Skip to content

Text · Report parliamentary committee draft

On the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Document LIBE-PR-776837 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)

Kind
Report parliamentary committee draft LIBE-PR-776837
Date
2 September 2025
Committee
Committee on Civil Liberties, Justice and Home Affairs
Rapporteur
Lena Düpont
Dossier
2022-0084
More facts (3)
Subject matter
PDON, INST, INFO
Reference
COM(2022)0119 – C90121/2022 – 2022/0084(COD)
More

In short

A summary of the text written by AI; ¶ opens the paragraph it rests on.

AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026

This is the rapporteur's draft report on the Commission proposal for a regulation on information security in the EU institutions, bodies, offices and agencies. It adopts Parliament's position at first reading and tables amendments to the proposal. The amendments add common minimum rules, require institutions to safeguard the integrity of democratic processes and curb foreign interference in tender procedures, and set training duties. They require the Coordination Group to adopt guidance on EUCI creation and classification that minimises classification and avoids overclassification, and to monitor compliance through a yearly evaluation report. They set deadlines for informing the originator and notifying competent authorities of breaches, and add end-to-end encryption and vulnerability reporting.

Position. The rapporteur proposes that Parliament adopt its position at first reading with amendments to the Commission proposal, adding common minimum rules, transparency and minimisation safeguards for classification, breach notification deadlines, and training and monitoring duties.

Key points

  1. Parliament adopts its position at first reading on the proposed regulation on information security in the Union's institutions, bodies, offices and agencies.
  2. The regulation would lay down common minimum information security rules for all Union institutions and bodies.
  3. Institutions and bodies must safeguard the integrity of the Union's democratic processes and adopt specific provisions in tender procedures to curb the risk of foreign interference, covering security infrastructure, vetting of third-party organisations and security clearance of staff.
  4. Institutions and bodies handling and storing EUCI must organise mandatory training at least once every 5 years, and design and implement training courses not later than six months after entry into force.
  5. Risk management must cover the integrity, availability and resilience of processing systems and services, the risks for the rights and freedoms of natural persons, and business continuity, disaster recovery and crisis management.
  6. The Coordination Group acts by a majority of at least two thirds of its members and must monitor compliance by institutions and bodies through a yearly evaluation report.
  7. A sub-group on administrative arrangements with third countries and international organisations is added, and cooperation and coordination with CERT-EU is strengthened.
  8. End-to-end encryption must be used, in particular when exchanging sensitive non-classified information.
  9. Guidance documents on EUCI creation and classification must take account of minimisation of classification and the risk of overclassification, and include rules on assessing and justifying classification to increase transparency and avoid unjustified lock-in effects.
  10. The originator must be informed, and competent authorities notified, of a breach without undue delay and not later than one week after the Security Authority has been informed.
  11. Institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement, while ensuring the principles on clearances are observed.
  12. The originator may consult intended recipients on the classification level to prevent overclassification, and must take into account recipients' rights and obligations under the Treaties for initial dissemination.

Who is affected

  • All Union institutions and bodies, which must apply common minimum information security rules and safeguard democratic processes.
  • Staff authorised to access EUCI, who must undergo mandatory training at least once every 5 years.
  • The Coordination Group, which acts by a two-thirds majority and monitors compliance through a yearly evaluation report.
  • Third countries and international organisations with a security of information agreement with the Union, whose security clearances may be accepted.

Figures and deadlines

  • at least once every 5 years — mandatory training for individuals authorised to access EUCI
  • not later than ... [six months after the date of entry into force of this Regulation] — deadline to design and implement training courses
  • a majority of at least two thirds of its members — voting rule for the Coordination Group
  • not later than one week after the Security Authority has been informed of the breach — deadline to inform the originator
  • not later than one week after the Security Authority has been informed of the breach — deadline to notify competent authorities

Legal basis. Article 294(2) and Article 298 of the Treaty on the Functioning of the European Union, and Article 106a of the Treaty establishing the European Atomic Energy Community

Read the text · Report a problem

Text

The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.

