Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-752795 → A-9-2023-0426
- From
- ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
- To
- A-9-2023-0426 Plenary report of 8 Dec 2023
- Changes
- Not comparable
- Paragraphs
- +319 added · −52 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 8: Paragraphs 61–120
Added(5) The growing cybersecurity risks and an overall complex threat landscape, with a clear risk of rapid spill-over of cyber incidents from one Member State to others and from a third country to the Union requires strengthened solidarity at Union level to better detect, prepare for, ▌respond to, and recover from, cybersecurity threats and incidents. Member States have also invited the Commission to present a proposal on a new Emergency Response Fund for Cybersecurity in the Council Conclusions on an EU Cyber Posture.
RemovedRecital 39: (39) Since the objective of this Regulation, namely to establish a general framework to avoid silos because cyber space has no borders, cannot be sufficiently achieved by the Member States but can rather be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.
Added(6) The Joint Communication on the EU Policy on Cyber Defence adopted on 10 November 2022 announced an EU Cyber Solidarity Initiative with the following objectives: strengthening of common EU detection, situational awareness and response capabilities by promoting the deployment of an EU network of Security Operations Centres (‘SOCs’), supporting gradual building of an EU-level cybersecurity reserve with services from trusted private providers and testing of critical entities for potential vulnerabilities based on EU risk assessments.
RemovedArticle 1 – paragraph 2 – point a: (a) to strengthen common Union detection and situational awareness of cyber threats and incidents thus allowing to reinforce the competitive position of industry and services sectors in the Union across the digital economy, grow industrial capacity of the Union and its Member States and contribute to the Union’s technological sovereignty in the area of cybersecurity;
Added(7) It is necessary to strengthen the detection and situational awareness of cyber threats and incidents throughout the Union and to strengthen solidarity by enhancing Member States’ and the Union’s preparedness and capabilities to prevent and respond to significant and large-scale cybersecurity incidents. Therefore a pan-European network of SOCs (European Cyber Shield) should be deployed to build and enhance common detection and situational awareness capabilities, reinforcing the Union’s threat detection and information sharing capabilities; a Cybersecurity Emergency Mechanism should be established to support Member States in preparing for, responding to, and immediately recovering from significant and large-scale cybersecurity incidents; a Cybersecurity Incident Review Mechanism should be established to review and assess specific significant or large-scale incidents. These actions shall be without prejudice to Articles 107 and 108 of the Treaty on the Functioning of the European Union (‘TFEU’).
RemovedArticle 1 – paragraph 2 – point c a (new): (ca) to develop, in a coordinated manner, skills and capabilities to ensure cybersecurity, in close cooperation with the Cybersecurity Skills Academy, to provide real opportunities to all and reduce regional disparities, close the talent gap, including closing the gender gap within the cybersecurity sector, and to boost the Union cyber workforce.
Added(8) To achieve these objectives, it is also necessary to amend Regulation (EU) 2021/694 of the European Parliament and of the Council in certain areas. In particular, this Regulation should amend Regulation (EU) 2021/694 as regards adding new operational objectives related to the European Cyber Shield and the Cybersecurity Emergency Mechanism under Specific Objective 3 of DEP, which aims at guaranteeing the resilience, integrity and trustworthiness of the Digital Single Market, at strengthening capacities to monitor cyber-attacks and threats and to respond to them, and at reinforcing cross-border cooperation on cybersecurity. This will be complemented by the specific conditions under which financial support may be granted for those actions should be established and the governance and coordination mechanisms necessary in order to achieve the intended objectives should be defined. Other amendments to Regulation (EU) 2021/694 should include descriptions of proposed actions under the new operational objectives, as well as measurable indicators to monitor the implementation of these new operational objectives.
RemovedArticle 3 – paragraph 2 – subparagraph 1 a (new): This Regulation shall enhance the operational cooperation between Member States, with the support of ENISA pursuant to Article 7 of Regulation (EU) 2019/881.
Added(9) The financing of actions under this Regulation should be provided for in Regulation (EU) 2021/694, which should remain the relevant basic act for these actions enshrined within the Specific Objective 3 of DEP. Specific conditions for participation concerning each action will be provided for in the relevant work programmes, in line with the applicable provision of Regulation (EU) 2021/694.
