Skip to content
EU Parl Watch

Changes between two versions

What changed between the plenary report and the adopted text

From · plenary report· 8 Dec 2023

A-9-2023-0426

on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

To · adopted text· 24 Apr 2024

TA-9-2024-0355

Cyber Solidarity Act

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+23 added · −351 removed · 0 changed paragraphs, packaging included.

Part 3 of 7: Paragraphs 121–180

Removed:3. This Regulation is without prejudice to the Member States’ primary responsibility for national security, public security, and the prevention, investigation, detection and prosecution of criminal offences.

Removed:Definitions

Removed:For the purposes of this Regulation, the following definitions apply:

Removed:(-1a) ‘National Security Operations Centre’ or ‘National SOC’ means a centralised national capacity continuously gathering and analysing cyber threat intelligence information and improving the cybersecurity posture in accordance with Article 4;

Removed:(1) ‘Cross-border Security Operations Centre’ or ‘ Cross-border SOC’ means a multi-country platform, that brings together in a coordinated network structure national SOCs in accordance with Article 5;

Removed:(2) ‘public body’ means bodiesgoverned by public law as defined in Article 2(1), point (4)), of Directive 2014/24/EU of the European Parliament and the Council;

Removed:(3) ‘Hosting Consortium’ means a consortium composed of participating states, represented by National SOCs, in accordance with Article 5.;

Removed:(4) ‘entity’ means an entity as defined in Article 6, point (38), of Directive (EU) 2022/2555;

Removed:(4a) ‘critical entity’ means critical entity as defined in Article 2, point (1), of Directive (EU) 2022/2557 of the European Parliament and of the Council.

Removed:(5) ‘entities operating in critical or highly critical sectors’ means entities in the sectors listed in Annexes I and ▌II to Directive (EU) 2022/2555;

Removed:(5a) ‘incident handling’ means incident handling as defined in Article 6, point (8), of Directive (EU) 2022/2555;

Removed:(5b) ‘risk’ means risk as defined in Article 6, point (9), of Directive (EU) 2022/2555;

Removed:(6) ‘cyber threat’ means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;

Removed:(6a) ‘significant cyber threat’ means a significant cyber threat as defined in Article 6, point (11), of Directive (EU) 2022/2555;

Removed:(7) ‘significant cybersecurity incident’ means a cybersecurity incident fulfilling criteria set out in Article 23(3) of Directive (EU) 2022/2555;

Removed:(8) ‘large-scale cybersecurity incident’ means an incident as defined in Article 6, point (7), of Directive (EU)2022/2555;

Removed:(9) ‘preparedness’ means a state of readiness and capability to ensure an effective rapid response to a significant or large-scale cybersecurity incident, obtained as a result of risk assessment and monitoring actions taken in advance;

Removed:(10) ‘response’ means action in the event of a significant or large-scale cybersecurity incident, or during or after such an incident, to address its immediate and short-term adverse consequences;

Removed:(10a) ‘managed security service provider’ means a managed service provider as defined in Article 6, point (40), of Directive (EU) 2022/2555;

Removed:(11) ‘trusted managed securiy service providers’ means managed security service providers selected to be included in the EU Cybersecurity Reserve in accordance with Article 16 of this Regulation.

Removed:THE EUROPEAN CYBER SHIELD

Removed:Establishment of the European Cyber Shield

Removed:1. A network of Security Operations Centres (‘European Cyber Shield’) shall be established to develop advanced capabilities for the Union to detect, analyse and process data on cyber threats and prevent incidents in the Union. It shall consist of all National Security Operations Centres (‘National SOCs’) and Cross-border Security Operations Centres (‘Cross-border SOCs’).

Removed:Actions implementing the European Cyber Shield shall be supported by funding from the Digital Europe Programme and implemented in accordance with Regulation (EU) 2021/694 and in particular Specific Objective 3 thereof.

Removed:2. The European Cyber Shield shall:

Removed:(a) pool and share data on cyber threats and incidents from various sources through Cross-border SOCs and where relevant exchange of information with CSIRTs Network;

Removed:(b) produce high-quality, actionable information and cyber threat intelligence, through the use of state-of-the art tools, notably Artificial Intelligence and data analytics technologies;

Removed:(c) contribute to better protection and response to cyber threats, including by providing concrete recommendations to entities;

Removed:(d) contribute to faster detection of cyber threats and situational awareness across the Union;

Removed:(e) provide services and activities for the cybersecurity community in the Union, including contributing to the development of advanced artificial intelligence and data analytics tools.

