Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-752795 → A-9-2023-0426

From
ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
To
A-9-2023-0426 Plenary report of 8 Dec 2023
Changes
Not comparable
Paragraphs
+319 added · −52 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 6 of 8: Paragraphs 301–360

AddedFINAL PROVISIONS

AddedAmendments to Regulation (EU) 2021/694

AddedRegulation (EU) 2021/694 is amended as follows:

Added(1) Article 6 is amended as follows:

Added(a) paragraph 1 is amended as follows:

Added(i) the following point (aa) is inserted:

Added‘(aa) support the development of an EU Cyber Shield, including the development, deployment and operation of National and Cross-border SOCs platforms that contribute to situational awareness in the Union and to enhancing the cyber threat intelligence capacities of the Union’;

Added(ii) the following point (g) is added:

Added‘(g) establish and operate a Cybersecurity Emergency Mechanism to support Member States in preparing for and responding to significant cybersecurity incidents, complementary to national resources and capabilities and other forms of support available at Union level, including the establishment of an EU Cybersecurity Reserve’;

Added(b) Paragraph 2 is replaced by the following:

Added‘2. The actions under Specific Objective 3 shall be implemented primarily through the European Cybersecurity Industrial, technology and research Competence Centre and the Network of National Coordination Centres, in accordance with Regulation (EU) 2021/887 of the European Parliament and of the Council*with the exception of actions implementing the EU Cybersecurity Reserve, which shall be implemented by the Commission and ENISA.

Added_______________

Added* Regulation (EU) 2021/887 of the European Parliament and of the Council of 20 May 2021 establishing the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres, (OJ L 202, 8.6.2021, p. 1, ELI: http://data.europa.eu/eli/reg/2021/887/oj).’;

Added(2) Article 9 is amended as follows:

Added(a) in paragraph 2, points (b), (c) and (d) are replaced by the following:

Added‘(b), EUR 1 776 956 000 for Specific Objective 2 – Artificial Intelligence;

Added(c), EUR 1 620 566 000 for Specific Objective 3 – Cybersecurity and Trust;

Added(d), EUR 500 347 000 for Specific Objective 4 – Advanced Digital Skills’;

Added(aa) the following new paragraph 2a is inserted:

Added‘ (2a). The amount referred to in paragraph 2 point c shall primarily be used for achieving the operational objectives referred into art. 6 par. 1 (a-f) of the Programme.’;

Added(ab) the following new paragraph 2b is inserted:

Added‘ (2b). The amount for the establishment and implementation of the EU Cybersecurity Reserve shall not exceed EUR 27 million for the intended duration of the Regulation laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cybersecurity threats and incidents.’;

Added(b) the following paragraph 8 is added:

Added‘8. By way of derogation from Article 12(4) of Regulation (EU, Euratom) 2018/1046, unused commitment and payment appropriations for actions in the context of the implementation of the EU cybersecurity Reserve, pursuing the objectives set out in Article 6(1), point (g) of this Regulation, shall be automatically carried over and may be committed and paid up to 31 December of the following financial year.’;

AddedThe Commission shall inform the Parliament and the Council of appropriations carried over in accordance with art. 12(6) of Regulation (EU, Euratom) 2018/1046.

Added(3) In Article 14, paragraph 2 is replaced by the following:

Added“2. The Programme may provide funding in any of the forms laid down in the Regulation (EU, Euratom) 2018/1046, including in particular through procurement as a primary form, or grants and prizes.

AddedWhere the achievement of the objective of an action requires the procurement of innovative goods and services, grants may be awarded only to beneficiaries that are contracting authorities or contracting entities as defined in Directives 2014/24/EU 27 and 2014/25/EU 28 of the European Parliament and of the Council.

AddedWhere the supply of innovative goods or services that are not yet available on a large-scale commercial basis is necessary to achieve the objectives of an action, the contracting authority or the contracting entity may authorise the award of multiple contracts within the same procurement procedure.

AddedFor duly justified reasons of public security, the contracting authority or the contracting entity may require that the place of performance of the contract be situated within the territory of the Union.

AddedWhen implementing procurement procedures for the EU Cybersecurity Reserve established by Article 12 of Regulation (EU) 2023/…, the Commission and ENISA may act as a central purchasing body to procure on behalf of or in the name of third countries associated to the Programme in line with Article 10. The Commission and ENISA may also act as wholesaler, by buying, stocking and reselling or donating supplies and services, including rentals, to those third countries. By derogation from Article 169(3) of Regulation (EU). …/…, the request from a single third country is sufficient to mandate the Commission or ENISA to act.

AddedWhen implementing procurement procedures for the EU Cybersecurity Reserve established by Article 12 of Regulation (EU) 2023/…XX, the Commission and ENISA may act as a central purchasing body to procure on behalf of or in the name of Union institutions, bodies and agencies. The Commission and ENISA may also act as wholesaler, by buying, stocking and reselling or donating supplies and services, including rentals, to Union institutions, bodies and agencies. By derogation from Article 169(3) of Regulation (EU) …/…, the request from a single Union institution, body or agency is sufficient to mandate the Commission or ENISA to act.