RemovedArticle 4 – paragraph 1 – subparagraph 1: In order to be able to participate in the European Cyber Shield, each Member State shall designate at least one National SOC. The National SOC shall be a public body.
Added(9a) In light of geopolitical developments and the growing cyber threat landscape (EPP 52) and in order to ensure continuity and further development of the measures laid down in this Regulation beyond 2027, particularly the European Cyber Shield and the Cybersecurity Emergency Mechanism, it is necessary to ensure a specific budget line in the multiannual financial framework for the period 2028-2034. Member States should endevour to commit themselves to supporting all necessary measures to reduce cyber threats and incidents throughout the Union and to strengthen solidarity.
RemovedArticle 6 – paragraph 3: 3. To encourage exchange of information between Cross-border SOCs, Cross-border SOCs shall ensure a high level of interoperability between themselves. To facilitate the interoperability between the Cross-border SOCs, the joint procurement of cyber infrastructures, services and tools shall be encouraged. Moreover, after consulting the ECCC and ENISA, the Commission is empowered to adopt delegated acts in accordance with Article 20a to supplement this Regulation, byspecifying the conditions for this interoperability.
Added(10) Horizontal financial rules adopted by the European Parliament and by the Council on the basis of Article 322 TFEU apply to this Regulation. Those rules are laid down in Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council and determine in particular the procedure for establishing and implementing the Union budget, and provide for checks on the responsibility of financial actors. Rules adopted on the basis of Article 322 TFEU also include a general regime of conditionality for the protection of the Union budget as established in Regulation (EU, Euratom) 2020/2092 of the European Parliament and of the Council.
RemovedArticle 6 – paragraph 4: 4. Cross-border SOCs shall conclude cooperation agreements with one another, specifying information sharing principles among the cross-border platforms. In the context of a potential or ongoing large-scale cybersecurity incident, information sharing mechanisms shall comply with the relevant provisions under the Directive (EU) 2022/2555.
Added(11) For the purpose of sound financial management, specific rules should be laid down for the carry-over of unused commitment and payment appropriations. While respecting the principle that the Union budget is set annually, this Regulation should, on account of the unpredictable, exceptional and specific nature of the cybersecurity landscape, provide for possibilities to carry over unused funds beyond those set out inRegulation (EU, Euratom) 2018/1046 , thus maximising the Cybersecurity Emergency Mechanism’s capacity to support Member States in countering effectively cyber threats.
RemovedArticle 7 – paragraph 1: 1. Where the Cross-border SOCs obtain information relating to a potential or ongoing large-scale cybersecurity incident, they shall provide relevant information to EU=CyCLONe, the CSIRTs network and the Commission, in view of their respective crisis management roles in accordance with Directive (EU) 2022/2555 without undue delay. This paragraph shall not impose any additional obligations on public or private entities to communicate a potential or ongoing large-scale cybersecurity incident.
Added(11a) The Cybersecurity Emergency Mechanism and the EU Cybersecurity Reserve established in this Regulation are new initiatives and were not envisaged in the establishment of the multiannual financial framework for 2021-2027, and funding for those initiatives is intended to limit the reduction of funding for other priorities in the Digital Europe Programme to the minimum extent possible. The amount of the financial resources dedicated to the EU Cyber Security Reserve should therefore be decreased and it should be primarily drawn from the unallocated margins under the multiannual financial framework ceilings or mobilised through the non-thematic multiannual financial framework special instruments. Any earmarking or reallocation of funds from existing programmes should be kept to an absolute minimum, in order to shield existing programmes, in particular Erasmus+, from negative impact and ensure that those programmes can achieve their set objectives.
RemovedArticle 7 – paragraph 2: 2. The Commission is empowered to adopt delegated acts in accordance with Article 20a to supplement this Regulation by determining the procedural arrangements for the information sharing provided for in paragraphs 1.