Removed:It shall be developed in cooperation with the pan-European High Performance Computing infrastructure established pursuant to Regulation (EU) 2021/1173.

Removed:National Security Operations Centres

Removed:1. In order to be able to participate in the European Cyber Shield, each Member State shall designate at least one National SOC. The National SOC shall be a centralised capacity in a public body. When possible, the National SOCs shall be incorporated into the CSIRTs or other existing cybersecurity infrastructures and governance.

Removed:It shall have the capacity to act as a reference point and gateway to other public and private organisations at national level, particularly their National SOCs, for collecting and analysing information on cybersecurity threats and incidents, and, where relevant, sharing those information with members of the CSIRTs network of that Member State, and contributing to a Cross-border SOC. It shall be equipped with state-of-the-art technologies capable of preventing, detecting, aggregating, and analysing data relevant to cybersecurity threats and incidents.

Removed:A National SOC or CSIRT may request telemetry, sensor or logging data of their national critical entities from managed security service providers that provide a service to the critical entity. That data shall be shared in accordance with Union data protection law and with the sole purpose of supporting the National SOC or CSIRT to the detect and prevent cybersecurity threats and incidents.

Removed:2. Following a call for expression of interest, National SOCs may be selected by the European Cybersecurity Competence Centre (‘ECCC’) to participate in a joint procurement of tools and infrastructures with the ECCC. The ECCC may award grants to the selected National SOCs to fund the operation of those tools and infrastructures. The Union financial contribution shall cover up to 50% of the acquisition costs of the tools and infrastructures, and up to 50% of the operation costs, with the remaining costs to be covered by the Member State. Before launching the procedure for the acquisition of the tools and infrastructures, the ECCC and the National SOC shall conclude a hosting and usage agreement regulating the usage of the tools and infrastructures.

Removed:3. A National SOC selected pursuant to paragraph 2 shall commit to apply to participate in a Cross-border SOC within two years from the date on which the tools and infrastructures are acquired, or on which it receives grant funding, whichever occurs sooner. If a National SOC is not a participant in a Cross-border SOC by that time, it shall not be eligible for additional Union support under this Regulation.

Removed:Cross-border Security Operations Centres

Removed:1. A Hosting Consortium consisting of at least three Member States, represented by National SOCs, committed to working together to coordinate their cyber-detection and threat monitoring activities shall be eligible to participate in actions to establish a Cross-border SOC. A Cross-border SOC shall be designed to detect and analyse cyber threats, prevent incidents and support the production of high-quality intelligence, in particular through the exchange of data from various sources, public and private, as well as through the sharing of state-of-the-art tools and by jointly developing cyber detection, analysis, prevention and protection capabilities in a trusted and secure environment.

Removed:2. Following a call for expression of interest, a Hosting Consortium may be selected by the ECCC to participate in a joint procurement of tools and infrastructures with the ECCC. The ECCC may award to the Hosting Consortium a grant to fund the operation of the tools and infrastructures. The Union financial contribution shall cover up to 75% of the acquisition costs of the tools and infrastructures, and up to 50% of the operation costs, with the remaining costs to be covered by the Hosting Consortium. Before launching the procedure for the acquisition of the tools and infrastructures, the ECCC and the Hosting Consortium shall conclude a hosting and usage agreement regulating the usage of the tools and infrastructures.

Removed:2a. By way of derogation from Article 176 of Regulation (EU, Euratom) 2018/1046, entities established in third countries that are not parties to the GPA shall not participate in the joint procurement of tools and infrastructures.

Removed:3. Members of the Hosting Consortium shall conclude a written consortium agreement which sets out their internal arrangements for implementing the hosting and usage Agreement.

Removed:4. A Cross-border SOC shall be represented for legal purposes by a National SOC acting as coordinating SOC, or by the Hosing Consortium if it has legal personality. The co-ordinating SOC shall be responsible for compliance with the requirements of the hosting and usage agreement and of this Regulation.

