Changes between two versions
What changed between the plenary report and the adopted text
From · plenary report· 8 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+23 added · −351 removed · 0 changed paragraphs, packaging included.
Part 5 of 7: Paragraphs 241–300
Removed:(c) ensure that the EU Cybersecurity Reserve brings EU added value, by contributing to the objectives set out in Article 3 of Regulation (EU) 2021/694, including promoting the development of cybersecurity skills in the EU, and the achievement of gender balance in the sector, and reinforcing the Union’s technological sovereignty, open strategic autonomy, competitiveness and resilience.
Removed:2. When procuring services for the EU Cybersecurity Reserve, the contracting authority shall include in the procurement documents the following selection criteria:
Removed:(a) the provider shall demonstrate that its personnel has the highest degree of professional integrity, independence, responsibility, and the requisite technical competence to perform the activities in their specific field, and ensures the permanence/continuity of expertise as well as the required technical resources;
Removed:(b) the provider, its subsidiaries and subcontractors shall have in place a framework to protect sensitive information relating to the service, and in particular evidence, findings and reports, and is compliant with Union security rules on the protection of EU classified information;
Removed:(c) the provider shall provide sufficient proof that its governing structure is transparent, not likely to compromise its impartiality and the quality of its services or to cause conflicts of interest;
Removed:(d) the provider shall have appropriate security clearance, at least for personnel intended for service deployment;
Removed:(e) the provider shall have the relevant level of security for its IT systems;
Removed:(f) the provider shall be equipped with up to date the hardware and software technical equipment necessary to support the requested service and shall, as applicable, comply with Regulation (EU) .../... of the European Parliament and of the Council (2022/0272(COD));
Removed:(g) the provider shall be able to demonstrate that it has experience in delivering similar services to relevant national authorities or entities operating in critical or highly critical sectors;
Removed:(h) the provider shall be able to provide the service within a short timeframe in the Member State(s) where it can deliver the service;
Removed:(i) the provider shall be able to provide the service in the local language of the Member State(s), or in one of the working languages of the Union’s institutions, where it can deliver the service;
Removed:(j) once an European cybersecurity certification scheme for managed security service pursuant to Regulation (EU) 2019/881 is in place, the provider shall be certified in accordance with that scheme within a period of two years after the scheme has been adopted.
Removed:(ja) the provider shall be able to provide the service independently and not as part of a bundle, thus safeguarding the user possibility to switch to another service provider;
Removed:(jb) for the purposes of Article 12(1) the provider shall include in the tenders proposal the possibility for conversion of unused incident response services into exercises or trainings;
Removed:(jc) the provider shall be established and shall have its executive management structures in the Union, in an associated country or in a third country that is part to the Government Procurement Agreement in the context of World Trade Organisation(GPA).
Removed:(jd) . The provider shall not be subject to control by a non-associated third country or by a non-associated third-country entity that is not party to the GPA or, alternatively, such an entity shall have been subject to screening within the meaning of Regulation (EU) 2019/452 and, where necessary, to mitigation measures, taking into account the objectives set out in this Regulation.
Removed:Support to third countries
Removed:1. Third countries may request support from the EU Cybersecurity Reserve where Association Agreements concluded regarding their participation in DEP provide for this.
Removed:2. Support from the EU Cybersecurity Reserve shall be in accordance with this Regulation, and shall comply with any specific conditions laid down in the Association Agreements referred to in paragraph 1.
Removed:3. Users from associated third countries eligible to receive services from the EU Cybersecurity Reserve shall include competent authorities such as CSIRTs and cyber crisis management authorities.
Removed:4. Each third country eligible for support from the EU Cybersecurity Reserve shall designate an authority to act as a single point of contact for the purpose of this Regulation.
Removed:5. Prior to receiving any support from the EU Cybersecurity Reserve, third countries shall provide to the Commission and the High Representative information about their cyber resilience and risk management capabilities, including at least information on national measures taken to prepare for significant or large-scale cybersecurity incidents, as well as information on responsible national entities, including CSIRTs or equivalent entities, their capabilities and the resources allocated to them. Where provisions of Articles 13 and 14 of this Regulation refer to Member States, they shall apply to third countries as set out in paragraph 1.
Removed:6. The Commission shall without undue delay notify the Council and coordinate with the High Representative about the requests received and the implementation of the support granted to third countries from the EU Cybersecurity Reserve.
Removed:CYBERSECURITY INCIDENT REVIEW MECHANISM
Removed:Cybersecurity Incident Review Mechanism
Removed:1. At the request of the Commission, the EU-CyCLONe or the CSIRTs network, ENISA shall review and assess threats, vulnerabilities and mitigation actions with respect to a specific significant or large-scale cybersecurity incident. Following the completion of a review and assessment of an incident, ENISA shall deliver an incident review report to the CSIRTs network, the EU-CyCLONe and the Commission to support them in carrying out their tasks, in particular in view of those set out in Articles 15 and 16 of Directive (EU) 2022/2555. Where relevant, the Commission shall share the report with the High Representative.
