Text · Report parliamentary committee draft
On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Document LIBE-PR-751547 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)
- Kind
- Report parliamentary committee draft LIBE-PR-751547
- Date
- 13 July 2023
- Committee
- Committee on Civil Liberties, Justice and Home Affairs
- Rapporteur
- Vladimír Bilčík
- Dossier
- 2022-0084
More facts (3)
- Formats
- Official page PDF Word
- Subject matter
- INFO, INST, PDON
- Reference
- COM(2022)0119 – C90121/2022 – 2022/0084(COD)
In short
A summary of the text written by AI; ¶ opens the paragraph it rests on.
AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026
This is the rapporteur's draft report on the Commission proposal for a regulation on information security in the Union's institutions, bodies, offices and agencies. It adopts Parliament's first-reading position and proposes 33 amendments to the Commission proposal. The amendments add common minimum rules, principles of minimisation and time-limiting of classification, protection for whistle-blowers, and safeguards for the integrity of democratic processes. They also set deadlines for breach notification, require training within six months of entry into force, and change the Coordination Group's voting rule to a two-thirds majority.
Position. The rapporteur proposes that Parliament adopt its first-reading position with 33 amendments to the Commission proposal, adding common minimum rules, classification minimisation, whistle-blower protection, democratic integrity safeguards, breach-notification deadlines and a two-thirds voting rule for the Coordination Group.
Key points
- Parliament adopts its position at first reading and calls on the Commission to refer the matter to Parliament again if it replaces or substantially amends its proposal.
- The regulation would lay down common minimum information security rules for all Union institutions and bodies.
- Classification of EU classified information should follow the principles of minimisation and limiting its duration in time.
- Institutions should enhance transparency, minimise confidential documents, protect whistle-blowers and avoid classification that prevents Union entities from fulfilling their mission.
- Institutions should increase organisational interoperability and protect networks, information systems, data and equipment used to capture, store, process and transmit information.
- When developing their document security framework, institutions shall safeguard the integrity of the Union's democratic processes and adopt provisions in tender procedures to curb the risk of foreign interference.
- Institutions handling EUCI shall organise mandatory training at least once every 5 years, and design and implement training courses not later than six months after entry into force.
- The Coordination Group would act by a majority of at least two thirds of its members and monitor compliance through a yearly evaluation report.
- A sub-group on administrative arrangements with third countries and international organisations would be set up, and the sub-group on EUCI sharing would include the European Parliament.
- Institutions would have to inform the originator and notify competent authorities of a breach without undue delay and not later than one week after the Security Authority is informed.
- The originator may consult intended recipients on classification level to prevent over-classification, and shall take into account recipients' rights and obligations under the Treaties.
- End-to-end encryption would be required in particular when exchanging sensitive non-classified information, and a process for identifying and reporting vulnerabilities would be set up.
Who is affected
- All Union institutions and bodies, which would have to apply common minimum information security rules.
- Staff authorised to access EUCI, who would receive mandatory training at least once every 5 years.
- The Coordination Group, which would act by a two-thirds majority and monitor compliance.
- Third countries and international organisations, whose security clearances may be accepted if the Union has a security of information agreement.
Figures and deadlines
- Mandatory training at least once every 5 years for individuals authorised to access EUCI.
- Training courses to be designed and implemented not later than six months after entry into force.
- Breach notification not later than one week after the Security Authority is informed.
- Coordination Group decisions by a majority of at least two thirds of its members.
Legal basis. Article 294(2) and Article 298 of the Treaty on the Functioning of the European Union, and Article 106a of the Treaty establishing the European Atomic Energy Community.
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (33)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
Draft european parliament legislative resolution
–having regard to Article 294(2) and Article 298 of the Treaty on the Functioning of the European Union, as well as Article 106a of the Treaty establishing the European Atomic Energy Community, pursuant to which the Commission submitted the proposal to Parliament (C90121/2022),
–having regard to the opinions of the Committee on Industry, Research and Energy and the Committee on Constitutional Affairs,
–having regard to the letters from the Committee on Foreign Affairs and the Committee on International Trade,
–having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A90000/2023),
2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3.Instructs its President to forward its position to the Council, the Commission and the national parliaments.
