Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-752795 → A-9-2023-0426
- From
- ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
- To
- A-9-2023-0426 Plenary report of 8 Dec 2023
- Changes
- Not comparable
- Paragraphs
- +319 added · −52 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 5 of 8: Paragraphs 241–300
Added5. Requests for incident response and immediate recovery support shall include:
Added(a) appropriate information regarding the affected entity and potential impacts of the incident and the planned use of the requested support, including an indication of the estimated needs;
Added(b) information about measures taken to mitigate the incident for which the support is requested, as referred to in paragraph 2;
Added(c) information about other forms of support available to the affected entity, including contractual arrangements in place for incident response and immediate recovery services, as well as insurance contracts potentially covering such type of incident.
Added6. ENISA, in cooperation with the Commission and the NIS Cooperation Group, shall develop a template to facilitate the submission of requests for support from the EU Cybersecurity Reserve.
Added7. The Commission is empowered to adopt delegated acts, in accordance with Article 20a to supplement this Regulation by specifying further the detailed arrangements for allocating the EU Cybersecurity Reserve support services. ▌
AddedImplementation of the support from the EU Cybersecurity Reserve
Added1. Requests for support from the EU Cybersecurity Reserve, shall be assessed by the Commission, with the support of ENISA or as defined in contribution agreements under Article 12(6), and a response shall be transmitted to the users referred to in Article 12(3) without undue delay and in any event within 24 hours.
Added2. To prioritise requests, in the case of multiple concurrent requests, the following criteria shall be taken into account, where relevant:
Added(a) the severity of the cybersecurity incident;
Added(b) the type of entity affected, with higher priority given to incidents affecting essential entities as defined in Article 3(1) of Directive (EU) 2022/2555;
Added(c) the potential impact on the affected Member State(s) or users;
Added(d) the scale and potential cross-border nature of the incident and the risk of spill over to other Member States or users;
Added(e) the measures taken by the user to assist the response, and immediate recovery efforts, as referred in Article 13(2) and Article 13(5), point (b).
Added3. The EU Cybersecurity Reserve services shall be provided in accordance with specific agreements between the service provider and the user to which the support under the EU Cybersecurity Reserve is provided. Those agreements shall include liability conditions and any other provisions the parties to the agreement deem necessary for the provision of the respective service.
Added4. The agreements referred to in paragraph 3 shall be based on templates prepared by ENISA, after consulting Member States and, where appropriate, other users of the EU Cybersecurity Reserve.
Added5. The Commission and ENISA shall bear no contractual liability for damages caused to third parties by the services provided in the framework of the implementation of the EU Cybersecurity Reserve, except in cases of gross negligence in the evaluation of the application of the service provider or in case where the Commission or ENISA are users of the EU Cybersecurity Reserve according to Article 14 (3).
Added6. Within one month from the end of the support action, the users shall provide Commission and ENISA CSIRTs Network and, where relevant, EU-CyCLONe with a summary report about the service provided, results achieved and the lessons learned. When the user is from a third country as set out in Article 17, such report shall be shared with the High Representative.
AddedThe report shall respect Union and national law concerning the protection of sensitive or classified information.
Added7. The Commission shall report on a regular basis and at least twice a year to the NIS Cooperation Group about the use and the results of the support. It shall protect confidential information, in accordance with Union and national law concerning the protection of sensitive or classified information.
AddedCoordination with crisis management mechanisms
Added1. In cases where significant or large-scale cybersecurity incidents originate from or result in disasters as defined in Decision 1313/2013/EU, the support under this Regulation for responding to such incidents shall complementactions under and without prejudice to Decision 1313/2013/EU.
Added2. In the event of a large-scale, cross border cybersecurity incident where Integrated Political Crisis Response arrangements (IPCR) are triggered, the support under this Regulation for responding to such incident shall be handled in accordance with relevant protocols and procedures under the IPCR.
Added3. In consultation with the High Representative, support under theCybersecurity Emergency Mechanism may complement assistance provided in the context of the Common Foreign and Security Policy and Common Security and Defence Policy, including through the Cyber Rapid Response Teams. It may also complement or contribute to assistance provided by one Member State to another Member State in the context of Article 42(7) TFEU.
Added4. Support under the Cybersecurity Emergency Mechanism may form part of the joint response between the Union and Member States in situations referred to in Article 222 TFEU
AddedTrusted providers
Added1. In procurement procedures for the purpose of establishing the EU Cybersecurity Reserve, the contracting authority shall act in accordance with the principles laid down in the Regulation (EU, Euratom) 2018/1046 and in accordance with the following principles:
Added(a) ensure the EU Cybersecurity Reserve includes services that may be deployed in all Member States, taking into account in particular national requirements for the provision of such services, including certification or accreditation;
Added(b) ensure the protection of the essential security interests of the Union and its Member States.
Added(c) ensure that the EU Cybersecurity Reserve brings EU added value, by contributing to the objectives set out in Article 3 of Regulation (EU) 2021/694, including promoting the development of cybersecurity skills in the EU, and the achievement of gender balance in the sector, and reinforcing the Union’s technological sovereignty, open strategic autonomy, competitiveness and resilience.
