Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-752795 → A-9-2023-0426

From
ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
To
A-9-2023-0426 Plenary report of 8 Dec 2023
Changes
Not comparable
Paragraphs
+319 added · −52 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 3 of 8: Paragraphs 121–180

Added(34) For the purpose of selecting private service providers to provide services in the context of the EU Cybersecurity Reserve, it is necessary to establish a set of minimum criteria that should be included in the call for tenders to select these providers, so as to ensure that the needs of Member States’ authorities and entities operating in critical or highly critical sectors are met. The participation of smaller providers, active at regional and local level should be encouraged.

Added(35) To support the establishment of the EU Cybersecurity Reserve, the Commission could consider requesting ENISA to prepare a candidate certification scheme pursuant to Regulation (EU) 2019/881 for managed security services in the areas covered by the Cybersecurity Emergency Mechanism. In order to fulfil the additional tasks deriving from this provision, ENISA should receive adequate, additional funding.

Added(36) In order to support the objectives of this Regulation of promoting shared situational awareness, enhancing Union’s resilience and enabling effective response to significant and large-scale cybersecurity incidents, the EU=CyCLONe, the CSIRTs network or the Commission should be able to ask ENISA to review and assess threats, vulnerabilities and mitigation actions with respect to a specific significant or large-scale cybersecurity incident. After the completion of a review and assessment of an incident, ENISA should prepare an incident review report, in collaboration with relevant stakeholders, including representatives from the private sector, Member States, the Commission and other relevant EU institutions, bodies, offices and agencies. As regards the private sector, ENISA is developing channels for exchanging information with specialised providers, including providers of managed security solutions and vendors, in order to contribute to ENISA’s mission of achieving a high common level of cybersecurity across the Union. Building on the collaboration with stakeholders, including the private sector, the review report on specific incidents should aim at assessing the causes, impacts and mitigations of an incident, after it has occurred. Particular attention should be paid to the input and lessons shared by the managed security service providers that fulfil the conditions of highest professional integrity, impartiality and requisite technical expertise as required by this Regulation. The report should be delivered and feed into the work of the EU=CyCLONe, the CSIRTs network and the Commission. When the incident relates to a third country, it will also be shared by the Commission with the High Representative.

Added(37) Taking into account the unpredictable nature of cybersecurity attacks and the fact that they are often not contained in a specific geographical area and pose high risk of spill-over, the strengthening of resilience of neighbouring countries and their capacity to respond effectively to significant and large-scale cybersecurity incidents contributes to the protection of the Union as a whole. Therefore, third countries associated to the DEP may be supported from the EU Cybersecurity Reserve, where this is provided for in the respective association agreement to DEP. The funding for associated third countries should be supported by the Union in the framework of relevant partnerships and funding instruments for those countries. The support should cover services in the area of response to and immediate recovery from significant or large-scale cybersecurity incidents. The conditions set for the EU Cybersecurity Reserve and trusted providers in this Regulation should apply when providing support to the third countries associated to DEP.

Added(37a) Third countries could access resources and support pursuant to this Regulation, using the incident response support from the EU Cybersecurity Reserve. Furthermore, incident response service providers from third countries, including third countries associated to the Digital Europe Programme or other international partner countries, and NATO members, may be needed for the provision of specific services in the EU Cybersecurity Reserve. By way of derogation from Regulation (EU, Euratom) 2018/1046, in order to strengthen the Union’s technological sovereignty, its open strategic autonomy, competitiveness and resilience, and to safeguard the Union’s strategic assets, interests, or security, entities established in third countries that are not party to the GPA and that have not been subject to screening within the meaning of Regulation (EU) 2019/452 of the European Parliament and of the Council and, where necessary, to mitigation measures, taking into account the objectives set out in this Regulation, should not be allowed to participate. The external dimension of this Regulation should be in line with the provisions established in the Association Agreement under the Digital Europe Programme. The participation of third countries should be subject to public scrutiny, with the participation of the legislative powers, to ensure that citizens can participate in the process.

Added(38) In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission to specify the conditions for the interoperability between Cross-border SOCs; determine the procedural arrangements for the information sharing related to a potential or ongoing large-scale cybersecurity incident between Cross-border SOCs and Union entities; laying down technical requirements to ensure security of the European Cyber Shield; specify the types and the number of response services required for the EU Cybersecurity Reserve; and, specify further the detailed arrangements for allocating the EU Cybersecurity Reserve support services. Those powers should be exercised in accordance with Regulation (EU) 182/2011 of the European Parliament and of the Council*.

Added________________

Added* Regulation (EU) No 182/2011 of the European Parliament and of the Council of 16 February 2011 laying down the rules and general principles concerning mechanisms for control by the Member States of the Commission's exercise of implementing powers (OJ L 55, 28.2.2011, p. 13, ELI: http://data.europa.eu/eli/reg/2011/182/oj).