Removed:2. To prepare the incident review report referred to in paragraph 1, ENISA shall collaborate with and gather feedback from all relevant stakeholders, including representatives of Member States, the Commission, other relevant EU institutions, bodies, offices and agencies, managed security services providers in the National and Cross-border SOCs and users of cybersecurity services, complemented with guarantees and monitoring that is adequate to ensure that lessons learned and best practicies identified are backed by the actors in the cybersecurity services industry. Where appropriate, ENISA shall also collaborate with entities affected by significant or large-scale cybersecurity incidents. To support the review, ENISA may also consult other types of stakeholders. Consulted representatives shall disclose any potential conflict of interest.
Removed:3. The report shall cover a review and analysis of the specific significant or large-scale cybersecurity incident, including the main causes, vulnerabilities and lessons learned. It shall protect confidential information, in accordance with Union or national law concerning the protection of sensitive or classified information. It shall not include any details about actively exploited vulnerabilities that remain unpatched.
Removed:3a. The report referred to in paragraph 1 of this Article shall set out lessons learned from the peer reviews carried out pursuant to Article 19 of Directive (EU) 2022/2555.
Removed:4. Where appropriate, the report shall draw recommendations, including for all relevant stakeholders, to improve the Union’s cyber posture.
Removed:5. Where possible, a version of the report shall be made available publicly. This version shall only include public information.
Removed:FINAL PROVISIONS
Removed:Amendments to Regulation (EU) 2021/694
Removed:Regulation (EU) 2021/694 is amended as follows:
Removed:(1) Article 6 is amended as follows:
Removed:(a) paragraph 1 is amended as follows:
Removed:(i) the following point (aa) is inserted:
Removed:‘(aa) support the development of an EU Cyber Shield, including the development, deployment and operation of National and Cross-border SOCs platforms that contribute to situational awareness in the Union and to enhancing the cyber threat intelligence capacities of the Union’;
Removed:(ii) the following point (g) is added:
Removed:‘(g) establish and operate a Cybersecurity Emergency Mechanism to support Member States in preparing for and responding to significant cybersecurity incidents, complementary to national resources and capabilities and other forms of support available at Union level, including the establishment of an EU Cybersecurity Reserve’;
Removed:(b) Paragraph 2 is replaced by the following:
Removed:‘2. The actions under Specific Objective 3 shall be implemented primarily through the European Cybersecurity Industrial, technology and research Competence Centre and the Network of National Coordination Centres, in accordance with Regulation (EU) 2021/887 of the European Parliament and of the Council*with the exception of actions implementing the EU Cybersecurity Reserve, which shall be implemented by the Commission and ENISA.
Removed:_______________
Removed:* Regulation (EU) 2021/887 of the European Parliament and of the Council of 20 May 2021 establishing the European Cybersecurity Industrial, Technology and Research Competence Centre and the Network of National Coordination Centres, (OJ L 202, 8.6.2021, p. 1, ELI: http://data.europa.eu/eli/reg/2021/887/oj).’;
Removed:(2) Article 9 is amended as follows:
Removed:(a) in paragraph 2, points (b), (c) and (d) are replaced by the following:
Removed:‘(b), EUR 1 776 956 000 for Specific Objective 2 – Artificial Intelligence;
Removed:(c), EUR 1 620 566 000 for Specific Objective 3 – Cybersecurity and Trust;
Removed:(d), EUR 500 347 000 for Specific Objective 4 – Advanced Digital Skills’;
Removed:(aa) the following new paragraph 2a is inserted:
Removed:‘ (2a). The amount referred to in paragraph 2 point c shall primarily be used for achieving the operational objectives referred into art. 6 par. 1 (a-f) of the Programme.’;
Removed:(ab) the following new paragraph 2b is inserted:
Removed:‘ (2b). The amount for the establishment and implementation of the EU Cybersecurity Reserve shall not exceed EUR 27 million for the intended duration of the Regulation laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cybersecurity threats and incidents.’;
Removed:(b) the following paragraph 8 is added:
Removed:‘8. By way of derogation from Article 12(4) of Regulation (EU, Euratom) 2018/1046, unused commitment and payment appropriations for actions in the context of the implementation of the EU cybersecurity Reserve, pursuing the objectives set out in Article 6(1), point (g) of this Regulation, shall be automatically carried over and may be committed and paid up to 31 December of the following financial year.’;
Removed:The Commission shall inform the Parliament and the Council of appropriations carried over in accordance with art. 12(6) of Regulation (EU, Euratom) 2018/1046.
Removed:(3) In Article 14, paragraph 2 is replaced by the following:
Removed:“2. The Programme may provide funding in any of the forms laid down in the Regulation (EU, Euratom) 2018/1046, including in particular through procurement as a primary form, or grants and prizes.
Removed:Where the achievement of the objective of an action requires the procurement of innovative goods and services, grants may be awarded only to beneficiaries that are contracting authorities or contracting entities as defined in Directives 2014/24/EU 27 and 2014/25/EU 28 of the European Parliament and of the Council.
Removed:Where the supply of innovative goods or services that are not yet available on a large-scale commercial basis is necessary to achieve the objectives of an action, the contracting authority or the contracting entity may authorise the award of multiple contracts within the same procurement procedure.