Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ITRE-PR-752802 → A-9-2023-0307
- From
- ITRE-PR-752802 report parliamentary committee draft of 7 Sept 2023
- To
- A-9-2023-0307 Plenary report of 26 Oct 2023
- Changes
- Not comparable
- Paragraphs
- +199 added · −23 removed · 4 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 7: Paragraphs 61–120
Added(4b) The Union certification scheme for managed security services should ensure the availability of secure and high-quality services which guarantee a safe digital transition and contribute to the achievement of targets set up in the Digital Decade Policy Programme, especially with regard to the goal that 75% of Union undertakings start using Cloud, AI or Big Data, that more than 90% of microenterprises and SMEs reach at least a basic level of digital intensity and that key public services are offered online.
Added(4c) In the current fast evolving digital and technological landscape, the offer of educational resources and formal trainings differ and knowledge can be acquired in various ways, both formal, for example through university or courses and non-formal, for example through on the job trainings or longstanding work experience in the relevant field.
Added(5) In addition to the deployment of ICT products, ICT services or ICT processes, managed security services often provide additional service features that rely on the competences, expertise and experience of their personnel. A very high level of these competences, expertise and experience as well as appropriate internal procedures should be part of the security objectives in order to ensure a very high quality of the managed security services provided. In order to ensure that all aspects of a managed security service can be covered by a dedicated certification scheme, it is therefore necessary to amend Regulation (EU) 2019/881. The development of certification schemes established pursuant to this Regulation should take into account the results and recommendations of the evaluation and review provided for in this Regulation.
Added(5a) With a view to facilitating the growth of a reliable Union market, whilst also creating partnerships with likeminded third countries, including in light of the provisions of the Regulation (EU) .../... of the European Parliament and of the Council (2023/0109(COD)) with regard to the access to the EU Cybersecurity Reserve, the certification process established within the framework established by this Regulation should be streamlined to ensure international recognition and alignment with international standards.
Added(5b) With the aim of ensuring the development of a trustworthy Union market for managed security services, the providers thereof and Member States should collaborate and contribute to the collection of data on the situation and the evolution of the cybersecurity labour market.
Added(5c) A Union-wide coordinated approach to strengthening the resilience of critical infrastructure is based on the Member States’ capacity building. However, the Union is faced with a talent gap, characterised by a shortage of skilled professionals, and a rapidly evolving threat landscape as acknowledged in the Commission communication of 18 April 2023 on the Cybersecurity Skills Academy. Therefore, in order to facilitate the emergence of high-quality, essential managed security services and to have a better overview of the composition of the Union cybersecurity workforce, cooperation between Member States, the Commission, ENISA and stakeholders, including the private sector and academia, should be strengthened through the development of public-private partnerships, support of research and innovation initiatives, the development and mutual recognition of common standards and certification of cybersecurity skills, including through the European Cyber Security Skills Framework. This should also facilitate the mobility of cybersecurity professionals within the Union as well as the integration of cybersecurity knowledge and training in educational programmes, while ensuring access to apprenticeships and traineeships for young people, including persons living in disadvantaged regions, such as islands, sparsely populated, rural and remote areas. Those measures should also aim to attract more women and girls in the field and contribute towards addressing the gender gap in science, technology, engineering, and mathematics. The private sector should also aim to deliver on-the-job training addressing the most in-demand skills, involving public administration and start-ups, as well as microenterprises and SMEs.
Added(5d) Appropriate funding and resources should be ensured for the purpose of the additional tasks entrusted to ENISA by the amendments to Regulation (EU) 2019/881 introduced by this Regulation.
Added(5e) In order to supplement certain non-essential elements of this Regulation, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission to provide for a European cybersecurity certification scheme for ICT products, ICT services, ICT processes and managed security services. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making . In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.
