Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-752795 → A-9-2023-0426
- From
- ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
- To
- A-9-2023-0426 Plenary report of 8 Dec 2023
- Changes
- Not comparable
- Paragraphs
- +319 added · −52 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 4 of 8: Paragraphs 181–240
AddedNational Security Operations Centres
Added1. In order to be able to participate in the European Cyber Shield, each Member State shall designate at least one National SOC. The National SOC shall be a centralised capacity in a public body. When possible, the National SOCs shall be incorporated into the CSIRTs or other existing cybersecurity infrastructures and governance.
AddedIt shall have the capacity to act as a reference point and gateway to other public and private organisations at national level, particularly their National SOCs, for collecting and analysing information on cybersecurity threats and incidents, and, where relevant, sharing those information with members of the CSIRTs network of that Member State, and contributing to a Cross-border SOC. It shall be equipped with state-of-the-art technologies capable of preventing, detecting, aggregating, and analysing data relevant to cybersecurity threats and incidents.
AddedA National SOC or CSIRT may request telemetry, sensor or logging data of their national critical entities from managed security service providers that provide a service to the critical entity. That data shall be shared in accordance with Union data protection law and with the sole purpose of supporting the National SOC or CSIRT to the detect and prevent cybersecurity threats and incidents.
Added2. Following a call for expression of interest, National SOCs may be selected by the European Cybersecurity Competence Centre (‘ECCC’) to participate in a joint procurement of tools and infrastructures with the ECCC. The ECCC may award grants to the selected National SOCs to fund the operation of those tools and infrastructures. The Union financial contribution shall cover up to 50% of the acquisition costs of the tools and infrastructures, and up to 50% of the operation costs, with the remaining costs to be covered by the Member State. Before launching the procedure for the acquisition of the tools and infrastructures, the ECCC and the National SOC shall conclude a hosting and usage agreement regulating the usage of the tools and infrastructures.
Added3. A National SOC selected pursuant to paragraph 2 shall commit to apply to participate in a Cross-border SOC within two years from the date on which the tools and infrastructures are acquired, or on which it receives grant funding, whichever occurs sooner. If a National SOC is not a participant in a Cross-border SOC by that time, it shall not be eligible for additional Union support under this Regulation.
AddedCross-border Security Operations Centres
Added1. A Hosting Consortium consisting of at least three Member States, represented by National SOCs, committed to working together to coordinate their cyber-detection and threat monitoring activities shall be eligible to participate in actions to establish a Cross-border SOC. A Cross-border SOC shall be designed to detect and analyse cyber threats, prevent incidents and support the production of high-quality intelligence, in particular through the exchange of data from various sources, public and private, as well as through the sharing of state-of-the-art tools and by jointly developing cyber detection, analysis, prevention and protection capabilities in a trusted and secure environment.
Added2. Following a call for expression of interest, a Hosting Consortium may be selected by the ECCC to participate in a joint procurement of tools and infrastructures with the ECCC. The ECCC may award to the Hosting Consortium a grant to fund the operation of the tools and infrastructures. The Union financial contribution shall cover up to 75% of the acquisition costs of the tools and infrastructures, and up to 50% of the operation costs, with the remaining costs to be covered by the Hosting Consortium. Before launching the procedure for the acquisition of the tools and infrastructures, the ECCC and the Hosting Consortium shall conclude a hosting and usage agreement regulating the usage of the tools and infrastructures.
Added2a. By way of derogation from Article 176 of Regulation (EU, Euratom) 2018/1046, entities established in third countries that are not parties to the GPA shall not participate in the joint procurement of tools and infrastructures.
Added3. Members of the Hosting Consortium shall conclude a written consortium agreement which sets out their internal arrangements for implementing the hosting and usage Agreement.
Added4. A Cross-border SOC shall be represented for legal purposes by a National SOC acting as coordinating SOC, or by the Hosing Consortium if it has legal personality. The co-ordinating SOC shall be responsible for compliance with the requirements of the hosting and usage agreement and of this Regulation.
AddedCooperation and information sharing within and between Cross-border SOCs
Added1. Members of a Hosting Consortium shall exchange relevant information among themselves within the Cross-border SOC including information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, threat-actor-specific information, cybersecurity alerts and recommendations regarding the configuration of cybersecurity tools to detect cyber attacks, where such information sharing:
Added(a) improves the exchange of cyber threat intelligence between National and Cross-border SOCs and industry ISACs with the aim to prevent, detect, or mitigate threats;
Added(b) enhances the level of cybersecurity, in particular through raising awareness in relation to cyber threats, limiting or impeding the ability of such threats to spread, supporting a range of defensive capabilities, vulnerability remediation and disclosure, threat detection, containment and prevention techniques, mitigation strategies, or response and recovery stages or promoting collaborative threat research between public and private entities.