Added(12) To more effectively prevent, assess,respond to, and recover from, cyber threats and incidents, it is necessary to develop more comprehensive knowledge about the threats to critical assets and infrastructures on the territory of the Union, including their geographical distribution, interconnection and potential effects in case of cyber-attacks affecting those infrastructures. A proactive approach to identifying, mitigating, and preventing potential cyber threats includes an increased capacity of advanced detection capabilities necessary to stop advanced persistent threats. Threat intelligence is information collected, analysed, and interpreted to understand potential threats and risks. By analysing and correlating vast amounts of data, it uncovers patterns, trends, and indicators of compromise that can reveal malicious activities or vulnerabilities. A network of SOCs should be deployed (‘the European Cyber Shield’), comprising of several interoperating cross-border platforms, each grouping together several National SOCs. That infrastructure should serve national and Union cybersecurity interests and needs, leveraging state of the art technology for advanced data collection and analytics tools, enhancing cyber detection and management capabilities and providing real-time situational awareness. A National SOC refers to a centralised capacity responsible for continuously gathering threat intelligence information and improving the cybersecurity posture of entities under national jurisdiction by preventing, detecting, and analysing cybersecurity threats. That infrastructure should serve to increase detection of cybersecurity threats and incidents and thus complement and support Union entities and networks responsible for crisis management in the Union, notably the EU Cyber Crises Liaison Organisation Network (‘EU-CyCLONe’), as defined in Directive (EU) 2022/2555 of the European Parliament and of the Council.
RemovedArticle 11 – paragraph 1: 1. For the purpose of supporting the coordinated preparedness testing of entities referred to in Article 10(1), point (a), across the Union, the Commission, after consulting the NIS Cooperation Group and ENISA, shall identify the sectors, or sub-sectors, concerned, from the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555 from which entities may be subject to the coordinated preparedness testing, in accordance with the arrangements established for the types of entity in the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555.
Added(13) In order to participate in the Cyber Shield, each Member State should designate a public body at national level tasked with coordinating cyber threat detection activities in that Member State. Member States are encouraged to incorporate the National SOC capacity into their existing cyber structure and governance in order to avoid creating additional governance layers and to align this Regulation with existing legislative act, including Directive (EU) 2022/2555. These National SOCs should act as a reference point and gateway at national level for participation of private and public entities, particularly their National SOCs, in the European Cyber Shield and should ensure that cyber threat information from public and private entities is shared and collected at national level in an effective and streamlined manner. National SOCs should strengthen the cooperation and information sharing between public and private entities to break up currently existing communication silos. In doing so, they may support the creation of data exchange models and should facilitate and encourage the sharing of information in a trusted and secure environment. Close and coordinated cooperation between public and private entities is central to strengthening the Union’s resilience in the cybersecurity sphere.
RemovedIn order to harmonise it with the NIS2 Directive.
Added(14) As part of the European Cyber Shield, a number of Cross-border Cybersecurity Operations Centres (‘Cross-border SOCs’) should be established. These should bring together National SOCs from at least three Member States, so that the benefits of cross-border threat detection and information sharing and management can be fully achieved. The general objective of Cross-border SOCs should be to strengthen capacities to analyse, prevent and detect cybersecurity threats and to support the production of high-quality intelligence including collecting and sharing data and information on possible malicious hacking, newly developed maliciuous threaths and exploits that have not yet deployed in a cyber-incidents, and analysis efforts, on cybersecurity threats, notably through the sharing of data from various sources, public or private, as well as through the sharing and joint use of state-of-the-art tools, and jointly developing detection, analysis and prevention capabilities in a trusted and secure environment with the support of ENISA, in matters related to operational cooperation among Member States. Cross-border SOCs should facilitate and encourage the sharing of information in a trusted and secure environment andshould provide new additional capacity, building upon and complementing existing SOCs and computer incident response teams (‘CSIRTs’) and other relevant actors.
RemovedArticle 12 – paragraph 2: 2. The EU Cybersecurity Reserve shall consist of incident response services from trusted providers selected in accordance with the criteria laid down in Article 16. The Reserve shall include pre-committed services. The services shall be deployable in all Member States and shall contribute to boosting innovation in the Digital Single Market across the Union, bridging the innovation divide and generating the capabilities to make that possible.
Added(15) At national level, the monitoring, detection and analysis of cyber threats is typically ensured by SOCs of public and private entities, in combination with CSIRTs. In addition, CSIRTs exchange information in the context of the CSIRT network, in accordance with Directive (EU) 2022/2555. The Cross-border SOCs should constitute a new capacity that is incorporated into the existing cybersecurity infrastructure, particularly CSIRTs network, by pooling and sharing data on cybersecurity threats from public and private entities, in particular their SOCs, enhancing the value of such data through expert analysis and jointly acquired infrastructures and state of the art tools, and contributing to the Union’s technological sovereignty, its open strategic autonomy, competitiveness and resilience and to the development of a significant cybersecurity ecosystem, including in cooperation with trusted and like-minded international partners. .