Added(38a) Skilled personnel, that is able to reliably deliver the relevant cybersecurity services at highest standards, is imperative for the effective implementation of the European Cyber Shield and the Cybersecurity Emergency Mechanism. It is therefore concerning that the Union is faced with a talent gap, characterised by a shortage of skilled professionals, while facing a rapidly evolving threat landscape as acknowledged in the Commission communication of 18 April 2023 on the Cyber Skills Academy. It is important to bridge this talent gap by strengthening cooperation and coordination among the different stakeholders, including the private sector, academia, Member States, the Commission and ENISA to scale up and create synergies, in all territories, for the investment in education and training, the development of public-private partnerships, support of research and innovation initiatives, the development and mutual recognition of common standards and certification of cybersecurity skills, including through the European Cyber Security Skills Framework. This should also facilitate the mobility of cybersecurity professionals within the Union. This Regulation should aim to promote a more diverse cybersecurity workforce. All measures aiming to increase cybersecurity skills requires safeguards to avoid a ‘brain drain’ and a risk to labour mobility.

Added(38b) The reinforcement of specialised, interdisciplinary and general skills and competences across the Union is needed, with a special focus on women, as the gender gap persists in cybersecurity with women comprising 20 % of the average worldwide presence. Women must be present and part of the design of the digital future and its governance.

Added(38c) Strengthening research and innovation (R&I) in cybersecurity is intended to increase the resilience and the open strategic autonomy of the Union. Similarly, it is important to create synergies with R&I programmes and with existing instruments and institutions and to strengthen cooperation and coordination among the different stakeholders, including the private sector, civil society, academia, Member States, the Commission and ENISA;

Added(38d) This Regulation should contribute to the commitment of the European Declaration on Digital Rights and Principles for the Digital Decade linked to protect the interests of our democracies, people, businesses and public institutions against cybersecurity risks and cybercrime including data breaches and identity theft or manipulation. The application of this Regulation should also contribute to improving the implementation of other legislation, for example on artificial intelligence, data privacy and data regulation in terms of cybersecurity and cyber resilience.

Added(38e) Increasing cybersecurity culture which comprehends security, including that of the digital environment, as a public good will be key for the successful implementation of this Regulation. Therefore, developing measures to include and increase citizens’ awareness should be another means of guaranteeing the safeguard of our democracies and fundamental values.

Added(38f) In order to supplement certain non-essential elements of this Regulation, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to specify the conditions for interoperability between the Cross-border SOCs, establish the procedural arrangements for the information sharing between the Cross-border SOCs on the one hand and EU-CyCLONe, the CSIRTs network and the Commission on the other, specify the types and number of response services required for the EU Cybersecurity Reserve, and specify further the detailed arrangements for allocating the EU Cyersecurity Reserve support services. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making*. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

Added___________________

Added*OJ L 123, 12.5.2016, p. 1, ELI: http://data.europa.eu/eli/agree_interinstit/2016/512/oj.

Added(39) Since the objectives of this Regulation, namely to reinforce the Union’s cyber threat prevention, detection, response and recover capacities and to establish a general framework breaking up communication silo cannot be sufficiently achieved by the Member States but can rather be better achieved at Union level. Hence, the Union may adopt measures, in accordance with the principles of subsidiarity and proportionality as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective,

AddedHAVE ADOPTED THIS REGULATION:

AddedGENERAL OBJECTIVES, SUBJECT MATTER, AND DEFINITIONS

AddedSubject-matter and objectives

Added1. This Regulation lays down measures to strengthen capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents, in particular through the following actions:

Added(a) the deployment of a pan-European network of Security Operations Centres (‘European Cyber Shield’) to build and enhance common detection and situational awareness capabilities;

Added(b) the creation of a Cybersecurity Emergency Mechanism to support Member States in preparing for, responding to, and immediate recovery from significant and large-scale cybersecurity incidents;

Added(c) the establishment of a European Cybersecurity Incident Review Mechanism to review and assess significant or large-scale incidents.

Added2. This Regulation pursues the objective to strengthen solidarity at Union level through following specific objectives:

Added(a) to strengthen common Union detection and situational awareness of cyber threats and incidents thus allowing support for the industrial capacity of the Union and the Member States in the cybersecurity sector, and to reinforce the competitive position of industry, in particular microenterprises, SMEs including startups, and services sectors in the Union across the digital economy and to contribute to the Union’s technological sovereignty its open strategic autonomy, competitiveness and and resilience in that sector, strengthening the cybersecurity ecosystem with a view to ensuring strong Union capabilities, including in cooperation with international partners;

Added(b) to reinforce preparedness of entities operating in critical and highly critical sectors across the Union and strengthen solidarity by developing common response capacities against significant or large-scale cybersecurity incidents, including by making Union cybersecurity incident response support available for third countries associated to the Digital Europe Programme (‘DEP’);

Added(c) to enhance Union resilience and contribute to effective response by reviewing and assessing significant or large-scale incidents, including drawing lessons learned and, where appropriate, recommendations.