Added2. The written consortium agreement referred to in Article 5(3) shall establish:
Added(a) a commitment to share a significant ▌.data referred to in paragraph 1, and the conditions under which that information is to be exchanged;
Added(b) a governance framework incentivising the sharing of information by all participants;
Added(c) targets for contribution to the development of advanced artificial intelligence and data analytics tools.
Added3. To encourage exchange of information among Cross-border SOCs and with industry ISACs, Cross-border SOCs shall ensure a high level of interoperability between themselves and, where possible, with industry ISACs. To facilitate the interoperability between the Cross-border SOCsand with industry ISACs, information sharing standards and protocols may be harmonised with international standards and industry best practices. The joint procurement of cyber infrastructures, services and tools shall also be encouraged. Moreover, after consulting the ECCC and ENISA, the Commission is empowered, by... [six months from the date of entry into force of this Regulation] to adopt delegated acts in accordance with Article 20a to supplement this Regulation, by specifying the conditions for this interoperability in close coordination with the Cross-border SOCs and on the basis of international standards and industry best practices.
Added4. Cross-border SOCs shall conclude cooperation agreements with one another and with, where appropriate, industry ISACs,, specifying information sharing and interoperability principles among the cross-border platforms, taking into consideration existing relevant information sharing mechanisms provided for in Directive (EU) 2022/2555. Where appropriate, Cross-border SOCs shall conclude cooperation agreements with industry ISACs. In the context of a potential or ongoing large-scale cybersecurity incident, information sharing mechanisms shall comply with the relevant provisions of the Directive (EU) 2022/2555.
AddedCooperation and information sharing with the CSIRT network
Added1. Where the Cross-border SOCs obtain information relating to a potential or ongoing large-scale cybersecurity incident for the purpose of shared situation awareness, the coordinating SOC shall provide the relevant information to its CSIRT or competent authority, which will report this to the EU-CyCLONe, the CSIRTs network and the Commission and ENISA, in line withtheir respective crisis management roles and procedures in accordance with Directive (EU) 2022/2555 without undue delay. This paragraph shall not impose further obligations on public or private entities to communicate a potential or ongoing large-scale cybersecurity incident for the fulfilment of the obligations laid down in the Directive (EU) 2022/2555.
Added2. The Commission is empowered to adopt delegated acts in accordance with Article 20a after consulting the CSIRT network to supplement this Regulation by determining the procedural arrangements for the information sharing provided for in paragraphs 1 of this Article and in accordance with Directive (EU) 2022/2555..
AddedSecurity
Added1. Member States participating in the European Cyber Shield shall ensure a high level of confidentiality and data security and physical security of the European Cyber Shield infrastructure, and shall ensure that the infrastructure shall be adequately managed and controlled in such a way as to protect it from threats and to ensure its security and that of the systems, including that of data exchanged through the infrastructure.
Added2. Member States participating in the European Cyber Shield shall ensure that the sharing of information within the European Cyber Shield with entities which are not Member State public bodies does not negatively affect the security interests of the Union.
Added3. The Commission may adopt implementing acts laying down technical requirements for Member States to comply with their obligation under paragraph 1 and 2. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 21(2) of this Regulation. They shall comply with Directives (EU) 2022/2555 and (EU) 2022/2557 . In its implementing acts, the Commission, supported by the High Representative, shall take into account relevant defence-level security standards, in order to facilitate cooperation with military actors.
AddedCYBERSECURITY EMERGENCY MECHANISM
AddedEstablishment of the Cybersecurity Emergency Mechanism
Added1. A Cybersecurity Emergency Mechanism is established to improve the Union’s resilience to major cybersecurity threats and prepare for and mitigate, in a spirit of solidarity, the short-term impact of significant and large-scale cybersecurity incidents (the ‘Mechanism’).
Added2. Actions implementing the ▌Mechanism shall be supported by funding from DEP and implemented in accordance with Regulation (EU) 2021/694 and in particular Specific Objective 3 thereof.
AddedType of actions
Added1. The Mechanism shall support the following types of actions:
Added(a) preparedness actions, including the coordinated preparedness testing of entities operating in highly critical sectors across the Union;
Added(b) response actions, supporting response to and immediate recovery from significant and large-scale cybersecurity incidents, to be provided by trusted managed security service providers participating in the EU Cybersecurity Reserve established under Article 12;
Added(c) mutual assistance actions consisting of the provision of assistance from national authorities of one Member State to another Member State, in particular as provided for in Article 11(3), point (f), of Directive (EU) 2022/2555.
Added1a. Following the triggering of the Mechanism, the Commission shall, on an annual basis, assess and publish a report on both the positive and the negative working of the Mechanism, including whether further cooperation or training requirements are needed.
