Skip to content
EU Parl Watch

Changes between two versions

What changed between the plenary report and the adopted text

From · plenary report· 8 Dec 2023

A-9-2023-0426

on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

To · adopted text· 24 Apr 2024

TA-9-2024-0355

Cyber Solidarity Act

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+23 added · −351 removed · 0 changed paragraphs, packaging included.

Part 4 of 7: Paragraphs 181–240

Removed:CYBERSECURITY EMERGENCY MECHANISM

Removed:Establishment of the Cybersecurity Emergency Mechanism

Removed:1. A Cybersecurity Emergency Mechanism is established to improve the Union’s resilience to major cybersecurity threats and prepare for and mitigate, in a spirit of solidarity, the short-term impact of significant and large-scale cybersecurity incidents (the ‘Mechanism’).

Removed:2. Actions implementing the ▌Mechanism shall be supported by funding from DEP and implemented in accordance with Regulation (EU) 2021/694 and in particular Specific Objective 3 thereof.

Removed:Type of actions

Removed:1. The Mechanism shall support the following types of actions:

Removed:(a) preparedness actions, including the coordinated preparedness testing of entities operating in highly critical sectors across the Union;

Removed:(b) response actions, supporting response to and immediate recovery from significant and large-scale cybersecurity incidents, to be provided by trusted managed security service providers participating in the EU Cybersecurity Reserve established under Article 12;

Removed:(c) mutual assistance actions consisting of the provision of assistance from national authorities of one Member State to another Member State, in particular as provided for in Article 11(3), point (f), of Directive (EU) 2022/2555.

Removed:1a. Following the triggering of the Mechanism, the Commission shall, on an annual basis, assess and publish a report on both the positive and the negative working of the Mechanism, including whether further cooperation or training requirements are needed.

Removed:Coordinated preparedness testing of entities

Removed:1. For the purpose of supporting the coordinated preparedness testing of entities referred to in Article 10(1), point (a), across the Union, the Commission, after consulting the NIS Cooperation Group and ENISA, shall identify the sectors, or sub-sectors, concerned, from the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555 from which entities may be subject to the coordinated preparedness testing, taking into account existing and planned coordinated risk assessments and resilience testing in accordance with the arrangements established for the entities in the Sectors of High Criticality listed in Annex I to Directive (EU) 2022/2555.

Removed:2. The NIS Cooperation Group in cooperation with the Commission, ENISA, and the High Representative, and the entities that are subject to coordinated preparedness testing pursuant to paragraph 1, shall develop common risk scenarios and methodologies for the coordinated preparedness testing exercises, culminating in a concerted workplan. Entities subject to coordinated preparedness testing shall develop and implement a remediation plan that carries out the recommendations resulting from preparedness tests.

Removed:The NIS Cooperation Group may inform the prioritisation of sectors, or sub-sectors for the coordinated preparedness testing exercises.

Removed:Establishment of the EU Cybersecurity Reserve

Removed:1. An EU Cybersecurity Reserve shall be established, in order to assist users referred to in paragraph 3, in responding or providing support for responding to significant or large-scale cybersecurity incidents, and immediate recovery from such incidents.

Removed:Where it is apparent that the procured services cannot be fully used for the purposes of providing support for responding to significant or large-scale incidents, those services can exceptionally be converted to excercises or trainings for dealing with incidents, and provided to the users upon request, by the contracting authority.

Removed:2. The EU Cybersecurity Reserve shall consist of incident response services from trusted managed security service providers selected in accordance with the criteria laid down in Article 16. The EU Cybersecurity reserve shall include pre-committed services. The services shall be deployable in all Member States, shall reinforce the Union’s technological sovereignty, its open strategic autonomy, competitiveness and resilience in the cyber security sector including by boosting innovation in the Digital Single Market across the Union.

Removed:3. Users of the services from the EU Cybersecurity Reserve shall include:

Removed:(a) Member States’ cyber crisis management authorities and CSIRTs as referred to in Article 9 (1) and (2) and Article 10 of Directive (EU) 2022/2555, respectively;

Removed:(b) Union institutions, bodies and agencies as referred to in Article 3 (1) of the Regulation (EU) .../2023 of the European Parliament and of the Council and CERT-EU.

Removed:4. Users referred to in paragraph 3, point (a), shall use the services from the EU Cybersecurity Reserve in order to respond or support response to and immediate recovery from significant or large-scale incidents affecting entities operating in critical or highly critical sectors.

Removed:5. The Commission shall have overall responsibility for the implementation of the EU Cybersecurity Reserve. The Commission shall determine the priorities and evolution of the EU Cybersecurity Reserve in coordination with the NIS2 Coordination Group and, in line with the requirements of the users referred to in paragraph 3, and shall supervise its implementation, and ensure complementarity, consistency, synergies and links with other support actions under this Regulation as well as other Union actions and programmes.

Removed:6. The Commission shall entrust the operation and administration of the EU Cybersecurity Reserve, in full or in part, to ENISA, by means of contribution agreements.

Removed:7. In order to support the Commission in establishing the EU Cybersecurity Reserve, ENISA shall prepare a mapping of the services needed, including the needed skills and capacity of the cybersecurity workforce, after consulting Member States and the Commission, and where appropriate, managed security services providers, and other cybersecurity industry representatives. ENISA shall prepare a similar mapping, after consulting the Commission, managed security services providers, and where appropriate, other cybersecurity industry representatives to identify the needs of third countries eligible for support from the EU Cybersecurity Reserve pursuant to Article 17. The Commission, where relevant, shall consult the High Representative and inform the Council about the needs of third countries.

