Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-745538 → A-9-2023-0253
- From
- ITRE-PR-745538 report parliamentary committee draft of 31 Mar 2023
- To
- A-9-2023-0253 Plenary report of 27 Jul 2023
- Changes
- Not comparable
- Paragraphs
- +850 added · −171 removed · 3 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 9 of 20: Paragraphs 422–481
Added3b. The Expert Group may provide market surveillance authorities with non-binding evaluations of products with digital elements to facilitate investigations under Article 43.
Added4. The Expert Group shall be chaired by the Commission and shall be constituted in accordance with the horizontal rules on the creation and operation of Commission expert groups. In that context, the Commission may invite experts with specific expertise on an ad hoc basis.
Added5. The Expert Group shall carry out its tasks in accordance with the principle of transparency. The Commission shall publish the composition of the Expert Group, the declaration of interests of its members, a summary of the meetings of the Expert Group and other relevant documents on the Commission website.
AddedFor the purpose of this Regulation and in order to respond to the demand of professionals capable of ensuring the cybersecurity of products with digital elements, the Commission and Member States, in cooperation with ENISA, shall ensure the implementation of:
Added(a) education and training programmes in the cyber security field and their associated career pathways, contributing to making the cyber security workforce more resilient and inclusive, also in terms of gender and aligned with the needs of undertakings concerned, in particular where such undertakings are microenterprises, small or medium-sized enterprises, including start-ups, or public administration;
Added(b) initiatives to increase the collaboration between the private sector, economic operators, including via re-skilling or up-skilling for manufacturers’ employees, consumers, education and training providers as well as Member States, expanding the options for young people to access jobs in this sector;
Added(c) strategies aiming to enhance workforce mobility, developing cyber security skills and creating organisational and technological tools to maximise existent cyber security talent.
AddedBy way of derogation from Article 2(1), third subparagraph, point (b), of Regulation (EU) 2023/988 where products with digital elements are not subject to specific requirements laid down in other Union harmonisation legislation within the meaning of [Article 3, point (25) of Regulation (EU) 2023/988, Chapter III, Section 1, Chapters V and VII, and Chapters IX to XI of Regulation (EU) 2023/988 shall apply to those products with respect to safety risks not covered by this Regulation.
Added1. Products with digital elements classified as high-risk AI systems in accordance with Article [Article 6] of Regulation [the AI Regulation] which fall within the scope of this Regulation, and fulfil the essential requirements set out in Section 1 of Annex I of this Regulation, and where the processes put in place by the manufacturer are compliant with the essential requirements set out in Section 2 of Annex I, shall be deemed in compliance with the requirements related to cybersecurity set out in Article [Article 15] of Regulation [the AI Regulation], without prejudice to the other requirements related to accuracy and robustness included in the aforementioned Article, and in so far as the achievement of the level of protection required by those requirements is demonstrated by the EU declaration of conformity issued under this Regulation.
Added2. For the products and cybersecurity requirements referred to in paragraph 1, the relevant conformity assessment procedure as required by Article [Article 43] of Regulation [AI Regulation] shall apply. For the purpose of that assessment, relevant bodies which are entitled to control the conformity of the high-risk AI systems under the Regulation [AI Regulation] shall be also entitled to control the conformity of the high-risk AI systems that fall within the scope of this Regulation with the requirements set out in Annex I to this Regulation, provided that the compliance of those notified bodies with the requirements laid down in Article 29 of this Regulation have been assessed in the context of the notification procedure under Regulation [AI Regulation].
Added3. By derogation from paragraph 2, critical products with digital elements listed in Annex III of this Regulation, which have to apply the conformity assessment procedures referred to in Articles 24(2)(a), 24(2)(b), 24(3)(a) and 24(3)(b) under this Regulation and which are also classified as high-risk AI systems according to Article [Article 6] of the Regulation [AI Regulation] and to which the conformity assessment procedure based on internal control referred to in Annex [Annex VI] to Regulation [the AI Regulation] applies, shall be subject to the conformity assessment procedures as required by this Regulation in so far as the essential requirements of this Regulation are concerned.
Added3a. Manufacturers of products with digital elements classified as high-risk AI systems in accordance with paragraph 1 of this Article may participate in the AI regulatory sandboxes referred to in Article 53 of Regulation [the AI Regulation].
AddedMachinery products that fall within the scope of Regulation (EU) 2023/1230 which are products with digital elements or partly completed products with digital elements within the meaning of this Regulation and for which an EU declaration of conformity has been issued on the basis of this Regulation shall be deemed to be in conformity with the essential health and safety requirements set out in Annex [Annex III, Sections 1.1.9 and 1.2.1] to Regulation (EU) 2023/1230, as regards protection against corruption and safety and reliability of control systems, and in so far as the achievement of the level of protection required by those requirements is demonstrated in the EU declaration of conformity issued under this Regulation.
Added1. Without prejudice to Directives 2014/24/EU and 2014/25/EU of the European Parliament and of the Council, Member States shall ensure, when procuring products with digital elements, a high level of cybersecurity and an appropriate support period.