RemovedArticle 12 – paragraph 6: 6. The Commission shall entrust the operation and administration of the EU Cybersecurity Reserve, in full or in part, to ENISA, by means of contribution agreements
Added(16) The Cross-border SOCs should act as a central point allowing for a broad pooling of relevant data and cyber threat intelligence, enable the spreading of threat information among a large and diverse set of actors (e.g., Computer Emergency Response Teams (‘CERTs’), CSIRTs, Information Sharing and Analysis Centers (‘ISACs’), operators of critical infrastructures) with a view to facilitating the break-up of currently existing communication siloes. In doing so, Cross-border SOCs could also support the creation of data exchange models across the Union. The information exchanged among participants in a Cross-border SOC could include data from networks and sensors, threat intelligence feeds, indicators of compromise, and contextualised information about incidents, threats and vulnerabilities including collecting and sharing data and information on possible malicious hacking, newly developed maliciuous threaths and exploits that have not yet deployed in a cyber-incidents, and analysis efforts. In addition, Cross-border SOCs should also enter into cooperation agreements with other Cross-border SOCs.
RemovedArticle 12 – paragraph 8: 8. The Commission is empowered to adopt delegated acts in accordance with Article 20a to supplement this Regulation by specifying the types and the number of response services required for the EU Cybersecurity Reserve.
Added(17) Shared situational awareness among relevant authorities is an indispensable prerequisite for Union-wide preparedness and coordination with regards to significant and large-scale cybersecurity incidents. Directive (EU) 2022/2555 establishes the EU–CyCLONe to support the coordinated management of large-scale cybersecurity incidents and crises at operational level and to ensure the regular exchange of relevant information among Member States and Union institutions, bodies and agencies. Recommendation (EU) 2017/1584 on coordinated response to large-scale cybersecurity incidents and crises addresses the role of all relevant actors. Directive (EU) 2022/2555 also recalls the Commission’s responsibilities in the Union Civil Protection Mechanism (‘UCPM’) established by Decision 1313/2013/EU of the European Parliament and of the Council, as well as for providing analytical reports for the Integrated Political Crisis Response Mechanism (‘IPCR’) arrangements under Council Implementing Decision (EU) 2018/1993. Therefore, in situations where Cross-border SOCs obtain information related to a potential or ongoing large-scale cybersecurity incident, they should provide relevant information to EU-CyCLONe, the CSIRTs network and the Commission in accordance with Directive (EU) 2022/2555. In particular, depending on the situation, information to be shared could include technical information, information about the nature and motives of the attacker or potential attacker, and higher-level non-technical information about a potential or ongoing large-scale cybersecurity incident. In this context, due regard should be paid to the need-to-know principle and to the potentially sensitive nature of the information shared.
RemovedArticle 13 – paragraph 7: 7. The Commission is empowered to adopt delegated acts in accordance with Article 20a to supplement this Regulation by specifying further the detailed arrangements for allocating the EU Cybersecurity Reserve support services.
Added(18) Entities participating in the European Cyber Shield should ensure a high-level of interoperability among themselves including, as appropriate, as regards data formats, taxonomy, data handling and data analysis tools, and secure communications channels, a minimum level of application layer security, situational awareness dashboard, and indicators. The adoption of a common taxonomy and the development of a template for situational reports to describe the technical cause and impacts of cybersecurity incidents should take into account the ongoing work on incident notification in the context of the implementation of Directive (EU) 2022/2555.
RemovedArticle 14 – paragraph 2 – point e a (new): (ea) the potential impact of human error that has produced the cybersecurity incident and has increased the risks of data breaches;
Added(19) In order to enable the exchange of data on cybersecurity threats from various sources, on a large-scale basis, in a trusted and secure environment, entities participating in the European Cyber Shield should be equipped with state-of-the-art and highly-secure tools, equipment and infrastructures and skilled personnel. This should make it possible to improve collective detection capacities and timely warnings to authorities and relevant entities, notably by using the latest artificial intelligence and data analytics technologies.