Added2. When procuring services for the EU Cybersecurity Reserve, the contracting authority shall include in the procurement documents the following selection criteria:
Added(a) the provider shall demonstrate that its personnel has the highest degree of professional integrity, independence, responsibility, and the requisite technical competence to perform the activities in their specific field, and ensures the permanence/continuity of expertise as well as the required technical resources;
Added(b) the provider, its subsidiaries and subcontractors shall have in place a framework to protect sensitive information relating to the service, and in particular evidence, findings and reports, and is compliant with Union security rules on the protection of EU classified information;
Added(c) the provider shall provide sufficient proof that its governing structure is transparent, not likely to compromise its impartiality and the quality of its services or to cause conflicts of interest;
Added(d) the provider shall have appropriate security clearance, at least for personnel intended for service deployment;
Added(e) the provider shall have the relevant level of security for its IT systems;
Added(f) the provider shall be equipped with up to date the hardware and software technical equipment necessary to support the requested service and shall, as applicable, comply with Regulation (EU) .../... of the European Parliament and of the Council (2022/0272(COD));
Added(g) the provider shall be able to demonstrate that it has experience in delivering similar services to relevant national authorities or entities operating in critical or highly critical sectors;
Added(h) the provider shall be able to provide the service within a short timeframe in the Member State(s) where it can deliver the service;
Added(i) the provider shall be able to provide the service in the local language of the Member State(s), or in one of the working languages of the Union’s institutions, where it can deliver the service;
Added(j) once an European cybersecurity certification scheme for managed security service pursuant to Regulation (EU) 2019/881 is in place, the provider shall be certified in accordance with that scheme within a period of two years after the scheme has been adopted.
Added(ja) the provider shall be able to provide the service independently and not as part of a bundle, thus safeguarding the user possibility to switch to another service provider;
Added(jb) for the purposes of Article 12(1) the provider shall include in the tenders proposal the possibility for conversion of unused incident response services into exercises or trainings;
Added(jc) the provider shall be established and shall have its executive management structures in the Union, in an associated country or in a third country that is part to the Government Procurement Agreement in the context of World Trade Organisation(GPA).
Added(jd) . The provider shall not be subject to control by a non-associated third country or by a non-associated third-country entity that is not party to the GPA or, alternatively, such an entity shall have been subject to screening within the meaning of Regulation (EU) 2019/452 and, where necessary, to mitigation measures, taking into account the objectives set out in this Regulation.
AddedSupport to third countries
Added1. Third countries may request support from the EU Cybersecurity Reserve where Association Agreements concluded regarding their participation in DEP provide for this.
Added2. Support from the EU Cybersecurity Reserve shall be in accordance with this Regulation, and shall comply with any specific conditions laid down in the Association Agreements referred to in paragraph 1.
Added3. Users from associated third countries eligible to receive services from the EU Cybersecurity Reserve shall include competent authorities such as CSIRTs and cyber crisis management authorities.
Added4. Each third country eligible for support from the EU Cybersecurity Reserve shall designate an authority to act as a single point of contact for the purpose of this Regulation.
Added5. Prior to receiving any support from the EU Cybersecurity Reserve, third countries shall provide to the Commission and the High Representative information about their cyber resilience and risk management capabilities, including at least information on national measures taken to prepare for significant or large-scale cybersecurity incidents, as well as information on responsible national entities, including CSIRTs or equivalent entities, their capabilities and the resources allocated to them. Where provisions of Articles 13 and 14 of this Regulation refer to Member States, they shall apply to third countries as set out in paragraph 1.
Added6. The Commission shall without undue delay notify the Council and coordinate with the High Representative about the requests received and the implementation of the support granted to third countries from the EU Cybersecurity Reserve.
AddedCYBERSECURITY INCIDENT REVIEW MECHANISM
AddedCybersecurity Incident Review Mechanism
Added1. At the request of the Commission, the EU-CyCLONe or the CSIRTs network, ENISA shall review and assess threats, vulnerabilities and mitigation actions with respect to a specific significant or large-scale cybersecurity incident. Following the completion of a review and assessment of an incident, ENISA shall deliver an incident review report to the CSIRTs network, the EU-CyCLONe and the Commission to support them in carrying out their tasks, in particular in view of those set out in Articles 15 and 16 of Directive (EU) 2022/2555. Where relevant, the Commission shall share the report with the High Representative.
Added2. To prepare the incident review report referred to in paragraph 1, ENISA shall collaborate with and gather feedback from all relevant stakeholders, including representatives of Member States, the Commission, other relevant EU institutions, bodies, offices and agencies, managed security services providers in the National and Cross-border SOCs and users of cybersecurity services, complemented with guarantees and monitoring that is adequate to ensure that lessons learned and best practicies identified are backed by the actors in the cybersecurity services industry. Where appropriate, ENISA shall also collaborate with entities affected by significant or large-scale cybersecurity incidents. To support the review, ENISA may also consult other types of stakeholders. Consulted representatives shall disclose any potential conflict of interest.
Added3. The report shall cover a review and analysis of the specific significant or large-scale cybersecurity incident, including the main causes, vulnerabilities and lessons learned. It shall protect confidential information, in accordance with Union or national law concerning the protection of sensitive or classified information. It shall not include any details about actively exploited vulnerabilities that remain unpatched.
Added3a. The report referred to in paragraph 1 of this Article shall set out lessons learned from the peer reviews carried out pursuant to Article 19 of Directive (EU) 2022/2555.
Added4. Where appropriate, the report shall draw recommendations, including for all relevant stakeholders, to improve the Union’s cyber posture.
Added5. Where possible, a version of the report shall be made available publicly. This version shall only include public information.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=5
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 30 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=5 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
year = {2023},
date = {2023-12-08},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=5}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=5},
urldate = {2026-09-30},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}