislation;

3. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

4. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Change 2

RemovedRecital 1: (1) Cybersecurity is one of the key challenges for the Union and the number and variety of connected devices will rise exponentially in the coming years. Cyberattacks are also on the rise and have a critical impact not just on the Union’s economy, but also on democracy and society in the Union. It is therefore necessary to strengthen the Union’s approach to cybersecurity and cyber resilience and to improve the functioning of the internal market by laying down a uniform regulatory framework for essential cybersecurity requirements for placing products with digital elements on the Union market. Two major problems adding costs for users and society should be addressed: a low level of cybersecurity of products with digital elements, reflected by widespread vulnerabilities and the insufficient and inconsistent provision of security updates to address them, and an insufficient understanding and access to information by users, preventing them from choosing products with adequate cybersecurity properties or using them in a secure manner.

AddedAMENDMENTS BY THE EUROPEAN PARLIAMENT*

RemovedRecital 2: (2) This Regulation aims to set the boundary conditions for the development of secure products with digital elements by ensuring that hardware and software products are placed on the market with fewer vulnerabilities and that manufactures take security seriously throughout a product’s life cycle. It also aims to create conditions allowing users to take cybersecurity into account when selecting and using products with digital elements, for example by improving transparency with regard to the expected lifetime of products placed on the market and the provision of security updates.

Addedto the Commission proposal

RemovedRecital 4: (4) While the existing Union legislation applies to certain products with digital elements, there is no horizontal Union regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements. The various acts and initiatives taken thus far at Union and national levels only partially address the identified cybersecurity-related problems and risks, creating a legislative patchwork within the internal market, increasing legal uncertainty for both manufacturers and users of those products and adding an unnecessary burden on undertakings to comply with a number of requirements for similar types of products. The cybersecurity of these products has a particularly strong cross-border dimension, as products manufactured in one country are often used by organisations and consumers across the entire internal market. This makes it necessary to regulate the field at Union level, to ensure a harmonised and clear regulatory framework for undertakings, particularly micro, small and medium-sized enterprises. The Union regulatory landscape should be harmonised by introducing cybersecurity requirements for products with digital elements. In addition, certainty for operators and users should be ensured across the Union, as well as a better harmonisation of the single market, creating more viable conditions for operators aiming at entering the Union market.

Added---------------------------------------------------------

RemovedRecital 4 a (new): (4a) The horizontal nature of this Regulation means that it will have an impact on very different segments of the Union's economy. It is therefore important that the specificities of each sector are taken into account and that the cybersecurity requirements laid down in this Regulation are proportional to the risks, in order to avoid overburdening specific sectors. The Commission should issue and publish guidelines, including with regard to those matters, to assist businesses in implementing this Regulation.

AddedProposal for a

RemovedRecital 5: (5) At Union level, various programmatic and political documents, such as the EU’s Cybersecurity Strategy for the Digital Decade16 , the Council Conclusions of 2 December 2020 and of 23 May 2022 or the Resolution of the European Parliament of 10 June 202117 have called for specific Union cybersecurity requirements for digital or connected products, with several countries around the world introducing measures to address this issue on their own initiative. In the final report of the Conference on the Future of Europe,18 citizens called for “a stronger role for the EU in countering cybersecurity threats”. In order for the Union to play a leading international role in the field of cybersecurity, it is important to establish an ambitious overarching regulatory framework.

AddedREGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

RemovedRecital 8: (8) By setting cybersecurity requirements for placing on the market products with digital elements, the cybersecurity of these products for consumers and for businesses alike will be enhanced. This also includes requirements for placing on the market consumer products with digital elements intended for vulnerable consumers, such as toys and baby monitors. Those requirements will also ensure that cybersecurity is taken into account throughout supply chains, for the purpose of making final products with digital elements more secure. This will, in turn, represent a competitive advantage for manufacturers established or represented in the Union, which will be able to showcase the cybersecurity of their products.

Addedon horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 and Directive 2020/1828/EC (Cyber Resilience Act)

RemovedRecital 9: (9) This Regulation ensures a high level of cybersecurity of products with digital elements. It does not regulate services, such as Software-as-a-Service (SaaS), except for remote data processing solutions relating to a product with digital elements understood as any data processing at a distance for which the software is designed and developed by the manufacturer of the product concerned or under the responsibility of that manufacturer, and the absence of which would prevent such a product with digital elements from performing one of its core functions. Directive (EU) 2022/2555 puts in place cybersecurity and incident reporting requirements for essential and important entities, such as critical infrastructure, with a view to increasing the resilience of the services they provide. Directive (EU) 2022/2555 applies to cloud computing services and cloud service models, such as SaaS. All entities providing cloud computing services in the Union that meet or exceed the threshold for medium-sized enterprises fall in the scope of that Directive.

