Changes between two versions
What changed between the plenary report and the adopted text
From · plenary report· 8 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+23 added · −351 removed · 0 changed paragraphs, packaging included.
Part 6 of 7: Paragraphs 301–358
Removed:For duly justified reasons of public security, the contracting authority or the contracting entity may require that the place of performance of the contract be situated within the territory of the Union.
Removed:When implementing procurement procedures for the EU Cybersecurity Reserve established by Article 12 of Regulation (EU) 2023/…, the Commission and ENISA may act as a central purchasing body to procure on behalf of or in the name of third countries associated to the Programme in line with Article 10. The Commission and ENISA may also act as wholesaler, by buying, stocking and reselling or donating supplies and services, including rentals, to those third countries. By derogation from Article 169(3) of Regulation (EU). …/…, the request from a single third country is sufficient to mandate the Commission or ENISA to act.
Removed:When implementing procurement procedures for the EU Cybersecurity Reserve established by Article 12 of Regulation (EU) 2023/…XX, the Commission and ENISA may act as a central purchasing body to procure on behalf of or in the name of Union institutions, bodies and agencies. The Commission and ENISA may also act as wholesaler, by buying, stocking and reselling or donating supplies and services, including rentals, to Union institutions, bodies and agencies. By derogation from Article 169(3) of Regulation (EU) …/…, the request from a single Union institution, body or agency is sufficient to mandate the Commission or ENISA to act.
Removed:The Programme may also provide financing in the form of financial instruments within blending operations. ’;
Removed:(4) The following article 16a is added:
Removed:‘Article 16a
Removed:In the case of actions implementing the European Cyber Shield established by Article 3 of Regulation (EU) 2023/XX, the applicable rules shall be those set out in Articles 4 and 5 of Regulation (EU) 2023/…. In the case of conflict between the provisions of this Regulation and Articles 4 and 5 of Regulation (EU) 2023/…, the latter shall prevail and apply to those specific actions.’;
Removed:(5) Article 19 is replaced by the following:
Removed:‘Grants under the Programme shall be awarded and managed in accordance with Title VIII of Regulation (EU, Euratom) 2018/1046 and may cover up to 100 % of the eligible costs, without prejudice to the co-financing principle as laid down in Article 190 of Regulation (EU, Euratom) 2018/1046. Such grants shall be awarded and managed as specified for each specific objective.
Removed:Support in the form of grants may be awarded directly by the ECCC without a call for proposals to the National SOCs referred to in Article 4 of Regulation (EU) .../... and the Hosting Consortium referred to in Article 5 of Regulation (EU) .../..., in accordance with Article 195(1), point (d) of Regulation (EU, Euratom) 2018/1046.
Removed:Support in the form of grants for the Cybersecurity Emergency Mechanism as set out in Article 10 of Regulation (EU) .../...may be awarded directly by the ECCC to Member States without a call for proposals, in accordance with Article 195(1), point (d) of Regulation (EU, Euratom) 2018/1046.
Removed:For actions specified in Article 10(1), point (c) of Regulation (EU) .../..., the ECCC shall inform the Commission and ENISA about Member States’ requests for direct grants without a call for proposals.
Removed:For the support of mutual assistance for response to a significant or large-scale cybersecurity incident as defined in Article 10(c), of Regulation (EU) .../..., and in accordance with Article 193(2), second subparagraph, point (a), of Regulation (EU, Euratom) 2018/1046, in duly justified cases, the costs may be considered to be eligible even if they were incurred before the grant application was submitted.”;
Removed:(6) Annexes I and II to Regulation (EU) 2021/694 are amended in accordance with the Annexto this Regulation.
Removed:Article19a
Removed:Additional ressources for ENISA
Removed:ENISA shall receive additional resources to carry out its additional tasks conferred on it by this Regulation. That additional support, including funding, shall not jeopardise the achievement of the objectives of other Union’s Programmes, in particular the Digital Europe Programme.
Removed:Evaluation and Review
Removed:1. By [two years from the date of application of this Regulation] and every two years thereafter, the Commission shall carry out an evaluation of the functioning of the measures laid down in this Regulation and shall submit a report to the European Parliament and to the Council.
