Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-745538 → A-9-2023-0253

From
ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
To
A-9-2023-0253 Plenary report of 27 Jul 2023
Changes
Not comparable
Paragraphs
+850 added · −171 removed · 3 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 8 of 20: Paragraphs 362–421

Added(33) ‘market surveillance authority’ means the authority as defined in Article 3, point (4) of Regulation (EU) 2019/1020;

Added(34) ‘harmonised standard’ means a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012;

Added(34a) ‘international standard’ means an international standard as defined in Article 2, point (1)(a) of Regulation (EU) No 1025/2012;

Added(35) ‘▌risk’ means risk as defined in Article 6, point (9) of Directive (EU) 2022/2555;

Added(36) ‘significant cybersecurity risk’ means a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption;

Added(37) ‘software bill of materials’ or ‘SBOM’ means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;

Added(38) ‘vulnerability’ means a vulnerability as defined in Article 6, point (15) of Directive (EU) 2022/2555;

Added(39) ‘actively exploited vulnerability’ means a vulnerability for which there is reliable evidence that execution of malicious code was performed by an actor on a system without permission of the system owner;

Added(39a) ‘incident’ means an incident as defined in Article 6, point (6) of Directive (EU) 2022/2555;

Added(39b) ‘near miss’ means a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555;

Added(39c) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;(40) ‘personal data’ means data as defined in Article 4, point (1), of Regulation (EU) 2016/679.

Added1. Member States shall not impede, for the matters covered by this Regulation, the making available on the market of products with digital elements which comply with this Regulation.

Added2. ▌Member States shall not prevent the presentation and use of a prototype product with digital elements which does not comply with this Regulation, provided that the availability of such a product is limited in time and geographical area and is supplied exclusively for testing and, where possible, a visible sign indicating its non-compliance.

Added3. Member States shall not prevent the making available free of charge of unfinished software which does not comply with this Regulation provided that the software is only made available for a limited period required for testing purposes and that a visible sign clearly indicates that it does not comply with this Regulation and will not be available on the market for purposes other than testing.

Added3a. Member States, if applicable with the support of ENISA, may establish controlled testing environments for innovative products to facilitate their development. In that context, particular support shall be provided for microenterprises, small and medium-sized enterprises, including start-ups.

AddedProducts with digital elements shall only be made available on the market where:

Added(1) they meet the essential requirements set out in Section 1 of Annex I, under the condition that they are properly installed, maintained, used for their intended purpose or under conditions which can reasonably be foreseen, and, where applicable, provided with the necessary security and functionality updates, and

Added(2) the processes put in place by the manufacturer comply with the essential requirements set out in Section 2 of Annex I.

Added1. Products with digital elements that belong to a category which is listed in Annex III shall be considered critical products with digital elements. Products which have the core functionality of a category that is listed in Annex III to this Regulation shall be considered as falling into that category. Categories of critical products with digital elements shall be divided into class I and class II as set out in Annex III, reflecting the level of cybersecurity risk related to these products.

AddedThe integration of a product of higher class of criticality does not change the level of criticality for the product into which it is integrated.

Added2. The Commission is empowered to adopt delegated acts in accordance with Article 50 to amend Annex III by including in the list of categories of critical products with digital elements a new category or withdrawing an existing one from that list. The first such delegated act may be adopted no earlier than two years after the date of entry into force of this Regulation. Any subsequent delegated act may be adopted at the earliest two years thereafter. When assessing the need to amend the list in Annex III, the Commission shall take into account the level of cybersecurity risk related to the category of products with digital elements. In determining the level of cybersecurity risk, one or several of the following criteria shall be taken into account:

Added(a) the cybersecurity-related functionality of the product with digital elements, and whether the product with digital elements has at least one of following attributes:

Added(i) it is designed to run with elevated privilege or manage privileges;

Added(ii) it has direct or privileged access to networking or computing resources;

Added(iii) it is designed to control access to data or operational technology;

Added(iv) it performs a function critical to trust, in particular security functions such as network control, endpoint security, and network protection.

Added(b) the intended use in sensitive environments, including in industrial settings or by essential entities of the type referred to in the Article 3 of Directive (EU) 2022/2555;

Added(c) the intended use of performing critical or sensitive functions, such as processing of personal data;

Added(d) the potential extent of an adverse impact, in particular in terms of its intensity and its ability to affect a plurality of persons;

Added(e) the extent to which the use of products with digital elements has already caused material or non-material loss or disruption or has given rise to significant concerns in relation to the materialisation of an adverse impact.

