Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to report parliamentary committee draft

LIBE-PR-751547 → LIBE-PR-776837

From
LIBE-PR-751547 report parliamentary committee draft of 13 Jul 2023
To
LIBE-PR-776837 report parliamentary committee draft of 2 Sept 2025
Changes
11 changes to the text
Paragraphs
+0 added · −0 removed · 15 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 1 of 1: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

7 unchanged paragraphs

on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

(COM(2022)0119 – C90121/2022 – 2022/0084(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

– having regard to the Commission proposal to Parliament and the Council (COM(2022)0119),

– having regard to Article 294(2) and Article 298 of the Treaty on the Functioning of the European Union, as well as Article 106a of the Treaty establishing the European Atomic Energy Community, pursuant to which the Commission submitted the proposal to Parliament (C90121/2022),

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

Changed– having regard to Rule 5960 of its Rules of Procedure,

Changed– having regard to the opinionsopinion of the Committee on Industry, Research and Energy and the Committee on Constitutional Affairs,Energy,

Changed– having regard to the letters from the Committee on Foreign AffairsAffairs, the Committee on International Trade and the Committee on InternationalConstitutional Trade,Affairs,

Changed– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A90000/2023),(A100000/2025),

4 unchanged paragraphs

1. Adopts its position at first reading hereinafter set out;

2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Recital 1: (1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected as well as the interoperability of such tools.

Change 1

ChangedRecital 1 a (new): (1a) Union institutions and bodies are obliged to apply Article 15(3) TFEUof the Treaty on the Functioning of the European Union(‘TFEU’) in line with democratic principles, in particular those laid down in Article 10(3) TEUof the Treaty on European Union (‘TEU’) and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’). Therefore, the creation and classification of European Union classified information (‘EUCI’)(EUCI) should take place in line with the principles of minimisation of the use of classification and limiting in time the duration of such a classification.

Recital 3 a (new): (3a) In the context of information security, Union institutions and bodies should increase organisational interoperability and act together to ensure that networks, information systems, data and the equipment and material assets employed to capture, store, process and transmit the information are protected.

Recital 4: (4) In recent years, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.

Change 2

ChangedRecital 5 a (new): (5a) Sharing of EUCI in a transparent and timely manner is of key importance for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union entitiesinstitutions and bodies from fulfilling their mission, and should ensure that whistle-blowers are adequately protected, and that there is a high level of protection of information in line with Union law and best practices.

4 unchanged paragraphs

Recital 6: (6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , including the rules on international transfers of personal data, Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.

Recital 8: (8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.

Recital 14: (14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure and terminal devices used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures.

Recital 18: (18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out. That evaluation should take into account the full supply chain and the operational environment.

Change 3

ChangedRecital 21: (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.

Change 4

ChangedRecital 21 a (new): (21a) The informationInformation held by the Union entitiesinstitutions and bodies is also exchanged through the ICTinformation and communication technology (‘ICT’) environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systemssystems, whether owned and operated by a Union entityinstitution or body or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment.

Recital 24: (24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness and capabilities of a Union institution or body should be assessed before they handle and store a specified level of EUCI.

Article 1 – paragraph 1: 1. This Regulation lays down common minimum information security rules for all Union institutions and bodies.

Change 5

ChangedArticle 4 – paragraph 1: 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of the Union’s democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall atas leasta minimum address the acquisition and maintenance of security infrastructure, the vetting of third partythird-party organisations and security clearance procedures in respect of staff.

Change 6

ChangedArticle 4 – paragraph 6 – subparagraph 2: Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entitiesinstitutions and bodies shall, not later than ...[six... [six months after the date of entry into force of this Regulation], design and implement effective and appropriate training courses commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI.

Article 5 – paragraph 2 – point e a (new): (ea) ensuring the integrity, availability and resilience of processing systems and services.

Article 5 – paragraph 3 – point a a (new): (aa) the risks for the rights and freedoms of natural persons;

Change 7

ChangedArticle 5 – paragraph 3 – point f: (f) business continuity, disastercontinuity,disaster recovery and crisis management;management ;

11 unchanged paragraphs

Article 6 – paragraph 2 – introductory part: 2. Acting by a majority of at least two thirds of its members and in the common interest of all Union institutions and bodies, the Coordination Group shall:

Article 6 – paragraph 2 – point e a (new): (ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report;

Article 7 – paragraph 1 – point e a (new): (ea) a sub-group on administrative arrangements with third countries and international organisations.

Article 10 – paragraph 1 – point c a (new): (ca) strengthening cooperation and coordination with CERT-EU.

Article 11 – paragraph 4 – point d a (new): (da) end-to-end encryption, in particular when exchanging sensitive non-classified information;

Article 18 – paragraph 2: 2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. Such guidance documents shall take into account the principle of minimisation of the use of classified information as well as the risk of overclassification of certain documents. Such guidance documents shall include rules on assessing and justifying information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects.

Article 20 – paragraph 3 a (new): 3a. This Article is without prejudice to Regulation (EC) No 1049/2001.

Article 22 – paragraph 3 – point a: (a) inform the originator without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach;

Article 22 – paragraph 3 – point e: (e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach.

Article 23 – paragraph 3: 3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 are observed.

Article 32 – paragraph 1 – introductory part: 1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. The originator may consult intended recipients regarding the classification level of an EUCI document, in particular in the event of any doubt as to the confidential nature of an item of information and its appropriate level of classification, and to prevent over-classification of such a document. For the purposes of the initial dissemination of an EUCI document, the originator shall take into account the rights and obligations of information recipients arising from the Treaties. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is:

Change 8

ChangedArticle 41 – paragraph 1 – point f a (new): (fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards for reporting vulnerabilities ,vulnerabilities, as appropriate; thatappropriate, processwhich shall be complemented by regular audits and penetration tests where appropriate.

Change 9

ChangedArticle 52 – paragraph 2: 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall ensure synergy between the need to protect EUCI and Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure.

Change 10

ChangedArticle 54 – paragraph 1 – point -a (new): (-a) there is a legal obligation under Union law or an interinstitutional agreement concluded between Union institutions; or

Change 11

ChangedArticle 54 – paragraph 1 – point a: (a) there is a proven need for the exchange includingexchange, in line with the ‘need-to-know’ principle;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2025). “Changes between LIBE-PR-751547 and LIBE-PR-776837”. Text, 2 September 2025. from LIBE-PR-751547, to LIBE-PR-776837. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547/compare/LIBE-PR-776837?all=1 (retrieved 25 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2025-09-02,
  author = {{European Parliament}},
  title = {{Changes between LIBE-PR-751547 and LIBE-PR-776837}},
  year = {2025},
  date = {2025-09-02},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547/compare/LIBE-PR-776837?all=1}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-751547/compare/LIBE-PR-776837?all=1},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. from LIBE-PR-751547, to LIBE-PR-776837. Data: European Parliament Open Data (CC BY 4.0)}
}