Removed:8. The Commission is empowered to adopt delegated acts, in accordance with Article 20a to supplement this Regulation by specifying the types and the number of response services required for the EU Cybersecurity Reserve. ▌..

Removed:Requests for support from the EU Cybersecurity Reserve

Removed:1. The users referred to in Article 12(3) may request services from the EU Cybersecurity Reserve to support response to and immediate recovery from significant or large-scale cybersecurity incidents.

Removed:2. To receive support from the EU Cybersecurity Reserve, the users referred to in Article 12(3) shall take measures to mitigate the effects of the incident for which the support is requested, including the provision of direct technical assistance, and other resources to assist the response to the incident, and immediate recovery efforts.

Removed:3. Requests for support from users referred to in Article 12(3), point (a), of this Regulation shall be transmitted to the Commission and ENISA via the Single Point of Contact designated or established by the Member State in accordance with Article 8(3) of Directive (EU) 2022/2555.

Removed:4. Member States shall inform the CSIRTs network, and where appropriate EU-CyCLONe, about their requests for incident response and immediate recovery support pursuant to this Article.

Removed:5. Requests for incident response and immediate recovery support shall include:

Removed:(a) appropriate information regarding the affected entity and potential impacts of the incident and the planned use of the requested support, including an indication of the estimated needs;

Removed:(b) information about measures taken to mitigate the incident for which the support is requested, as referred to in paragraph 2;

Removed:(c) information about other forms of support available to the affected entity, including contractual arrangements in place for incident response and immediate recovery services, as well as insurance contracts potentially covering such type of incident.

Removed:6. ENISA, in cooperation with the Commission and the NIS Cooperation Group, shall develop a template to facilitate the submission of requests for support from the EU Cybersecurity Reserve.

Removed:7. The Commission is empowered to adopt delegated acts, in accordance with Article 20a to supplement this Regulation by specifying further the detailed arrangements for allocating the EU Cybersecurity Reserve support services. ▌

Removed:Implementation of the support from the EU Cybersecurity Reserve

Removed:1. Requests for support from the EU Cybersecurity Reserve, shall be assessed by the Commission, with the support of ENISA or as defined in contribution agreements under Article 12(6), and a response shall be transmitted to the users referred to in Article 12(3) without undue delay and in any event within 24 hours.

Removed:2. To prioritise requests, in the case of multiple concurrent requests, the following criteria shall be taken into account, where relevant:

Removed:(a) the severity of the cybersecurity incident;

Removed:(b) the type of entity affected, with higher priority given to incidents affecting essential entities as defined in Article 3(1) of Directive (EU) 2022/2555;

Removed:(c) the potential impact on the affected Member State(s) or users;

Removed:(d) the scale and potential cross-border nature of the incident and the risk of spill over to other Member States or users;

Removed:(e) the measures taken by the user to assist the response, and immediate recovery efforts, as referred in Article 13(2) and Article 13(5), point (b).

Removed:3. The EU Cybersecurity Reserve services shall be provided in accordance with specific agreements between the service provider and the user to which the support under the EU Cybersecurity Reserve is provided. Those agreements shall include liability conditions and any other provisions the parties to the agreement deem necessary for the provision of the respective service.

Removed:4. The agreements referred to in paragraph 3 shall be based on templates prepared by ENISA, after consulting Member States and, where appropriate, other users of the EU Cybersecurity Reserve.

Removed:5. The Commission and ENISA shall bear no contractual liability for damages caused to third parties by the services provided in the framework of the implementation of the EU Cybersecurity Reserve, except in cases of gross negligence in the evaluation of the application of the service provider or in case where the Commission or ENISA are users of the EU Cybersecurity Reserve according to Article 14 (3).

Removed:6. Within one month from the end of the support action, the users shall provide Commission and ENISA CSIRTs Network and, where relevant, EU-CyCLONe with a summary report about the service provided, results achieved and the lessons learned. When the user is from a third country as set out in Article 17, such report shall be shared with the High Representative.

Removed:The report shall respect Union and national law concerning the protection of sensitive or classified information.

Removed:7. The Commission shall report on a regular basis and at least twice a year to the NIS Cooperation Group about the use and the results of the support. It shall protect confidential information, in accordance with Union and national law concerning the protection of sensitive or classified information.

Removed:Coordination with crisis management mechanisms

Removed:1. In cases where significant or large-scale cybersecurity incidents originate from or result in disasters as defined in Decision 1313/2013/EU, the support under this Regulation for responding to such incidents shall complementactions under and without prejudice to Decision 1313/2013/EU.

Removed:2. In the event of a large-scale, cross border cybersecurity incident where Integrated Political Crisis Response arrangements (IPCR) are triggered, the support under this Regulation for responding to such incident shall be handled in accordance with relevant protocols and procedures under the IPCR.

Removed:3. In consultation with the High Representative, support under theCybersecurity Emergency Mechanism may complement assistance provided in the context of the Common Foreign and Security Policy and Common Security and Defence Policy, including through the Cyber Rapid Response Teams. It may also complement or contribute to assistance provided by one Member State to another Member State in the context of Article 42(7) TFEU.

Removed:4. Support under the Cybersecurity Emergency Mechanism may form part of the joint response between the Union and Member States in situations referred to in Article 222 TFEU

Removed:Trusted providers

Removed:1. In procurement procedures for the purpose of establishing the EU Cybersecurity Reserve, the contracting authority shall act in accordance with the principles laid down in the Regulation (EU, Euratom) 2018/1046 and in accordance with the following principles:

Removed:(a) ensure the EU Cybersecurity Reserve includes services that may be deployed in all Member States, taking into account in particular national requirements for the provision of such services, including certification or accreditation;

Removed:(b) ensure the protection of the essential security interests of the Union and its Member States.