Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ITRE-PR-752795 → A-9-2023-0426

From
ITRE-PR-752795 report parliamentary committee draft of 4 Sept 2023
To
A-9-2023-0426 Plenary report of 8 Dec 2023
Changes
Not comparable
Paragraphs
+319 added · −52 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
Title (to)
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 8 of 8: EXPLANATORY STATEMENT

EXPLANATORY STATEMENT

27 unchanged paragraphs

CONTEXT

Cybersecurity is and should be at the core of our democracies. Threats to cybersecurity are linked to the spread of insecurity among the population and companies, as well as to the rise of disinformation, which challenges democratic principles that preserve respect for human rights. To prevent this, a secure digital environment subject to public scrutiny is crucial for our democracies.

Cyberattacks in the EU are increasing in terms of methods and impact. In addition, the Russian attack to Ukraine has created deep changes, even before the invasion, and has opened a new era for cyberware according to the ENISA’s Threat Landscape 2022 report. The priorities identified from this conflict in cyber are the need to build capabilities in multilateral programs and projects and the need to develop skills fast. In order to be more resilient, a common European response is urgently needed, based on stronger cooperation at the European level beyond the national one.

Increasing Cybersecurity Culture which comprehends security, including that of the digital environment, as a public good will be key for the successful implementation of this regulation.

Moreover, cyberattacks are frequently targeted at local, regional or national public services and infrastructures (e.g. the healthcare sector that remains a prime target for cyber-attacks). Evidence also points out that local authorities are amongst the most vulnerable target due to the lack of financial and human resources, and it is particularly important the awareness among leaders at local level to increase digital resilience. Attacks primarily and directly affect citizens and thus endanger our democracies, including through disinformation campaigns. The feeling of insecurity that these situations can create in the population can lead to political preferences that follow a radical commitment to security to the detriment of respect for fundamental rights. However, the opposite is true: security is an essential part of our democracies, compatible with and necessary for all other rights.

In addition, companies and SMEs in the EU are also experiencing cybercrime, and with the increasing use of the digital sphere to conduct businesses, there is a bigger concern in cybersecurity. SMEs are those less prepared, with fewer resources to protect themselves and even less aware that they can be subject of such attacks.

The expectation is that these attacks will continue and increase in the future. Especially in situations of political instability and more particularly in contexts of war. With the digital transition going further every day, digital resilience becomes more and more important for our daily lives and for the open strategic autonomy of the EU.

PROPOSAL OF THE RAPPORTEUR

The Rapporteur believes that the EU needs to be better prepared for the future and welcomes this urgent piece of legislation to pool recourses, information, and knowledge to ensure solidarity between Member States, to grow industrial capacity in the EU, to develop co-ordinately skills and capabilities that ensure cybersecurity, to be more resilient to future attacks and to protect our democracies against self-serving use of security needs. Moreover, it is important to protect the integrity of our electoral processes. This piece of legislation is an essential commitment to achieve the objective of open strategic autonomy.

For these reasons, the EU needs strong and coordinated governance in the EU and structured cooperation with the private sector to foster the development of the European cyber industry. In addition to collaboration with like-minded international partners, but also with other countries that do not have the same capabilities and may need to be assisted when they are victims of cyber-attacks. The EU Cyber Solidarity Act must define well its governance and not overlap already existing initiatives and legislation, such as the NIS2 Directive.

The proposal is based significantly on the exchange of information in a voluntary manner among Member States. For that reason, the Rapporteur proposes to enhance the guarantees to build trust among Member States to increase their participation and cooperation, for example regarding joint acquisitions of infrastructure as well as the involvement of the legislative powers, to ensure citizens trust and democratic guarantees.

Secondly, the Rapporteur proposes to ensure the budget from the upcoming MFFs for this initiative, also with commitment from the Member States, to guarantee continuity to the activities developed under the EU Cyber Solidarity Act beyond 2027.

Thirdly, the Rapporteur proposes to improve the governance structure, have a clear governance definition, and link it with existing legislation.

The Rapporteur also proposes a better coordination among Member States’ different entities in charge of cyber security to offer a common cyber shield. Moreover, to increase ENISA’s contribution on the coordination and interaction between the different actors of the national communities.

Regarding the new cybersecurity reserve, the Rapporteur believes it has the potential of developing industrial capacities in the EU, including for SMEs, with investments in research and innovation to develop state of the art technologies, such as cloud and artificial intelligence technologies. In addition, the Rapporteur proposes to maintain the participation of the industry, enhance the criteria and trust of their participation (i.e. connecting their participation to a national or local company) by clarifying the criteria and the definition of technological sovereignty and to guarantee a balance between non-EU and EU actors. In addition, the Rapporteur proposes for the Cyber Emergency Mechanism a certification scheme to be used for private providers to build a longstanding and trusted partnership.