Added2. Member States shall ensure that manufacturers remedy vulnerabilities in publicly procured products with digital elements, including by making security updates available promptly.
AddedOBLIGATIONS OF ECONOMIC OPERATORS
Added1. When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential requirements set out in Section 1 of Annex I.
Added2. For the purposes of complying with the obligation laid down in paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing security incidents and minimising the impacts of such incidents, including in relation to the health and safety of users.
Added2a. On the basis of the cybersecurity risk assessment, manufacturers shall determine how the essential requirements set out in Section 1 of Annex I are applicable to their product with digital elements. They shall include the risk assessment in the technical documentation as set out in Article 23.3. When placing a product with digital elements on the market, the manufacturer shall include a cybersecurity risk assessment in the technical documentation as set out in Article 23 and Annex V. For products with digital elements referred to in Articles 8 and 24(4) that are also subject to other Union acts, the cybersecurity risk assessment may be part of the risk assessment required by those respective Union acts. Where certain essential requirements are not applicable to the marketed product with digital elements, the manufacturer shall include a clear justification in that documentation.
Added4. For the purposes of complying with the obligation laid down in paragraph 1, manufacturers shall exercise due diligence when integrating components sourced from third parties in products with digital elements. It falls upon the manufacturer to ensure that such components do not compromise the security of the product with digital elements, including when integrating components of free and open-source software that have not been made available on the market in the course of a commercial activity.
AddedManufacturers shall, upon identifying a vulnerability in a component, including in a free and open-source component, which is integrated in the product with digital elements, address and remediate the vulnerability in accordance with the vulnerability handling requirements set out in Annex I, Section 2, and share the corrective measures taken with the person or entity maintaining the component.
Added4a. The manufacturer of components shall provide to the manufacturer of the final product with digital elements the information and documentation necessary to comply with the requirements of this Regulation, when supplying them with such components. This information shall be provided free of charge.
Added5. The manufacturer shall systematically document, in a manner that is proportionate to the nature and the cybersecurity risks, relevant cybersecurity aspects concerning the product with digital elements, including vulnerabilities they become aware of and any relevant information provided by third parties, and, where applicable, update the risk assessment of the product.
Added6. When placing a product with digital elements on the market, manufacturers shall determine the support period during which vulnerabilities of that product are handled effectively and in accordance with the essential requirements set out in Section 2 of Annex I. In doing so, the manufacturer shall ensure that the support period is proportionate to the expected product lifetime as well as in line with the nature of the product and users’ expectations, the availability of the operating environment and, where applicable, the support period of the main components integrated into the product with digital elements. To that end manufacturers shall make available upon request of market surveillance authorities information on the expected product lifetime they considered in order to determine the duration of the support period for the product made available on the market. Market surveillance authorities shall monitor products with digital elements and ensure actively that manufacturers have applied these criteria in an adequate manner, including an assessment of the information received from the manufacturers on the expected product lifetime, when determining the support period.
AddedWhere applicable, the support period shall be clearly stated on the product, its packaging or be included in contractual agreements. In any case, end users shall also be informed before purchase of the duration of the support period.
AddedManufacturers shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Section 2, point (5), of Annex I, to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources.
AddedWhere applicable, for consumer products with digital elements, those procedures shall include automatic security updates by default. Users should retain the possibility of de-activating those automatic security updates.
AddedManufacturers shall actively inform users when their product with digital elements has reached the end of its support period.
Added6a Where the support period is shorter than five years and the handling of vulnerabilities has ended, manufacturers may provide access to the source code of such a product with digital elements to other undertakings which commit to extending the provision of vulnerability handling services, in particular security updates. Access to such source codes shall be provided only where provided for in a contractual arrangement. Those arrangements shall protect the ownership of the product with digital elements and shall prevent the dissemination of the source code to the public, except where such code has already been provided under a free and open-source licence.
Added7. Before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 23.
AddedThey shall carry out the chosen conformity assessment procedures referred to in Article 24 or have them carried out.
AddedWhere compliance of the product with digital elements with the essential requirements set out in Section 1 of Annex I and of the processes put in place by the manufacturer with the essential requirements set out in Section 2 of Annex I has been demonstrated by that conformity assessment procedure, manufacturers shall draw up the EU declaration of conformity in accordance with Article 20 and affix the CE marking in accordance with Article 22.
Added8. Manufacturers shall keep the technical documentation and the EU declaration of conformity▌at the disposal of the market surveillance authorities for at least ten years or the support period, whichever is longer, after the product with digital elements has been placed on the market.
AddedMarket surveillance authorities shall ensure the confidentiality and appropriate protection of the information in the technical documentation provided by manufacturers in accordance with Article 52.
Added9. Manufacturers shall ensure that procedures are in place for products with digital elements that are part of a series of production to remain in conformity. The manufacturer shall adequately take into account changes in the development and production process or in the design or characteristics of the product with digital elements and changes in the harmonised horizontal or sector specific standards, European cybersecurity certification schemes or the common specifications referred to in Article 19 by reference to which the conformity of the product with digital elements is declared or by application of which its conformity is verified.