Added(Text with EEA relevance)

RemovedRecital 10: (10) In order not to hamper innovation or research, only free and open-source software supplied in the course of a commercial activity should be covered by this Regulation. In the context of software, a commercial activity might be characterized not only by charging a price for a product, but also by charging a price for technical support services, by providing a software platform through which the manufacturer monetises other services, or by the use of personal data for reasons other than exclusively for improving the security, compatibility or interoperability of the software. Where free and open-source software has been developed or supplied outside the course of a commercial activity, manufacturers that incorporate such software in their products with digital elements should take all the necessary steps to ensure the compliance with this Regulation.

AddedTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

RemovedRecital 12 a (new): (12a) Products with digital elements that are developed exclusively for national security or military purposes or products that are specifically designed to process classified information fall outside the scope of this Regulation. However, Member States are encouraged to ensure the same or higher level of protection for those products as for those falling within the scope of this Regulation.

AddedHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

RemovedRecital 14 a (new): (14a) This Regulation should not apply to components that are exclusively manufactured in order to replace identical components during repair operations in legacy products with digital elements, in order to avoid products with digital elements already circulating in the internal market having to be withdrawn due to the lack of spare parts.

AddedHaving regard to the proposal from the European Commission,

RemovedRecital 14 b (new): (14b) Leasing companies are not considered to be distributors for the purposes of this Regulation, insofar as their activities qualify solely as finance or credit provisions in support of the activities of the manufacturers or other economic operators.

AddedAfter transmission of the draft legislative act to the national parliaments,

RemovedLeasing companies acting as third-party for financing purposes in leasing contracts should not qualify as distributors, provided that their activities are only focused on the financing element.

AddedHaving regard to the opinion of the European Economic and Social Committee,

RemovedRecital 15: (15) Delegated Regulation (EU) 2022/30 specifies that the essential requirements set out in Article 3(3), point (d) (network harm and misuse of network resources), point (e) (personal data and privacy) and point (f) (fraud) of Directive 2014/53/EU apply to certain radio equipment. [Commission implementation decision XXX/2022 on a standardisation request to the European Standardisation Organisations] lays down requirements for the development of specific standards further specifying how these three essential requirements should be addressed. The essential requirements laid down by this Regulation include all the elements of the essential requirements referred to in Article 3(3), points (d), (e) and (f) of Directive 2014/53/EU. Further, the essential requirements laid down in this Regulation are aligned with the objectives of the requirements for specific standards included in that standardisation request. Therefore, if the Commission repeals or amends Delegated Regulation (EU) 2022/30 with the consequence that it ceases to apply to certain products subject to this Regulation, the Commission and the European Standardisation Organisations should take into account the standardisation work carried out in the context of Commission Implementing Decision C(2022)5637 on a standardisation request for the RED Delegated Regulation 2022/30 in the preparation and development of harmonised standards to facilitate the implementation of this Regulation. Where manufacturers comply with this Re…

AddedHaving regard to the opinion of the Committee of the Regions,

RemovedRecital 18 a (new): (18a) When procuring products with digital elements, Member States should give priority to products that have a high level of cybersecurity and an appropriate expected product lifetime, in order to improve their ability to deal with cyber threats, as well as to ensure the efficient use of public resources. Furthermore, Member States should ensure that manufacturers remedy vulnerabilities that affect publicly procured products with digital elements as a matter of urgency.

AddedActing in accordance with the ordinary legislative procedure,

RemovedRecital 19: (19) Certain tasks provided for in this Regulation should be carried out by ENISA, in accordance with Article 3(2) of Regulation (EU) 2019/881. In particular, ENISA should receive notifications from manufacturers of actively exploited vulnerabilities contained in products with digital elements, as well as significant incidents having an impact on the security of those products. ENISA should also forward these notifications to the relevant Computer Security Incident Response Teams (CSIRTs) or, respectively, to the relevant single points of contact of the Member States designated in accordance with Article [Article X] of Directive (EU) 2022/2555, and inform the relevant market surveillance authorities about the notified vulnerability. ENISA should ensure that such notifications are received, stored and transmitted via secure channels and that clear protocols are in place with regard to who can access them and the arrangements for their onward transmission. ENISA should not release to the public information about vulnerabilities for which a security update is not available. On the basis of the information it gathers, ENISA should prepare a biennial technical report on emerging trends regarding cybersecurity risks in products with digital elements and submit it to the Cooperation Group referred to in Directive (EU) 2022/2555. Furthermore, considering its expertise and mandate, ENISA should be able to support the process for implementation of this Regulation. In particular, it sho…