Added(5e) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and delivered an opinion on [DD/MM/YYYY],
AddedHAVE ADOPTED THIS REGULATION:
AddedRegulation (EU) 2019/881 is amended as follows:
Added(1) in Article 1(1), first subparagraph, point (b) is replaced by the following:
Added‘(b) a framework for the establishment of European cybersecurity certification schemes for the purpose of ensuring an adequate level of cybersecurity for ICT products, ICT services, ICT processes, and managed security services in the Union, as well as for the purpose of avoiding the fragmentation of the internal market with regard to cybersecurity certification schemes in the Union.’;
Added(2) Article 2 is amended as follows:
Added(a) points (9), (10) and (11) are replaced by the following:
Added‘(9) ‘European cybersecurity certification scheme’ means a comprehensive set of rules, technical requirements, standards and procedures that are established at Union level and that apply to the certification or conformity assessment of specific ICT products, ICT services, ICT processes, or managed security services;
Added’(10) ‘national cybersecurity certification scheme’ means a comprehensive set of rules, technical requirements, standards and procedures developed and adopted by a national public authority and that apply to the certification or conformity assessment of ICT products, ICT services, ICT processes and managed security services falling under the scope of the specific scheme;
Added(11) ‘European cybersecurity certificate’ means a document issued by a relevant body, attesting that a given ICT product, ICT service, ICT process or managed security service has been evaluated for compliance with specific security requirements laid down in a European cybersecurity certification scheme;’;
Added(b) the following point is inserted:
Added‘(14a) ‘managed security service’ means a service provided to a third party consisting of carrying out, or providing assistance for, or advice on activities relating to cybersecurity risk management, including incident handling, penetration testing, security audits and consulting’;
Added(c) points (20), (21) and (22) are replaced by the following:
Added‘(20) ‘technical specifications’ means a document that prescribes the technical requirements to be met by, or conformity assessment procedures relating to, an ICT product, ICT service, ICT process or managed security service;
Added(21) ‘assurance level’ means a basis for confidence that an ICT product, ICT service, ICT process or managed security service meets the security requirements of a specific European cybersecurity certification scheme, and indicates the level at which an ICT product, ICT service, ICT process or managed security service has been evaluated but as such does not measure the security of the ICT product, ICT service, ICT process or managed security service concerned;
Added(22) ‘conformity self-assessment’ means an action carried out by a manufacturer or provider of ICT products, ICT services, ICT processes or managed security services, which evaluates whether those ICT products, ICT services, ICT processes or managed security services meet the requirements of a specific European cybersecurity certification scheme;’;
Added(3) in Article 4, paragraph 6 is replaced by the following:
Added‘6. ENISA shall promote the use of European cybersecurity certification, with a view to avoiding the fragmentation of the internal market. ENISA shall contribute to the establishment and maintenance of a European cybersecurity certification framework in accordance with Title III of this Regulation, with a view to increasing the transparency of the cybersecurity of ICT products, ICT services, ICT processes, and managed security services, thereby strengthening trust in the digital internal market and its competitiveness.’;
Added(4) Article 8 is amended as follows:
Added(a) paragraph 1 is replaced by the following:
Added‘1. ENISA shall support and promote the development and implementation of Union policy on cybersecurity certification of ICT products, ICT services, ICT processes and managed security services, as established in Title III of this Regulation, by:
Added(a) monitoring developments, on an ongoing basis, in related areas of standardisation and recommending appropriate technical specifications for use in the development of European cybersecurity certification schemes pursuant to Article 54(1), point (c), where standards are not available;
Added(b) preparing candidate European cybersecurity certification schemes (‘candidate schemes’) for ICT products, ICT services, ICT processes and managed security services in accordance with Article 49;
Added(c) evaluating adopted European cybersecurity certification schemes in accordance with Article 49(8);
Added(d) participating in peer reviews pursuant to Article 59(4);
Added(e) assisting the Commission in providing the secretariat of the ECCG pursuant to Article 62(5).’;
Added(b) paragraph 3 is replaced by the following:
Added‘3. ENISA shall compile and publish guidelines and develop good practices, concerning the cybersecurity requirements for ICT products, ICT services, ICT processes and managed security services, in cooperation with national cybersecurity certification authorities and industry in a formal, structured and transparent way.’;
Added(c) paragraph 5 is replaced by the following:
Added‘5. ENISA shall facilitate the establishment and take-up of European and international standards for risk management and for the security of ICT products, ICT services, ICT processes and managed security services.’;
Added(5) in Article 46, paragraphs 1 and 2 are replaced by the following:
Added‘1. The European cybersecurity certification framework shall be established in order to improve the conditions for the functioning of the internal market by increasing the level of cybersecurity within the Union and enabling a harmonised approach at Union level to European cybersecurity certification schemes, with a view to creating a digital single market for ICT products, ICT services, ICT processes and managed security services.