Removed:Cooperation and information sharing within and between Cross-border SOCs

Removed:1. Members of a Hosting Consortium shall exchange relevant information among themselves within the Cross-border SOC including information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, threat-actor-specific information, cybersecurity alerts and recommendations regarding the configuration of cybersecurity tools to detect cyber attacks, where such information sharing:

Removed:(a) improves the exchange of cyber threat intelligence between National and Cross-border SOCs and industry ISACs with the aim to prevent, detect, or mitigate threats;

Removed:(b) enhances the level of cybersecurity, in particular through raising awareness in relation to cyber threats, limiting or impeding the ability of such threats to spread, supporting a range of defensive capabilities, vulnerability remediation and disclosure, threat detection, containment and prevention techniques, mitigation strategies, or response and recovery stages or promoting collaborative threat research between public and private entities.

Removed:2. The written consortium agreement referred to in Article 5(3) shall establish:

Removed:(a) a commitment to share a significant ▌.data referred to in paragraph 1, and the conditions under which that information is to be exchanged;

Removed:(b) a governance framework incentivising the sharing of information by all participants;

Removed:(c) targets for contribution to the development of advanced artificial intelligence and data analytics tools.

Removed:3. To encourage exchange of information among Cross-border SOCs and with industry ISACs, Cross-border SOCs shall ensure a high level of interoperability between themselves and, where possible, with industry ISACs. To facilitate the interoperability between the Cross-border SOCsand with industry ISACs, information sharing standards and protocols may be harmonised with international standards and industry best practices. The joint procurement of cyber infrastructures, services and tools shall also be encouraged. Moreover, after consulting the ECCC and ENISA, the Commission is empowered, by... [six months from the date of entry into force of this Regulation] to adopt delegated acts in accordance with Article 20a to supplement this Regulation, by specifying the conditions for this interoperability in close coordination with the Cross-border SOCs and on the basis of international standards and industry best practices.

Removed:4. Cross-border SOCs shall conclude cooperation agreements with one another and with, where appropriate, industry ISACs,, specifying information sharing and interoperability principles among the cross-border platforms, taking into consideration existing relevant information sharing mechanisms provided for in Directive (EU) 2022/2555. Where appropriate, Cross-border SOCs shall conclude cooperation agreements with industry ISACs. In the context of a potential or ongoing large-scale cybersecurity incident, information sharing mechanisms shall comply with the relevant provisions of the Directive (EU) 2022/2555.

Removed:Cooperation and information sharing with the CSIRT network

Removed:1. Where the Cross-border SOCs obtain information relating to a potential or ongoing large-scale cybersecurity incident for the purpose of shared situation awareness, the coordinating SOC shall provide the relevant information to its CSIRT or competent authority, which will report this to the EU-CyCLONe, the CSIRTs network and the Commission and ENISA, in line withtheir respective crisis management roles and procedures in accordance with Directive (EU) 2022/2555 without undue delay. This paragraph shall not impose further obligations on public or private entities to communicate a potential or ongoing large-scale cybersecurity incident for the fulfilment of the obligations laid down in the Directive (EU) 2022/2555.

Removed:2. The Commission is empowered to adopt delegated acts in accordance with Article 20a after consulting the CSIRT network to supplement this Regulation by determining the procedural arrangements for the information sharing provided for in paragraphs 1 of this Article and in accordance with Directive (EU) 2022/2555..

Removed:Security

Removed:1. Member States participating in the European Cyber Shield shall ensure a high level of confidentiality and data security and physical security of the European Cyber Shield infrastructure, and shall ensure that the infrastructure shall be adequately managed and controlled in such a way as to protect it from threats and to ensure its security and that of the systems, including that of data exchanged through the infrastructure.

Removed:2. Member States participating in the European Cyber Shield shall ensure that the sharing of information within the European Cyber Shield with entities which are not Member State public bodies does not negatively affect the security interests of the Union.

Removed:3. The Commission may adopt implementing acts laying down technical requirements for Member States to comply with their obligation under paragraph 1 and 2. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 21(2) of this Regulation. They shall comply with Directives (EU) 2022/2555 and (EU) 2022/2557 . In its implementing acts, the Commission, supported by the High Representative, shall take into account relevant defence-level security standards, in order to facilitate cooperation with military actors.