AddedWhereas:

RemovedRecital 19 a (new): (19a) ENISA should publish notified vulnerabilities in the European vulnerability database established under Directive (EU) 2022/2555. ENISA should have in place an appropriate procedure regarding the publication process in order to give manufacturers the time to develop the necessary security updates and users the time to implement them or take other corrective or mitigating measures. The database is intended to help manufacturers detect known exploitable vulnerabilities and understand their criticality, in order to place on the market more secure products.

Added(1) Cybersecurity is one of the key challenges for the Union and the number and variety of connected devices will rise exponentially in the coming years. Cyberattacks represent a matter of public interest as they have a critical impact not just on the Union’s economy, but also on democracy and consumer safety and health. It is therefore necessary to strengthen the Union’s approach to cybersecurity, address cyber resilience at Union level and improve the functioning of the internal market by laying down a uniform legal framework for essential cybersecurity requirements for placing products with digital elements on the Union market. Two major problems adding costs for users and society should be addressed: a low level of cybersecurity of products with digital elements, reflected by widespread vulnerabilities and the insufficient and inconsistent provision of security updates to address them, and an insufficient understanding and access to information by users, preventing them from choosing products with adequate cybersecurity properties or using them in a secure manner.

RemovedRecital 27: (27) The categories of critical products with digital elements referred to in Annex III of this Regulation should be understood as the products which have the core functionality of the type that is listed in Annex III to this Regulation. For example, Annex III to this Regulation lists products which are defined by their core functionality as general purpose microprocessors in class II. As a result, general purpose microprocessors are subject to mandatory third-party conformity assessment. This is not the case for other products not explicitly referred to in Annex III to this Regulation which may integrate a general purpose microprocessor. The Commission should adopt delegated acts [by 6 months since the entry into force of this Regulation] to specify the definitions of the product categories covered under class I and class II as set out in Annex III. In order to ensure legal clarity and certainty, amendments to the list in Annex III should be made no more frequently than once every two years and should be adopted only after a thorough evaluation by the Commission, including consultation of stakeholders.

Added(2) This Regulation aims to set the boundary conditions for the development of secure products with digital elements by ensuring that hardware and software products are placed on the market with fewer vulnerabilities and that manufactures take security seriously throughout a product’s life cycle. It also aims to create conditions allowing users to take cybersecurity into account when selecting and using products with digital elements, for example by improving transparency with regard to the support period of products placed on the market.

RemovedRecital 27 a (new): (27a) The Commission should set up an expert group on cyber resilience (the ‘Expert Group’), with a wide and diverse membership. The Expert Group should support the Commission in order to ensure the proper implementation of this Regulation, for example by advising the Commission on possible amendments to the list of critical products as set out in Annex III or by analysing in what way European and international standards can enable compliance with the essential requirements of this Regulation.

Added(3) The relevant Union legislation that is currently in force comprises several sets of horizontal rules that address certain aspects linked to cybersecurity from different angles, including measures to improve the security of the digital supply chain. However, the existing Union legislation related to cybersecurity, including Regulation (EU) 2019/881 of the European Parliament and of the Council and Directive (EU) 2022/2555 of the European Parliament and of the Council does not directly cover mandatory requirements for the security of products with digital elements.

RemovedRecital 32: (32) In order to ensure that products with digital elements are secure both at the time of their placing on the market as well as throughout their life-cycle, it is necessary to lay down essential requirements for vulnerability handling and essential cybersecurity requirements relating to the properties of products with digital elements. While manufacturers should comply with all essential requirements related to vulnerability handling throughout the expected product lifetime, they should determine which other essential requirements related to the product properties are relevant for the concerned type of product. For this purpose, manufacturers should undertake an assessment of the cybersecurity risks associated with a product with digital elements to identify relevant risks and relevant essential requirements and in order to deliver their products without known exploitable vulnerabilities that might have an impact on the security of those products and to appropriately apply suitable harmonised standards or common specifications.