Added(ca) to develop, in a coordinated manner, skills, knowhow abilities and competencies of the workforce, with a view to ensuring cybersecurity and creating synergies with the Cybersecurity Skills Academy.

Added3. This Regulation is without prejudice to the Member States’ primary responsibility for national security, public security, and the prevention, investigation, detection and prosecution of criminal offences.

AddedDefinitions

AddedFor the purposes of this Regulation, the following definitions apply:

Added(-1a) ‘National Security Operations Centre’ or ‘National SOC’ means a centralised national capacity continuously gathering and analysing cyber threat intelligence information and improving the cybersecurity posture in accordance with Article 4;

Added(1) ‘Cross-border Security Operations Centre’ or ‘ Cross-border SOC’ means a multi-country platform, that brings together in a coordinated network structure national SOCs in accordance with Article 5;

Added(2) ‘public body’ means bodiesgoverned by public law as defined in Article 2(1), point (4)), of Directive 2014/24/EU of the European Parliament and the Council;

Added(3) ‘Hosting Consortium’ means a consortium composed of participating states, represented by National SOCs, in accordance with Article 5.;

Added(4) ‘entity’ means an entity as defined in Article 6, point (38), of Directive (EU) 2022/2555;

Added(4a) ‘critical entity’ means critical entity as defined in Article 2, point (1), of Directive (EU) 2022/2557 of the European Parliament and of the Council.

Added(5) ‘entities operating in critical or highly critical sectors’ means entities in the sectors listed in Annexes I and ▌II to Directive (EU) 2022/2555;

Added(5a) ‘incident handling’ means incident handling as defined in Article 6, point (8), of Directive (EU) 2022/2555;

Added(5b) ‘risk’ means risk as defined in Article 6, point (9), of Directive (EU) 2022/2555;

Added(6) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;

Added(6a) ‘significant cyber threat’ means a significant cyber threat as defined in Article 6, point (11), of Directive (EU) 2022/2555;

Added(7) ‘significant cybersecurity incident’ means a cybersecurity incident fulfilling criteria set out in Article 23(3) of Directive (EU) 2022/2555;

Added(8) ‘large-scale cybersecurity incident’ means an incident as defined in Article 6, point (7), of Directive (EU)2022/2555;

Added(9) ‘preparedness’ means a state of readiness and capability to ensure an effective rapid response to a significant or large-scale cybersecurity incident, obtained as a result of risk assessment and monitoring actions taken in advance;

Added(10) ‘response’ means action in the event of a significant or large-scale cybersecurity incident, or during or after such an incident, to address its immediate and short-term adverse consequences;

Added(10a) ‘managed security service provider’ means a managed service provider as defined in Article 6, point (40), of Directive (EU) 2022/2555;

Added(11) ‘trusted managed securiy service providers’ means managed security service providers selected to be included in the EU Cybersecurity Reserve in accordance with Article 16 of this Regulation.

AddedTHE EUROPEAN CYBER SHIELD

AddedEstablishment of the European Cyber Shield

Added1. A network of Security Operations Centres (‘European Cyber Shield’) shall be established to develop advanced capabilities for the Union to detect, analyse and process data on cyber threats and prevent incidents in the Union. It shall consist of all National Security Operations Centres (‘National SOCs’) and Cross-border Security Operations Centres (‘Cross-border SOCs’).

AddedActions implementing the European Cyber Shield shall be supported by funding from the Digital Europe Programme and implemented in accordance with Regulation (EU) 2021/694 and in particular Specific Objective 3 thereof.

Added2. The European Cyber Shield shall:

Added(a) pool and share data on cyber threats and incidents from various sources through Cross-border SOCs and where relevant exchange of information with CSIRTs Network;

Added(b) produce high-quality, actionable information and cyber threat intelligence, through the use of state-of-the art tools, notably Artificial Intelligence and data analytics technologies;

Added(c) contribute to better protection and response to cyber threats, including by providing concrete recommendations to entities;

Added(d) contribute to faster detection of cyber threats and situational awareness across the Union;

Added(e) provide services and activities for the cybersecurity community in the Union, including contributing to the development of advanced artificial intelligence and data analytics tools.

AddedIt shall be developed in cooperation with the pan-European High Performance Computing infrastructure established pursuant to Regulation (EU) 2021/1173.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=3 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
  year = {2023},
  date = {2023-12-08},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=3}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=3},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}