Added3. The Commission is empowered to adopt a delegated act in accordance with Article 50 to supplement this Regulation by specifying the definitions of the product categories under class I and class II as set out in Annex III. The delegated act shall be adopted by ... [▌ 6 months after the entry into force of this Regulation].

Added4. Critical products with digital elements shall be subject to the conformity assessment procedures referred to in Article 24(2) and (3).

AddedWhere a new category of critical products with digital elements is added to class I or II as set out in Annex III by means of a delegated act pursuant to paragraph 2 of this Article, it shall be subject to the relevant conformity assessment procedures referred to in Article 24(2) and (3) of this Regulation within 12 months of the date of adoption of the delegated act concerned.

Added5. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by specifying categories of highly critical products with digital elements for which the manufacturers shall be required to obtain a European cybersecurity certificate under a European cybersecurity certification scheme at assurance level ‘high’ pursuant to Regulation (EU) 2019/881 to demonstrate conformity with the essential requirements set out in Annex I, or parts thereof. The obligation to obtain a European cybersecurity certificate shall apply within 12 months of the adoption of the relevant delegated act. When determining such categories of highly critical products with digital elements, the Commission shall take into account the level of cybersecurity risk related to the category of products with digital elements, in light of one or several of the criteria listed in paragraph 2, as well as in view of the assessment of whether that category of products is:

Added(a) used or relied upon by the essential entities of the type referred to in Article 3 of ▌Directive (EU) 2022/2555 or will have potential future significance for the activities of these entities; or

Added(b) relevant for the resilience of the overall supply chain of products with digital elements against disruptive events.

Added5a. The Commission is empowered to adopt the delegated acts referred to in paragraph 5 of this Article no earlier than 12 months after the adoption of the relevant European cybersecurity certification scheme pursuant to Regulation (EU) 2019/881.

Added1. By ... [6 months after the date of entry into force of this Regulation], the Commission shall establish an expert group on cyber resilience (the ‘Expert Group’). The Expert Group shall be appointed for a renewable three-year term by the Commission. The composition of the Expert Group shall aim to be gender and geographically balanced and shall include the following:

Added(a) representatives of each of the following:

Added(i) the European Union Agency for Cybersecurity;

Added(ia) the European Cybersecurity Competence Centre;

Added(ii) the European Data Protection Board;

Added(iii) European standardisation bodies.

AddedWhere needed, representatives of other Union Agencies may be invited.

Added(b) experts representing relevant economic operators, ensuring the adequate representation of microenterprises and small and medium-sized enterprises;

Added(c) experts representing civil society, including consumer organisations and the free and open-source community;

Added(d) experts appointed in a personal capacity, who have proven knowledge and experience in the areas covered by this Regulation;

Added(e) experts representing academia, including universities, research institutes and other scientific organisations, including persons with global expertise.

Added2. The Expert Group shall advise the Commission with regard to the following:

Added(a) the list of critical products with digital elements set out in Annex III, as well as on the possible need to update that list;

Added(b) the implementation of European cybersecurity certification schemes pursuant to Regulation (EU) 2019/881 and on the possibility to make them mandatory for highly critical products with digital elements;

Added(c) non-binding evaluations of products with digital elements upon request by a market surveillance authority that is conducting an investigation under Article 43;

Added(d) the application of relevant concepts of the new legislative framework to software, in particular free and open-source software;

Added(e) the elements of the Regulation to be addressed by the guidelines referred to in Article 17a;

Added(f) the availability and the quality of European and international standards, and the possibility to supplement or replace them with common technical specifications;

Added(g) the availability of skilled professionals in the field of cybersecurity across the Union, including of adequate personnel to perform third-party conformity assessments pursuant to this Regulation;

Added(h) the possible need to amend this Regulation.

AddedThe Expert Group shall also map trends at Union and Member State level regarding existing and patched vulnerabilities.

Added3. The Expert Group shall take into account the views of a wide range of stakeholders and perform their tasks with highest level of professionalism, independence, impartiality and objectivity.

Added3a. The Commission shall consult the Expert Group when preparing delegated or implementing acts based upon this Regulation.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
30 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=8 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
  year = {2023},
  date = {2023-07-27},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=8}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=8},
  urldate = {2026-09-30},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}