Added(4) While the existing Union legislation applies to certain products with digital elements, there is no horizontal Union regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements. The various acts and initiatives taken thus far at Union and national levels only partially address the identified cybersecurity-related problems and risks, creating a legislative patchwork within the internal market, increasing legal uncertainty for both manufacturers and users of those products and adding an unnecessary burden on undertakings and organisations to comply with a number of requirements for similar types of products. The cybersecurity of these products has a particularly strong cross-border dimension, as products manufactured in one country are often used by organisations and consumers across the entire internal market. This makes it necessary to regulate the field at Union level, to ensure a harmonised and clear regulatory framework for undertakings, particularly micro, small and medium-sized enterprises. The Union regulatory landscape should be harmonised by introducing cybersecurity requirements for products with digital elements. In addition, certainty for operators and users should be ensured across the Union, as well as a better harmonisation of the single market and proportionality for microenterprises and small and medium-sized enterprises, creating more viable conditions for economic operators aiming at entering the Union market.

RemovedRecital 32 a (new): (32a) Manufacturers should ensure, where possible and in particular in the case of business-to-consumer products, that security updates are installed automatically in order to remedy potential vulnerabilities as soon as possible. Users should retain the possibility to de-activate this feature. Once a product with digital elements has reached the end of its expected product lifetime and security updates are no longer made available, manufacturers should inform users in a simple and clear manner, for example via the display of a user-friendly notification.

Added(4a) The horizontal nature of this Regulation means that it will have an impact on very different segments of the Union's economy. It is therefore important that the specificities of each sector are taken into account and that the cybersecurity requirements laid down in this Regulation are proportional to the risks. The Commission should therefore issue guidelines which explain in a clear and detailed manner how to apply this Regulation. Guidelines should cover inter alia a detailed explanation of the scope, in particular the notion of remote data processing and the implications for free and open-source developers, the criteria used to determine how critical products with digital elements are classified and the interplay between this Regulation and other Union law.

RemovedRecital 32 b (new): (32b) Where manufacturers set the expected period lifetime to a period shorter than five years and therefore no longer offer security updates for the product with digital elements, they should make their source code available to undertakings that wish to provide security updates and other similar services. Such access should be made available only as part of a contractual arrangement that protects the ownership of the product with digital elements and prevents the dissemination of the source code to the general public. The obligation to provide free access to the source code should be in place only for five years after the product with digital elements has been placed on the market.

Added(4b) A business operating online may offer a variety of different services. Depending on the nature of services provided, the same entity may fall under several different categories of economic operators. Where an entity provides online intermediation services for a product with digital elements and is a provider of an online marketplace, as defined in Article 3(14) of Regulation 2023/988 of the European Parliament and of the Council, it does not qualify as an economic operator as defined in this Regulation. Where the same entity is a provider of an online marketplace and acts as an economic operator as defined in this Regulation, for the sale of products with digital elements, it should be subject to the scope of this Regulation with regard to such products. The provisions of Regulation (EU) 2023/988 is fully applicable to this Regulation. Given the prominent role that online marketplaces have in enabling electronic commerce, they should strive to cooperate with the market surveillance authorities of the Member States in order to ensure that products purchased through online marketplaces comply with the cybersecurity requirements laid down in this Regulation.

RemovedRecital 34: (34) To ensure that the national CSIRTs and the single point of contacts designated in accordance with Article [Article X] of Directive (EU) 2022/2555 are provided with the information necessary to fulfil their tasks and raise the overall level of cybersecurity of essential and important entities, and to ensure the effective functioning of market surveillance authorities, manufacturers of products with digital elements should notify to ENISA vulnerabilities that are being actively exploited. Mandatory notification should not apply to vulnerabilities that are discovered by ethical security hackers operating with no malicious intent and with the manufacturer’s consent. As most products with digital elements are marketed across the entire internal market, any exploited vulnerability in a product with digital elements should be considered a threat to the functioning of the internal market. Manufacturers should disclose fixed vulnerabilities to the European vulnerability database established under Directive (EU) 2022/2555 and managed by ENISA.

Added(5) At Union level, various programmatic and political documents, such as the EU’s Cybersecurity Strategy for the Digital Decade, the Council Conclusions of 2 December 2020 and of 23 May 2022 or the Resolution of the European Parliament of 10 June 2021, have called for specific Union cybersecurity requirements for digital or connected products, with several countries around the world introducing measures to address this issue on their own initiative. In the final report of the Conference on the Future of Europe, citizens called for “a stronger role for the EU in countering cybersecurity threats”. In order for the Union to play a leading international role in the field of cybersecurity, it is important to establish an ambitious overarching regulatory framework.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=2 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
  year = {2023},
  date = {2023-07-27},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=2}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=2},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}