Skip to content
EU Parl Watch

Changes between two versions

What changed between the plenary report and the adopted text

From · plenary report· 27 Jul 2023

A-9-2023-0253

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

To · adopted text· 12 Mar 2024

TA-9-2024-0130

Cyber Resilience Act

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+13 added · −868 removed · 0 changed paragraphs, packaging included.

Part 14 of 17: Paragraphs 723–782

Removed:14. Mobile device management software;

Removed:15. Physical and virtual network interfaces;

Removed:16. Operating systems not covered by class II;

Removed:17. Firewalls, intrusion detection and/or prevention systems not covered by class II;

Removed:19. General purpose microprocessors and microprocessors not covered by class II;

Removed:20. Microcontrollers;

Removed:21. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) intended for the use by essential entities of the type referred to in Article 3 of Directive(EU) 2022/2555;

Removed:22. Industrial Automation & Control Systems (IACS) not covered by class II, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC), industrial robots and their control systems and supervisory control and data acquisition systems (SCADA);

Removed:23. Industrial Internet of Things not covered by class II;

Removed:23a. Home automation systems, including smart home servers and virtual assistants;

Removed:23b. Security devices, including smart door locks, cameras and alarm systems;

Removed:23c. Smart toys;

Removed:23d. Personal health appliances and wearables.

Removed:Class II

Removed:1. Operating systems for servers, desktops, and mobile devices;

Removed:2. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments;

Removed:3. Public key infrastructure and digital certificate issuers;

Removed:4. Firewalls, intrusion detection and/or prevention systems intended for industrial use;

Removed:▌

Removed:6. Microprocessors intended for integration in programmable logic controllers and secure elements;

Removed:7. Routers, modems intended for the connection to the internet, and switches ▌;

Removed:8. Secure elements;

Removed:9. Hardware Security Modules (HSMs);

Removed:10. Secure cryptoprocessors;

Removed:11. Smartcards, smartcard readers and tokens;

Removed:12. Industrial Automation & Control Systems (IACS) intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC) and supervisory control and data acquisition systems (SCADA);

Removed:13. Industrial Internet of Things devices intended for the use by essential entities of the type referred to in Article 3 of Directive (EU) 2022/2555;

Removed:▌

Removed:15. Smart meters.

Removed:EU DECLARATION OF CONFORMITY

Removed:The EU declaration of conformity referred to in Article 20, shall contain all of the following information:

Removed:1. Name and type and any additional information enabling the unique identification of the product with digital elements;

Removed:2. Name and address of the manufacturer or his authorised representative;

Removed:3. A statement that the EU declaration of conformity is issued under the sole responsibility of the provider;

Removed:4. Object of the declaration (identification of the product allowing traceability. It may include a photograph, where appropriate);

Removed:5. A statement that the object of the declaration described above is in conformity with the relevant Union harmonisation legislation;

Removed:6. References to any relevant harmonised standards used or any other common specification or cybersecurity certification in relation to which conformity is declared;

Removed:7. Where applicable, the name and number of the notified body, a description of the conformity assessment procedure performed and identification of the certificate issued;

Removed:8. Additional information:

Removed:Signed for and on behalf of: …………………………………

Removed:(place and date of issue):

Removed:(name, function) (signature):

Removed:CONTENTS OF THE TECHNICAL DOCUMENTATION

Removed:The technical documentation referred to in Article 23 shall contain at least the following information, as applicable to the relevant product with digital elements:

Removed:1. a general description of the product with digital elements, including:

Removed:(a) its intended purpose;

Removed:(b) versions of software affecting compliance with essential requirements;

Removed:(c) where the product with digital elements is a hardware product, photographs or illustrations showing external features, marking and internal layout;

Removed:(d) user information and instructions as set out in Annex II;

Removed:2. a description of the design, development and production of the product and vulnerability handling processes, including:

Removed:(a) complete information on the design and development of the product with digital elements, including, where applicable, drawings and schemes and/or a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing;

Removed:(b) complete information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities and a description of the technical solutions chosen for the secure distribution of updates;

Removed:(c) complete information and specifications of the production and monitoring processes of the product with digital elements and the validation of these processes.

Removed:3. an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained as laid down in Article 10 of this Regulation, including how the essential requirements set out in Annex I, Section 1, are applicable;

Removed:4. a list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union, common specifications as set out in Article 19 of this Regulation or cybersecurity certification schemes under Regulation (EU) 2019/881 pursuant to Article 18(3), and, where those harmonised standards, common specifications or cybersecurity certification schemes have not been applied, descriptions of the solutions adopted to meet the essential requirements set out in Sections 1 and 2 of Annex I, including a list of other relevant technical specifications applied. In the event of partly applied harmonised standards, common specifications or cybersecurity certifications, the technical documentation shall specify the parts which have been applied;

Removed:5. reports of the tests carried out to verify the conformity of the product and of the vulnerability handling processes with the applicable essential requirements as set out in Sections 1 and 2 of Annex I;

Removed:6. a copy of the EU declaration of conformity;

Removed:7. where applicable, the software bill of materials as defined in Article 3, point (36), further to a reasoned request from a market surveillance authority provided that it is necessary in order for this authority to be able to check compliance with the essential requirements set out in Annex I.

Removed:CONFORMITY ASSESSMENT PROCEDURES

Removed:Conformity Assessment procedure based on internal control (based on Module A)