Removede.g. The potential impact of a ransomware attack to a particular infrastructure from the health sector.
Added(20) By collecting, sharing and exchanging data, the European Cyber Shield should enhance the Union’s technological sovereignty, its open strategic autonomy, competitiveness and resilience and an EU significant cybersecurity ecosystem. The pooling of high-quality curated data should also contribute to the development of advanced artificial intelligence and data analytics technologies. Artificial intelligence is the most effective when paired with human analysis. Therefore, a skilled labour force remains essential for pooling high-quality data. It should be facilitated through the connection of the European Cyber Shield with the pan-European High Performance Computing infrastructure established by Council Regulation (EU) 2021/1173.
RemovedArticle 14 – paragraph 4: 4. The agreements referred to in paragraph 3 shall be based on templates prepared by ENISA, after consulting Member States.
Added(21) While the European Cyber Shield is a civilian project, the cyber defence community could benefit from stronger civilian detection and situational awareness capabilities developed for the protection of critical infrastructure. Cross-border SOCs, with the support of the Commission and the European Cybersecurity Competence Centre (‘ECCC’), and in cooperation with the High Representative of the Union for Foreign Affairs and Security Policy (the ‘High Representative’), should gradually develop dedicated access conditions and safeguards protocols and standards to allow for cooperation with the cyber defence community, including vetting and security conditions, respecting the civilian character of institutions and the destination of funding, therefore using the funds available to the defence community.. The development of the European Cyber Shield should be accompanied by a reflection enabling future collaboration with networks and platforms responsible for information sharing in the cyber defence community, in close cooperation with the High Representative and in full respect of rights and freedoms..
RemovedArticle 16 – paragraph 1 – point c: (c) ensure that the EU Cybersecurity Reserve brings EU added value, by contributing to the objectives set out in Article 3 of Regulation (EU) 2021/694, including promoting the development of cybersecurity skills in the EU, with a particular focus on achieving gender balance.
Added(22) Information sharing among participants of the European Cyber Shield should comply with existing legal requirements and in particular Union and national data protection law, as well as the Union rules on competition governing the exchange of information. The recipient of the information should implement, insofar as the processing of personal data is necessary, technical and organisational measures that safeguard the rights and freedoms of data subjects, and destroy the data as soon as they are no longer necessary for the stated purpose and inform the body making the data available that the data have been destroyed.
RemovedArticle 16 – paragraph 2 – point i: (i) the provider shall be able to provide the service in the local language of the Member State(s), connecting their participation to a national or local company, where it can deliver the service, to enhance the trust of their participation;
Added(23) Without prejudice to Article 346 of TFEU, the exchange of information that is confidential pursuant to Union or national law should be limited to that which is relevant and proportionate to the purpose of that exchange. The exchange of such information should preserve the confidentiality of the information and protect the security and commercial interests of the entities concerned, in full respect of trade and business secrets.
RemovedArticle 18 – paragraph 2: 2. To prepare the incident review report referred to in paragraph 1, ENISA shall collaborate all relevant stakeholders, including representatives of Member States, the Commission, other relevant EU institutions, bodies and agencies, managed security services providers in the SOCs and users of cybersecurity services, complemented with guarantees and monitoring that is adequate to ensure that lessons learned and best practices identified are backed by the actors in the industry. Where appropriate, ENISA shall also collaborate with entities affected by significant or large-scale cybersecurity incidents. To support the review, ENISA may also consult other types of stakeholders. Consulted representatives shall disclose any potential conflict of interest.
Added(24) In view of the increasing risks and number of cyber incidents affecting Member States, it is necessary to set up a crisis support instrument to improve the Union’s resilience to significant and large-scale cybersecurity incidents and complement Member States’ actions through emergency financial support for preparedness, response and immediate recovery of essential services. That instrument should enable the rapid and effective deployment of assistance in defined circumstances and under clear conditions and allow for a careful monitoring and evaluation of how resources have been used. Whilst the primary responsibility for preventing, preparing for and responding to cybersecurity incidents and crises lies with the Member States, the Cybersecurity Emergency Mechanism promotes solidarity between Member States in accordance with Article 3(3) of the Treaty on European Union (‘TEU’).
RemovedArticle 18 – paragraph 3 a (new): 3a. The report shall include lessons learned from the peer reviews carried out pursuant to Article 19 of Directive (EU) 2022/2555.