Regarding the incident review mechanism, the Rapporteur proposes to reinforce the role of ENISA and the private sector in the SOCs, with the right guarantees and monitoring, to validate if the lessons learned identified are also backed by the actors in the industry. Moreover, the Rapporteur proposes to include as lessons learned via the peer reviews as stated in the NIS2 Directive and to increase ENISA funding aiming at ensuring an effective application of legislation and adequate protection to face cybersecurity threats.

In addition, this proposal by definition has a very relevant external dimension, be it as third countries can access resources and support from the EU Cyber Solidarity Act, using the incident response support from the EU Cybersecurity Reserve, and as non-EU actors from private sector are still needed for the cyber reserve. The external dimension also has to be subject to public scrutiny, with the participation of the legislative powers to guarantee that citizens can participate in the process. Cybersecurity should be considered a public good.

Furthermore, a central pillar of this proposal is the development of skills and competences that should go beyond simply investing in knowledge development, but investing in access for all citizens to be able to train in these skills. The Rapporteur proposes to reinforce the link with the EU Cybersecurity Skills Academy, which intends to close the cybersecurity talent gap by bringing together private and public initiatives and providing training and certification for citizens. The strengthening will need safeguards to avoid brain drain and would not be detrimental to labour mobility.

Furthermore, the Rapporteur proposes to invest and include active measures to develop skills in this sector, considering that 2023 is the European Year of Skills, as well as increase citizens’ awareness. The measures will be designed so that investments do not create imbalances between Member States, as the current high demand and high wages in this sector can lead to a certain type of brain drain towards the best-paid options.

For these reasons, the Rapporteur proposes a reinforcement of specialised, interdisciplinary, and general skills and competences across the EU, with a special focus on women, as the gender gap persist in cybersecurity with women comprising 20% of the average worldwide presence. Women must be present and part of the design of the digital future and its governance.

In addition, the Rapporteur proses to reinforce the triangle between national competence centres, the European Cybersecurity Competence Centre (ECCC) and ENISA in developing skills and competences. Moreover, increasing the role of industry in developing skills and creating partnerships with academia and civil society actors, counting with the regional experience, knowledge, and specialisation and third country alliances, with like-minded partners in order to increase the exchanges and ensure a global approach to support citizens, businesses and institutions.

The rapporteur also proposes to share cooperation in talent and measure of human harm of the cyberattacks (e.g., the impact of a ransomware attack to the health sector).

The Rapporteur proposes measures to include and increase citizen awareness without alarmism, as another measure to guarantee the safeguard of our democracies and fundamental values. Increasing Cybersecurity Culture which comprehends security, including that of the digital environment, as a public good. This way we will be able to guarantee a model of digital democracy, as opposed to one of digital authoritarianism, with transparency, democracy, and the certainty that the development of an ex-ante legislation can bring.

Furthermore, the Rapporteur believes that to strengthening R&I in cybersecurity will increase the resilience and the open strategic autonomy of the EU. Likewise, ensuring synergies with research and innovation programs and with existing instruments and institutions and to reinforce the triangle of knowledge to bridge the skills gap across the EU.

Moreover, this legislation will increase the resilience of the EU and its Member States, not only directly via the cybersecurity and cyber resilience laws, but also with the impact it can have for the exponential development of artificial intelligence and the impact the regulation of data and data privacy can have on cybersecurity.

In addition, this legislation will help achieve the commitment of the European Declaration on Digital Rights and Principles for the Digital Decade linked to protect the interests of people, businesses and public institutions against cybersecurity risks and cybercrime including data breaches and identity theft or manipulation.

In this light, the Rapporteur believes this proposal should be operational as fast as possible, including the European Cybersecurity shield and the Cyber Emergency Mechanism, to have a general framework and avoid silos, as cyber space has no borders.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2023). “Changes between ITRE-PR-752795 and A-9-2023-0426”. Text, 8 December 2023. from ITRE-PR-752795, to A-9-2023-0426. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=8 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-12-08,
  author = {{European Parliament}},
  title = {{Changes between ITRE-PR-752795 and A-9-2023-0426}},
  year = {2023},
  date = {2023-12-08},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=8}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752795/compare/A-9-2023-0426?all=1&part=8},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ITRE-PR-752795, to A-9-2023-0426. Data: European Parliament Open Data (CC BY 4.0)}
}