Jump to an amendment (33)

Draft european parliament legislative resolution

(COM(2022)0119 – C90121/2022 – 2022/0084(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

–having regard to the Commission proposal to Parliament and the Council (COM(2022)0119),

–having regard to Article 294(2) and Article 298 of the Treaty on the Functioning of the European Union, as well as Article 106a of the Treaty establishing the European Atomic Energy Community, pursuant to which the Commission submitted the proposal to Parliament (C90121/2022),

–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

–having regard to Rule 60 of its Rules of Procedure,

–having regard to the opinion of the Committee on Industry, Research and Energy,

–having regard to the letters from the Committee on Foreign Affairs, the Committee on International Trade and the Committee on Constitutional Affairs,

–having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A100000/2025),

1.Adopts its position at first reading hereinafter set out;

2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

3.Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Amendment 1

Proposal for a regulation

Recital 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected.(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected as well as the interoperability of such tools.

Or. en

Amendment 2

Proposal for a regulation

Recital 1 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(1a) Union institutions and bodies are obliged to apply Article 15(3) of the Treaty on the Functioning of the European Union(‘TFEU’) in line with democratic principles, in particular those laid down in Article 10(3) of the Treaty on European Union (‘TEU’) and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’). Therefore, the creation and classification of European Union classified information (EUCI) should take place in line with the principles of minimisation of the use of classification and limiting in time the duration of such a classification.

Or. en

Amendment 3

Proposal for a regulation

Recital 3 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(3a) In the context of information security, Union institutions and bodies should increase organisational interoperability and act together to ensure that networks, information systems, data and the equipment and material assets employed to capture, store, process and transmit the information are protected.

Or. en

Amendment 4

Proposal for a regulation

Recital 4

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(4) The recent pandemic caused a significant change in working practices with remote communication tools becoming the rule. Therefore, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.(4) In recent years, many procedures that were still at least partly paper-based were rapidly adjusted to enable electronic processing and exchanges of information. These developments require changes in the handling and protection of information. This Regulation takes account of the new working practices.

Or. en

Amendment 5

Proposal for a regulation

Recital 5 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(5a) Sharing EUCI in a transparent and timely manner is of key importance for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union institutions and bodies from fulfilling their mission, and should ensure that whistle-blowers are adequately protected, and that there is a high level of protection of information in line with Union law and best practices.

Or. en

Amendment 6

Proposal for a regulation

Recital 6

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.(6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , including the rules on international transfers of personal data, Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.
17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).
18 OJ 45, 14.6.1962, p. 1385.18 OJ 45, 14.6.1962, p. 1385.
19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).
20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).
21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1).21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1).
22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1).22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1).
23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149).23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149).
24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted

Or. en

Amendment 7

Proposal for a regulation

Recital 8

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.(8) With a view to establishing a formal common structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.

Or. en

Amendment 8

Proposal for a regulation

Recital 14

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures.(14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure and terminal devices used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures.

Or. en

Amendment 9

Proposal for a regulation

Recital 18

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites.(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out. That evaluation should take into account the full supply chain and the operational environment.

Or. en

Amendment 10

Proposal for a regulation

Recital 21

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.(21) Union institutions and bodies have traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.

Or. en

Amendment 11

Proposal for a regulation

Recital 21 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(21a) Information held by Union institutions and bodies is also exchanged through the information and communication technology (‘ICT’) environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systems, whether owned and operated by a Union institution or body or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment.

Or. en

Amendment 12

Proposal for a regulation

Recital 24

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness of a Union institution or body should be assessed before they handle and store a specified level of EUCI.(24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness and capabilities of a Union institution or body should be assessed before they handle and store a specified level of EUCI.

Or. en

Amendment 13

Proposal for a regulation

Article 1 – paragraph 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1. This Regulation lays down information security rules for all Union institutions and bodies.1. This Regulation lays down common minimum information security rules for all Union institutions and bodies.

Or. en

Amendment 14

Proposal for a regulation

Article 4 – paragraph 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process.1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of the Union’s democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall as a minimum address the acquisition and maintenance of security infrastructure, the vetting of third-party organisations and security clearance procedures in respect of staff.

Or. en

Amendment 15

Proposal for a regulation

Article 4 – paragraph 6 – subparagraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks.Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union institutions and bodies shall, not later than ... [six months after the date of entry into force of this Regulation], design and implement effective and appropriate training courses commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI.

Or. en

Amendment 16

Proposal for a regulation

Article 5 – paragraph 2 – point e a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ea) ensuring the integrity, availability and resilience of processing systems and services.