Added(25) The Cybersecurity Emergency Mechanism should provide support to Member States complementing their own measures and resources, and other existing support options in case of response to and immediate recovery from significant and large-scale cybersecurity incidents, such as the services provided by the European Union Agency for Cybersecurity (‘ENISA’) in accordance with its mandate, the coordinated response and the assistance from the CSIRTs network, the mitigation support from the EU-CyCLONe, as well as mutual assistance between Member States including in the context of Article 42(7) of TEU, the PESCO Cyber Rapid Response Teams and Hybrid Rapid Response Teams. It should address the need to ensure that specialised means are available to support preparedness and response to cybersecurity incidents across the Union and in third countries.
RemovedRegulation (EU) 2021/694
Added(26) This instrument is without prejudice to procedures and frameworks to coordinate crisis response at Union level, in particular the UCPM, IPCR, and Directive (EU) 2022/2555. It may contribute to or complement actions implemented in the context of Article 42(7) of TEU or in situations defined in Article 222 of TFEU. The use of this instrument should also be coordinated with the implementation of Cyber Diplomacy Toolbox’s measures, where appropriate.
RemovedArticle 19 – paragraph 1 – point 2 – point b, Article 9 – paragraph 8: 8. By derogation from Article 12(4) of Regulation (EU, Euratom) 2018/1046, unused commitment and payment appropriations for actions in the context of the implementation of the EU Cybersecurity Reserve, pursuing the objectives set out in Article 6(1), point (g) of this Regulation, shall be automatically carried over and may be committed and paid up to 31 December of the following financial year.;
Added(27) Assistance provided under this Regulation should be in support of, and complementary to, the actions taken by Member States at national level. To this end, close cooperation and consultation between the Commission, ENISA and the affected Member State should be ensured. When requesting support under the Cybersecurity Emergency Mechanism, the Member State should provide relevant information justifying the need for support.
RemovedRegulation (EU) 2021/694
Added(28) Directive (EU) 2022/2555 requires Member States to designate or establish one or more cyber crisis management authorities and ensure they have adequate resources to carry out their tasks in an effective and efficient manner. It also requires Member States to identify capabilities, assets and procedures that can be deployed in the case of a crisis as well as to adopt a national large-scale cybersecurity incident and crisis response plan where the objectives of and arrangements for the management of large-scale cybersecurity incidents and crises are set out. Member States are also required to establish one or more CSIRTs tasked with incident handling responsibilities in accordance with a well-defined process and covering at least the sectors, subsectors and types of entities under the scope of that Directive, and to ensure they have adequate resources to carry out effectively their tasks. This Regulation is without prejudice to the Commission’s role in ensuring the compliance by Member States with the obligations of Directive (EU) 2022/2555. The CybersecurityEmergency Mechanism should provide assistance for actions aimed at reinforcing preparedness as well as incident response actions to mitigate the impact of significant and large-scale cybersecurity incidents, to support immediate recovery and/or restore the functioning of essential services.
RemovedArticle 19 – paragraph 1 – point 3, Article 14 – paragraph 2 – subparagraph 1: The Programme may provide funding in any of the forms laid down in the Financial Regulation, including in particular through procurement as a primary form, or grants and prizes. In the context of the Programme, additional resources shall be provided to ENISA in order to carry out its tasks, including funding for research and development and coordinating with national cybersecurity agencies and industry stakeholders. That additional funding shall not jeopardise the achievement of the objectives of the Programme.