AddedThe Programme may also provide financing in the form of financial instruments within blending operations. ’;

Added(4) The following article 16a is added:

Added‘Article 16a

AddedIn the case of actions implementing the European Cyber Shield established by Article 3 of Regulation (EU) 2023/XX, the applicable rules shall be those set out in Articles 4 and 5 of Regulation (EU) 2023/…. In the case of conflict between the provisions of this Regulation and Articles 4 and 5 of Regulation (EU) 2023/…, the latter shall prevail and apply to those specific actions.’;

Added(5) Article 19 is replaced by the following:

Added‘Grants under the Programme shall be awarded and managed in accordance with Title VIII of Regulation (EU, Euratom) 2018/1046 and may cover up to 100 % of the eligible costs, without prejudice to the co-financing principle as laid down in Article 190 of Regulation (EU, Euratom) 2018/1046. Such grants shall be awarded and managed as specified for each specific objective.

AddedSupport in the form of grants may be awarded directly by the ECCC without a call for proposals to the National SOCs referred to in Article 4 of Regulation (EU) .../... and the Hosting Consortium referred to in Article 5 of Regulation (EU) .../..., in accordance with Article 195(1), point (d) of Regulation (EU, Euratom) 2018/1046.

AddedSupport in the form of grants for the Cybersecurity Emergency Mechanism as set out in Article 10 of Regulation (EU) .../...may be awarded directly by the ECCC to Member States without a call for proposals, in accordance with Article 195(1), point (d) of Regulation (EU, Euratom) 2018/1046.

AddedFor actions specified in Article 10(1), point (c) of Regulation (EU) .../..., the ECCC shall inform the Commission and ENISA about Member States’ requests for direct grants without a call for proposals.

AddedFor the support of mutual assistance for response to a significant or large-scale cybersecurity incident as defined in Article 10(c), of Regulation (EU) .../..., and in accordance with Article 193(2), second subparagraph, point (a), of Regulation (EU, Euratom) 2018/1046, in duly justified cases, the costs may be considered to be eligible even if they were incurred before the grant application was submitted.”;

Added(6) Annexes I and II to Regulation (EU) 2021/694 are amended in accordance with the Annexto this Regulation.

AddedArticle19a

AddedAdditional ressources for ENISA

AddedENISA shall receive additional resources to carry out its additional tasks conferred on it by this Regulation. That additional support, including funding, shall not jeopardise the achievement of the objectives of other Union’s Programmes, in particular the Digital Europe Programme.

AddedEvaluation and Review

Added1. By [two years from the date of application of this Regulation] and every two years thereafter, the Commission shall carry out an evaluation of the functioning of the measures laid down in this Regulation and shall submit a report to the European Parliament and to the Council.

Added2. The evaluation shall assess in particular:

Added(a) the use and added value of the Cross-Border SOCs and the extent to which they contribute to fastering the detection of and respone to cyber threats and situational awareness; the active participation of National SOCs in the European Cyber Shield, including the number of National SOCs and Cross-border SOCs established and the extent to which it has contributed to the production and exchange of high-quality actionable information and cyber threat intelligence; the number and costs of cybersecurity infrastructure, or tools, or both jointly procured; the number of cooperation agreements concluded between Cross-border SOCs and with industry ISACs; the number of incidents reported to the CSIRT network and the impact it has on the work of the CSIRT Network;

Added(b) both the positive and the negative working of the Cybersecurity Emergency Mechanism, including whether further cooperation or training requirements are needed;

Added(c) the contribution of this Regulation to reinforce the Union’s resilience and open strategic autonomy, to improve the competitiveness of the relevant industry sectors, microenterprises, SMEs including start-ups, and the development of cybersecurity skills in the Union;

Added(d) the use and added value of the EU Cybersecurity Reserve, including the number of trusted security providers part of the EU Cybersecurity Reserve; the number, type, costs and impact of actions carried out supporting response to cybersecurity incidents, as well as its users and providers; the mean time for the Commission to acknowledge, the EU Cybersecurity Reserve to be deployed and to respond, and the user to recover from incidents; whether the scope of the EU Cybersecurity Reserve is to be broadened to incident preparedness services or common exercises with the trusted managed securiy service providers and potential users of the EU Cybersecurity Reserve to ensure efficient functioning of the EU Cybersecurity Reserve where necessary;

Added(e) the contribution of this Regulation to the development and improvement of the skills and competences of the workforce in the cybersecurity sector, needed to strengthen the Union's capacity to detect, prevent, respond to and recover from cybersecurity threats and incidents;

Added(f) the contribution of this Regulation to the deployment and development of state-of-the-art technologies in the Union.

Added3. On the basis of the reports referred to in paragraph 1, the Commission shall, where appropriate, submit a legislative proposal to the European Parliament and to the Council to amend this Regulation.

AddedExercise of the delegation

Added1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

Added2. The power to adopt delegated acts referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) shall be conferred on the Commission for a period of … years from … [date of entry into force of the basic legislative act or any other date set by the co-legislators]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the … year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.

Added3. The delegation of power referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=6 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
  year = {2023},
  date = {2023-12-08},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=6}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=6},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}