Added10. Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions set out in Annex II, in an electronic or physical form. Such information and instructions shall be in a language which can be easily understood by users. They shall be clear, understandable, intelligible and legible. They shall allow for a secure installation, operation and use of the products with digital elements.
AddedWhere such information and instructions are provided in electronic form, manufacturers shall:
Added(a) present them in a user-friendly format that makes it possible for the user to consult them online, download them, save them on an electronic device and print them;
Added(b) ensure that they are accessible online during at least the support period of the product with digital elements.
Added11. Manufacturers shall either provide the EU declaration of conformity with the product with digital elements or include in the instructions and information set out in Annex II the internet address at which the EU declaration of conformity can be accessed.
Added12. From the placing on the market and for at least the support period ▌, manufacturers who know or have reason to believe that the product with digital elements or the processes put in place by the manufacturer are not in conformity with the essential requirements set out in Annex I shall immediately take the corrective measures necessary to bring that product with digital elements or the manufacturer’s processes into conformity, to withdraw or to recall the product, as appropriate.
Added13. Manufacturers shall, further to a reasoned request from a market surveillance authority, provide that authority, in a language which can be easily understood by it, with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements and of the processes put in place by the manufacturer with the essential requirements set out in Annex I. They shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by the product with digital elements, which they have placed on the market.
Added14. A manufacturer that ceases its operations and, as a result, is not able to comply with the obligations laid down in this Regulation shall inform, before the cease of operation takes effect, the relevant market surveillance authorities about this situation, as well as, by any means available and to the extent possible, the users of the concerned products with digital elements placed on the market.
Added15. The Commission, after consulting the Expert Group and taking account of international standards, is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by specifying the format and elements of the software bill of materials set out in Section 2, point (1), of Annex I. ▌
Added1. The manufacturer shall▌notify to ENISA any actively exploited vulnerability contained in the product with digital elements in accordance with paragraph 1a of this Article. ▌ENISA shall, without undue delay, unless for justified cybersecurity risk-related grounds, forward the notification to the CSIRT designated for the purposes of coordinated vulnerability disclosure in accordance with Article 12 of Directive (EU) 2022/2555 of Member States concerned upon receipt and inform the market surveillance authority about the notified vulnerability. Where a notified vulnerability has no corrective or mitigating measures available, ENISA shall ensure that information about the notified vulnerability is shared in line with strict security protocols and on a need-to-know-basis.
Added1a. Notifications as referred to in paragraph 1 shall be subject to the following procedure:
Added(a) an early warning, without undue delay and in any event within 24 hours of the manufacturer becoming aware of the existence of an actively exploited vulnerability, including whether any known corrective or recommended risk mitigating measure is available;
Added(b) a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which, where applicable, updates the general information referred to in point (a), including any corrective or mitigating measures taken and indicates an assessment of extent of the vulnerability, including its severity and impact;
Added(c) a final report, within one month after the submission of the vulnerability notification under point (b) or when a corrective or mitigating measure is available, including at least the following:
Added(i) a description of the vulnerability, including its severity and impact;
Added(ii) where available, information concerning any actor that has exploited or that is exploiting the vulnerability;
Added(iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Added1b. After a security update is made available or another form of corrective or mitigating measures is put in place, ENISA shall add the notified vulnerability pursuant to paragraph 1 of this Article to the European vulnerability database referred to in Article 12 of Directive (EU) 2022/2555.
Added2. The manufacturer shall ▌ notify to ENISA any significant incident having impact on the security of the product with digital elements in accordance with paragraph 2b of this Article. ENISA shall, without undue delay, unless for justified cybersecurity risk-related grounds, forward the notifications to the single point of contact designated in accordance with Article 8 of Directive (EU) 2022/2555 of the Member States concerned and inform the market surveillance authority about the notified incidents. The mere act of notification shall not subject the notifying entity to increased liability.
Added2a. An incident shall be considered to be significant as referred to in paragraph 2, where:
Added(a) it has caused or is capable of causing severe operational disruption of the production or the services for the manufacturer concerned, which would impact the security of a product; or
Added(b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
Added2b. Notifications as referred to in paragraph 2 shall be subject to the following procedure:
Added(a) an early warning, without undue delay and in any event within 24 hours of the manufacturer becoming aware of the significant incident, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;
Added(b) an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the significant incident, which, where applicable, shall update the information referred to in point (a) and indicates an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=9
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 30 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-745538 and A-9-2023-0253”. Text, 27 July 2023. from ITRE-PR-745538, to A-9-2023-0253. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=9 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-07-27,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-745538 and A-9-2023-0253}},
year = {2023},
date = {2023-07-27},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=9}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-745538/compare/A-9-2023-0253?all=1&part=9},
urldate = {2026-09-30},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-745538, to A-9-2023-0253. Data: European Parliament Open Data (CC BY 4.0)}
}