Added(29) As part of the preparedness actions, to promote a consistent approach and strengthen security across the Union and its internal market, support should be provided for testing and assessing cybersecurity of entities operating in highly critical sectors identified pursuant to Directive (EU) 2022/2555 in a coordinated manner. For this purpose, the Commission, with the support of ENISA and in cooperation with the NIS Cooperation Group established by Directive (EU) 2022/2555, should regularly identify relevant sectors or subsectors, which should be eligible to receive financial support for coordinated testing at Union level. The sectors or subsectors should be selected from Annex I to Directive (EU) 2022/2555 (‘Sectors of High Criticality’). The coordinated testing exercises should be based on common risk scenarios and methodologies. The selection of sectors and development of risk scenarios should take into account relevant Union-wide risk assessments and risk scenarios, including the need to avoid duplication, such as the risk evaluation and risk scenarios called for in the Council conclusions on the development of the European Union's cyber posture to be conducted by the Commission, the High Representative and the NIS Cooperation Group, in coordination with relevant civilian and military bodies and agencies and established networks, including the EU-CyCLONe, as well as the risk assessment of communications networks and infrastructures requested by the Joint Ministerial Call of Nevers and conducted by the NIS Cooperation Group, with the support of the Commission and ENISA, and in cooperation with the Body of European Regulators for Electronic Communications (BEREC), the coordinated risk assessments to be conducted under Article 22 of Directive (EU) 2022/2555 and digital operational resilience testing as provided for in Regulation (EU) 2022/2554 of the European Parliament and of the Council. The selection of sectors should also take into account the Council Recommendation on a Union-wide coordinated approach to strengthen the resilience of critical infrastructure.
RemovedArticle 20 a (new): Article 20a / Exercise of the delegation / 1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article. / 2. The power to adopt delegated acts referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) shall be conferred on the Commission for a period of … years from … [date of entry into force of the basic legislative act or any other date set by the co-legislators]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the … year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period. / 3. The delegation of power referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force / 4. Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 Apr…
Added(30) In addition, the Cybersecurity Emergency Mechanism should offer support for other preparedness actions and support preparedness in other sectors, not covered by the coordinated testing of entities operating in highly critical sectors. Those actions could include various types of national preparedness activities.
RemovedRegulation (EU) 2021/694
Added(31) The Cybersecurity Emergency Mechanism should also provide support for incident response actions to mitigate the impact of significant and large-scale cybersecurity incidents, to support immediate recovery or restore the functioning of essential services. Where appropriate, it should complement the UCPM to ensure a comprehensive approach to respond to the impacts of cyber incidents on citizens.
RemovedAnnex I – paragraph 1 – point 1, Annex I – Specific Objective 3 – point 4: 4. Support closing the cybersecurity skills gap, with a particular focus on achieving gender balance by, for example, aligning cybersecurity skills programmes, adapting them to specific sectorial needs, including an interdisciplinary and general focus and facilitating access to targeted specialised training to enable all persons and territories, without prejudice to the possibility of benefiting from the opportunities provided by this Regulation.
Added(32) The Cybersecurity Emergency Mechanism should support assistance provided by Member States to a Member State affected by a significant or large-scale cybersecurity incident, including by the CSIRTs network set out in Article 15 of Directive (EU) 2022/2555. Member States providing assistance should be allowed to submit requests to cover costs related to dispatching of expert teams in the framework of mutual assistance. The eligible costs could include travel, accommodation and daily allowance expenses of cybersecurity experts.
Added(33) A Union-level Cybersecurity Reserve should gradually be set up, consisting of services from private providers of managed security services to support response and immediate recovery actions in cases of significant or large-scale cybersecurity incidents. The EU Cybersecurity Reserve should ensure the availability and readiness of services, while reinforcing the Union’s resilience, including the participation of European managed security services providers that are SMEs and ensuring the creation of a cybersecurity ecosystem, in particular microenterprises, SMEs including startups, with investment in research and innovation (R&I) to develop state-of-the-art technologies, such as those relating to cloud and artificial intelligence. Trusted providers, including SMEs, should be able to cooperate with one another to fulfil the criteria above.. The services from the EU Cybersecurity Reserve should serve to support national authorities in providing assistance to affected entities operating in critical or highly critical sectors as a complement to their own actions at national level. Therefore, the Cybersecurity Reserve should incentivize investment in research and innovation to boost the development of these technologies. Where appropriate, common exercises with the trusted providers and potential users of the Cybersecurity Reserve could be conducted to ensure efficient functioning of the Reserve when needed. When requesting support from the EU Cybersecurity Reserve, Member States should specify the support provided to the affected entity at the national level, which should be taken into account when assessing the Member State request. The services from the EU Cybersecurity Reserve may also serve to support Union institutions, bodies, offices and agencies, under similar conditions. The Commission should ensure the involvement of and extensive exchanges with the Member States aiming to avoid duplication with similar initiatives, including within the North Atlantic Treaty Organization (NATO).
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=2 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
year = {2023},
date = {2023-12-08},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=2},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}