Added2. The European cybersecurity certification framework shall provide for a mechanism to establish European cybersecurity certification schemes. It shall attest that the ICT products, ICT services and ICT processes that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the functions or services offered by, or accessible via, those products, services and processes throughout their life cycle. In addition, it shall attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements for the purpose of protecting the availability, authenticity, integrity and confidentiality of data, which are accessed, processed, stored or transmitted in relation to the provision of those services, and that those services are provided continuously with the requisite competence, expertise and experience by staff with a very high level of relevant technical knowledge and professional integrity.’;
Added(6) in Article 47, paragraphs 2 and 3 are replaced by the following:
Added‘2. The Union rolling work programme shall in particular include a list of ICT products, ICT services and ICT processes or categories thereof, and managed security services, that are capable of benefiting from being included in the scope of a European cybersecurity certification scheme. In that context, the Commission may include an in-depth assessment of existing training paths to bridge identified skills gaps and a list of proposals for addressing the needs for skilled employees and types of skills.
Added3. Inclusion of specific ICT products, ICT services and ICT processes or categories thereof, or of managed security services, in the Union rolling work programme shall be justified on the basis of one or more of the following grounds:
Added(a) the availability and the development of national cybersecurity certification schemes covering a specific category of ICT products, ICT services, ICT processes or managed security services and, in particular, as regards the risk of fragmentation;
Added(b) relevant Union or Member State law or policy;
Added(c) market demand;
Added(ca) technological developments and the availability and development of international cybersecurity certification schemes and international and industrial standards.
Added(d) developments in the cyber threat landscape;
Added(e) request for the preparation of a specific candidate scheme by the ECCG.’;
Added(7) Article 49, is amended as follows:
Added(a) paragraph 7 is replaced by the following:
Added‘7. The Commission, based on the candidate scheme prepared by ENISA, is empowered to adopt delegated acts in accordance with Article 65a, supplementing this Regulation by providing for a European cybersecurity certification scheme for ICT products, ICT services, ICT processes and managed security services which meets the requirements set out in Articles 51, 52 and 54.’;
Added(b) the following paragraph is inserted:
Added‘7a. Before adopting such delegated acts, the Commission, in cooperation with ENISA, shall carry out and publish an impact assessment of the proposed European cybersecurity certification scheme. While preparing the impact assessment, the Commission shall carry out public consultations and shall consult the SCCG and ECCG.’;
Added(8) Article 51 is amended as follows:
Added(a) the title is replaced by the following:
Added‘Security objectives of European cybersecurity certification schemes for ICT products, ICT services and ICT processes’
Added(b) the introductory sentence is replaced by the following:
Added‘A European cybersecurity certification scheme for ICT products, ICT services or ICT processes shall be designed to achieve, as applicable, at least the following security objectives:’;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752802/compare/A-9-2023-0307?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2023). “Changes between ITRE-PR-752802 and A-9-2023-0307”. Text, 26 October 2023. from ITRE-PR-752802, to A-9-2023-0307. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752802/compare/A-9-2023-0307?all=1&part=2 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2023-10-26,
author = {{European Parliament}},
title = {{Changes between ITRE-PR-752802 and A-9-2023-0307}},
year = {2023},
date = {2023-10-26},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752802/compare/A-9-2023-0307?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-752802/compare/A-9-2023-0307?all=1&part=2},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from ITRE-PR-752802, to A-9-2023-0307. Data: European Parliament Open Data (CC BY 4.0)}
}