| Text proposed by the Commission | Amendment |
|---|---|
| (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected. | (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected as well as the interoperability of such tools. |
| Text proposed by the Commission | Amendment |
|---|---|
| (1a) Union institutions are obliged to apply Article 15(3) TFEU in line with democratic principles, in particular those laid down in Article 10(3) TEU and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’). Therefore, creation and classification of European Union classified information (‘EUCI’) should take place in line with the principles of minimisation of the use of classification and limiting in time the duration of such a classification. |
| Text proposed by the Commission | Amendment |
|---|---|
| (3a) In the context of information security, Union institutions and bodies should increase organisational interoperability and act together to ensure that networks, information systems, data and the equipment and material assets employed to capture, store, process and transmit the information are protected. |
| Text proposed by the Commission | Amendment |
|---|---|
| (4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. | (4) In recent years, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) Sharing of EUCI in a transparent and timely manner is of key importance for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union entities from fulfilling their mission, and should ensure that whistle-blowers are adequately protected, and that there is a high level of protection of information in line with Union law and best practices. |
| Text proposed by the Commission | Amendment |
|---|---|
| (6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. | (6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , including the rules on international transfers of personal data, Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. |
| 17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). | 17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406). |
| 18 OJ 45, 14.6.1962, p. 1385. | 18 OJ 45, 14.6.1962, p. 1385. |
| 19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43). | 19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43). |
| 20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). | 20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39). |
| 21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1). | 21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1). |
| 22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1). | 22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1). |
| 23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149). | 23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149). |
| 24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted | 24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted |
| Text proposed by the Commission | Amendment |
|---|---|
| (8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. | (8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| (14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. | (14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure and terminal devices used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures. |
| Text proposed by the Commission | Amendment |
|---|---|
| (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. | (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out. That evaluation should take into account the full supply chain and the operational environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. | (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders. |
| Text proposed by the Commission | Amendment |
|---|---|
| (21a) The information held by the Union entities is also exchanged through the ICT environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systems whether owned and operated by a Union entity or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment. |
| Text proposed by the Commission | Amendment |
|---|---|
| (24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness of a Union institution or body should be assessed before they handle and store a specified level of EUCI. | (24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness and capabilities of a Union institution or body should be assessed before they handle and store a specified level of EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. This Regulation lays down information security rules for all Union institutions and bodies. | 1. This Regulation lays down common minimum information security rules for all Union institutions and bodies. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. | 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of the Union’s democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall at least address the acquisition and maintenance of security infrastructure, the vetting of third party organisations and security clearance procedures in respect of staff. |
| Text proposed by the Commission | Amendment |
|---|---|
| Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. | Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entities shall, not later than ...[six months after the date of entry into force of this Regulation], design and implement effective and appropriate training courses commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) ensuring the integrity, availability and resilience of processing systems and services. |
| Text proposed by the Commission | Amendment |
|---|---|
| (aa) the risks for the rights and freedoms of natural persons; |
| Text proposed by the Commission | Amendment |
|---|---|
| (f) business continuity and disaster recovery; | (f) business continuity, disaster recovery and crisis management; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. Acting by consent and in the common interest of all Union institutions and bodies, the Coordination Group shall: | 2. Acting by a majority of at least two thirds of its members and in the common interest of all Union institutions and bodies, the Coordination Group shall: |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report; |
| Text proposed by the Commission | Amendment |
|---|---|
| (ea) a sub-group on administrative arrangements with third countries and international organisations. |
| Text proposed by the Commission | Amendment |
|---|---|
| (ca) strengthening cooperation and coordination with CERT-EU. |
| Text proposed by the Commission | Amendment |
|---|---|
| (da) end-to-end encryption, in particular when exchanging sensitive non-classified information; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. | 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. Such guidance documents shall take into account the principle of minimisation of the use of classified information as well as the risk of overclassification of certain documents. Such guidance documents shall include rules on assessing and justifying information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3a. This Article is without prejudice to Regulation (EC) No 1049/2001. |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) inform the originator; | (a) inform the originator without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach; |
| Text proposed by the Commission | Amendment |
|---|---|
| (e) notify the competent authorities about the actual or potential compromise and the action taken. | (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach. |
| Text proposed by the Commission | Amendment |
|---|---|
| 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. | 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 are observed. |
| Text proposed by the Commission | Amendment |
|---|---|
| 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: | 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. The originator may consult intended recipients regarding the classification level of an EUCI document, in particular in the event of any doubt as to the confidential nature of an item of information and its appropriate level of classification, and to prevent over-classification of such a document. For the purposes of the initial dissemination of an EUCI document, the originator shall take into account the rights and obligations of information recipients arising from the Treaties. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is: |
| Text proposed by the Commission | Amendment |
|---|---|
| (fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards for reporting vulnerabilities , as appropriate; that process shall be complemented by regular audits and penetration tests where appropriate. |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus. | 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall ensure synergy between the need to protect EUCI and Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure. |
| Text proposed by the Commission | Amendment |
|---|---|
| (-a) there is a legal obligation under Union law or an interinstitutional agreement concluded between Union institutions; or |
| Text proposed by the Commission | Amendment |
|---|---|
| (a) there is a proven need for the exchange; | (a) there is a proven need for the exchange including in line with the ‘need-to-know’ principle; |
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2023). “DRAFT REPORT on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 13 July 2023. docId LIBE-PR-751547. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/LIBE-PR-751547 (CC BY 4.0).
BibTeX
@misc{epw-text-libe-pr-751547,
author = {{European Parliament}},
title = {{DRAFT REPORT on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
year = {2023},
date = {2023-07-13},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547}},
url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId LIBE-PR-751547. Data: EP Open Data API: document record (CC BY 4.0)}
}