Or. en

Amendment 17

Proposal for a regulation

Article 5 – paragraph 3 – point a a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(aa) the risks for the rights and freedoms of natural persons;

Or. en

Amendment 18

Proposal for a regulation

Article 5 – paragraph 3 – point f

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(f) business continuity and disaster recovery;(f) business continuity,disaster recovery and crisis management ;

Or. en

Amendment 19

Proposal for a regulation

Article 6 – paragraph 2 – introductory part

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. Acting by consent and in the common interest of all Union institutions and bodies, the Coordination Group shall:2. Acting by a majority of at least two thirds of its members and in the common interest of all Union institutions and bodies, the Coordination Group shall:

Or. en

Amendment 20

Proposal for a regulation

Article 6 – paragraph 2 – point e a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ea) monitor compliance by Union institutions and bodies with this Regulation as well as with the guidance documents established pursuant to point (c) through the adoption of a yearly evaluation report;

Or. en

Amendment 21

Proposal for a regulation

Article 7 – paragraph 1 – point e a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ea) a sub-group on administrative arrangements with third countries and international organisations.

Or. en

Amendment 22

Proposal for a regulation

Article 10 – paragraph 1 – point c a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ca) strengthening cooperation and coordination with CERT-EU.

Or. en

Amendment 23

Proposal for a regulation

Article 11 – paragraph 4 – point d a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(da) end-to-end encryption, in particular when exchanging sensitive non-classified information;

Or. en

Amendment 24

Proposal for a regulation

Article 18 – paragraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. The Coordination Group shall adopt guidance documents on EUCI creation and classification.2. The Coordination Group shall adopt guidance documents on EUCI creation and classification. Such guidance documents shall take into account the principle of minimisation of the use of classified information as well as the risk of overclassification of certain documents. Such guidance documents shall include rules on assessing and justifying information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects.

Or. en

Amendment 25

Proposal for a regulation

Article 20 – paragraph 3 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
3a. This Article is without prejudice to Regulation (EC) No 1049/2001.

Or. en

Amendment 26

Proposal for a regulation

Article 22 – paragraph 3 – point a

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(a) inform the originator;(a) inform the originator without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach;

Or. en

Amendment 27

Proposal for a regulation

Article 22 – paragraph 3 – point e

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(e) notify the competent authorities about the actual or potential compromise and the action taken.(e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach.

Or. en

Amendment 28

Proposal for a regulation

Article 23 – paragraph 3

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement.3. Union institutions and bodies may accept security clearances from third countries and international organisations with which the Union has a security of information agreement. They shall in any event ensure that the principles under paragraphs 1 and 2 are observed.

Or. en

Amendment 29

Proposal for a regulation

Article 32 – paragraph 1 – introductory part

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is:1. The Union institution or body under whose authority an EUCI document is created shall have originator control over that document. The originator shall determine the classification level of the document and shall be responsible for its initial dissemination. The originator may consult intended recipients regarding the classification level of an EUCI document, in particular in the event of any doubt as to the confidential nature of an item of information and its appropriate level of classification, and to prevent over-classification of such a document. For the purposes of the initial dissemination of an EUCI document, the originator shall take into account the rights and obligations of information recipients arising from the Treaties. Without prejudice to Regulation 1049/2001, the originator’s prior written consent shall be obtained before the information is:

Or. en

Amendment 30

Proposal for a regulation

Article 41 – paragraph 1 – point f a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards for reporting vulnerabilities, as appropriate, which shall be complemented by regular audits and penetration tests where appropriate.

Or. en

Amendment 31

Proposal for a regulation

Article 52 – paragraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus.2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall ensure synergy between the need to protect EUCI and Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure.

Or. en

Amendment 32

Proposal for a regulation

Article 54 – paragraph 1 – point -a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(-a) there is a legal obligation under Union law or an interinstitutional agreement concluded between Union institutions;

Or. en

Amendment 33

Proposal for a regulation

Article 54 – paragraph 1 – point a

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(a) there is a proven need for the exchange;(a) there is a proven need for the exchange, in line with the ‘need-to-know’ principle;

Or. en

Connections

The dossier, the decisions on this text and its other versions.

No connections found for this item.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2025). “DRAFT REPORT on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 2 September 2025. docId LIBE-PR-776837. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-776837 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/LIBE-PR-776837 (CC BY 4.0).
BibTeX
@misc{epw-text-libe-pr-776837,
  author = {{European Parliament}},
  title = {{DRAFT REPORT on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
  year = {2025},
  date = {2025-09-02},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-776837}},
  url = {https://news.eu-parl.st-solutions.dev/texts/LIBE-PR-776837},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. docId LIBE-PR-776837. Data: EP Open Data API: document record (CC BY 4.0)}
}