AddedCoordinated preparedness testing of entities
Added1. For the purpose of supporting the coordinated preparedness testing of entities referred to in Article 10(1), point (a), across the Union, the Commission, after consulting the NIS Cooperation Group and ENISA, shall identify the sectors, or sub-sectors, concerned, from the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555 from which entities may be subject to the coordinated preparedness testing, taking into account existing and planned coordinated risk assessments and resilience testing in accordance with the arrangements established for the entities in the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555.
Added2. The NIS Cooperation Group in cooperation with the Commission, ENISA, and the High Representative, and the entities that are subject to coordinated preparedness testing pursuant to paragraph 1, shall develop common risk scenarios and methodologies for the coordinated preparedness testing exercises, culminating in a concerted workplan. Entities subject to coordinated preparedness testing shall develop and implement a remediation plan that carries out the recommendations resulting from preparedness tests.
AddedThe NIS Cooperation Group may inform the prioritisation of sectors, or sub-sectors for the coordinated preparedness testing exercises.
AddedEstablishment of the EU Cybersecurity Reserve
Added1. An EU Cybersecurity Reserve shall be established, in order to assist users referred to in paragraph 3, in responding or providing support for responding to significant or large-scale cybersecurity incidents, and immediate recovery from such incidents.
AddedWhere it is apparent that the procured services cannot be fully used for the purposes of providing support for responding to significant or large-scale incidents, those services can exceptionally be converted to excercises or trainings for dealing with incidents, and provided to the users upon request, by the contracting authority.
Added2. The EU Cybersecurity Reserve shall consist of incident response services from trusted managed security service providers selected in accordance with the criteria laid down in Article 16. The EU Cybersecurity reserve shall include pre-committed services. The services shall be deployable in all Member States, shall reinforce the Union’s technological sovereignty, its open strategic autonomy, competitiveness and resilience in the cyber security sector including by boosting innovation in the Digital Single Market across the Union.
Added3. Users of the services from the EU Cybersecurity Reserve shall include:
Added(a) Member States’ cyber crisis management authorities and CSIRTs as referred to in Article 9 (1) and (2) and Article 10 of Directive (EU) 2022/2555, respectively;
Added(b) Union institutions, bodies and agencies as referred to in Article 3 (1) of the Regulation (EU) .../2023 of the European Parliament and of the Council and CERT-EU.
Added4. Users referred to in paragraph 3, point (a), shall use the services from the EU Cybersecurity Reserve in order to respond or support response to and immediate recovery from significant or large-scale incidents affecting entities operating in critical or highly critical sectors.
Added5. The Commission shall have overall responsibility for the implementation of the EU Cybersecurity Reserve. The Commission shall determine the priorities and evolution of the EU Cybersecurity Reserve in coordination with the NIS2 Coordination Group and, in line with the requirements of the users referred to in paragraph 3, and shall supervise its implementation, and ensure complementarity, consistency, synergies and links with other support actions under this Regulation as well as other Union actions and programmes.
Added6. The Commission shall entrust the operation and administration of the EU Cybersecurity Reserve, in full or in part, to ENISA, by means of contribution agreements.
Added7. In order to support the Commission in establishing the EU Cybersecurity Reserve, ENISA shall prepare a mapping of the services needed, including the needed skills and capacity of the cybersecurity workforce, after consulting Member States and the Commission, and where appropriate, managed security services providers, and other cybersecurity industry representatives. ENISA shall prepare a similar mapping, after consulting the Commission, managed security services providers, and where appropriate, other cybersecurity industry representatives to identify the needs of third countries eligible for support from the EU Cybersecurity Reserve pursuant to Article 17. The Commission, where relevant, shall consult the High Representative and inform the Council about the needs of third countries.
Added8. The Commission is empowered to adopt delegated acts, in accordance with Article 20a to supplement this Regulation by specifying the types and the number of response services required for the EU Cybersecurity Reserve. ▌..
AddedRequests for support from the EU Cybersecurity Reserve
Added1. The users referred to in Article 12(3) may request services from the EU Cybersecurity Reserve to support response to and immediate recovery from significant or large-scale cybersecurity incidents.
Added2. To receive support from the EU Cybersecurity Reserve, the users referred to in Article 12(3) shall take measures to mitigate the effects of the incident for which the support is requested, including the provision of direct technical assistance, and other resources to assist the response to the incident, and immediate recovery efforts.
Added3. Requests for support from users referred to in Article 12(3), point (a), of this Regulation shall be transmitted to the Commission and ENISA via the Single Point of Contact designated or established by the Member State in accordance with Article 8(3) of Directive (EU) 2022/2555.
Added4. Member States shall inform the CSIRTs network, and where appropriate EU-CyCLONe, about their requests for incident response and immediate recovery support pursuant to this Article.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=4
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=4 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
year = {2023},
date = {2023-12-08},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=4}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=4},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}