Removed:2. The evaluation shall assess in particular:
Removed:(a) the use and added value of the Cross-Border SOCs and the extent to which they contribute to fastering the detection of and respone to cyber threats and situational awareness; the active participation of National SOCs in the European Cyber Shield, including the number of National SOCs and Cross-border SOCs established and the extent to which it has contributed to the production and exchange of high-quality actionable information and cyber threat intelligence; the number and costs of cybersecurity infrastructure, or tools, or both jointly procured; the number of cooperation agreements concluded between Cross-border SOCs and with industry ISACs; the number of incidents reported to the CSIRT network and the impact it has on the work of the CSIRT Network;
Removed:(b) both the positive and the negative working of the Cybersecurity Emergency Mechanism, including whether further cooperation or training requirements are needed;
Removed:(c) the contribution of this Regulation to reinforce the Union’s resilience and open strategic autonomy, to improve the competitiveness of the relevant industry sectors, microenterprises, SMEs including start-ups, and the development of cybersecurity skills in the Union;
Removed:(d) the use and added value of the EU Cybersecurity Reserve, including the number of trusted security providers part of the EU Cybersecurity Reserve; the number, type, costs and impact of actions carried out supporting response to cybersecurity incidents, as well as its users and providers; the mean time for the Commission to acknowledge, the EU Cybersecurity Reserve to be deployed and to respond, and the user to recover from incidents; whether the scope of the EU Cybersecurity Reserve is to be broadened to incident preparedness services or common exercises with the trusted managed securiy service providers and potential users of the EU Cybersecurity Reserve to ensure efficient functioning of the EU Cybersecurity Reserve where necessary;
Removed:(e) the contribution of this Regulation to the development and improvement of the skills and competences of the workforce in the cybersecurity sector, needed to strengthen the Union's capacity to detect, prevent, respond to and recover from cybersecurity threats and incidents;
Removed:(f) the contribution of this Regulation to the deployment and development of state-of-the-art technologies in the Union.
Removed:3. On the basis of the reports referred to in paragraph 1, the Commission shall, where appropriate, submit a legislative proposal to the European Parliament and to the Council to amend this Regulation.
Removed:Exercise of the delegation
Removed:1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.
Removed:2. The power to adopt delegated acts referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) shall be conferred on the Commission for a period of … years from … [date of entry into force of the basic legislative act or any other date set by the co-legislators]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the … year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.
Removed:3. The delegation of power referred to in Article 6(3), Article 7(2), Article 12(8) and Article 13(7) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force
Removed:4. Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.
Removed:5. As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.
Removed:6. A delegated act adopted pursuant to Article 6(3), Article 7(2), Article 12(8) or Article 13(7) shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by [two months] at the initiative of the European Parliament or of the Council.
Removed:Committee procedure
Removed:1. The Commission shall be assisted by the Digital Europe Programme Coordination Committee established by Regulation (EU) 2021/694. That committee shall be a committee within the meaning of Regulation (EU) 182/2011.
Removed:2. Where reference is made to this paragraph, Article 5 of Regulation (EU) 182/2011 shall apply.
Removed:Entry into force
Removed:This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Removed:This Regulation shall be binding in its entirety and directly applicable in all Member States.
Removed:Done at Strasbourg,
Removed:For the European Parliament For the Council
Removed:The President The President
Removed:Regulation (EU) 2021/694 is amended as follows:
Removed:In Annex I, the section/ chapter ‘Specific Objective 3 – Cybersecurity and Trust’ is replaced by the following:
Removed:‘Specific Objective 3 – Cybersecurity and Trust
Removed:The Programme shall stimulate the reinforcement, building and acquisition of essential capacities to secure the Union’s digital economy, society and democracy by reinforcing the Union cybersecurity industrial potential and competitiveness, as well as by improving capabilities of both the private and public sectors to protect citizens and businesses from cyber threats, including by supporting the implementation of Directive (EU) 2016/1148.
Removed:Initial and, where appropriate, subsequent actions under this objective shall include:
Removed:Co-investment with Member States in advanced cybersecurity equipment, infrastructures and knowhow that are essential to protect critical infrastructures and the Digital Single Market at large. Such co-investment could include investments in quantum facilities and data resources for cybersecurity, situational awareness in cyberspace including National SOCs and Cross-border SOCs forming the European Cyber Shield, as well as other tools to be made available to public and private sector across Europe.
Removed:Scaling up existing technological capacities and networking the competence centres in Member States and making sure that those capacities respond to public sector and industry needs, including through products and services that reinforce cybersecurity and trust within the Digital Single Market.
Removed:Ensuring wide deployment of effective state-of-the-art cybersecurity and trust solutions across the Member States. Such deployment includes strengthening the security and safety of products, from their design to their commercialisation.
Removed:Support closing the cybersecurity skills gap, with a particular focus on achieving gender balance in the sector by, for example, aligning cybersecurity skills programmes, adapting them to specific sectorial needs, including an interdisciplinary and general focus and facilitating access to targeted specialised training to enable all persons and territories, without prejudice to the possibility of benefiting from the opportunities provided by this Regulation.
Removed:5. Promoting solidarity among Member States in preparing for and responding to significant cybersecurity incidents through deployment of cybersecurity services across borders, including support for mutual assistance between public authorities and the establishment of a reserve of trusted managed security service providers at Union level.’;
Removed:In Annex II the section/chapter ‘Specific Objective 3 – Cybersecurity and Trust’ is replaced by the following:
Removed:‘Specific Objective 3 – Cybersecurity and Trust
Removed:The number of cybersecurity infrastructure, or tools, or both jointly procured as part of the Cybersecurity Shield.
Removed:The number of users and user communities getting access to European cybersecurity facilities
Removed:The number, type, costs and impact of actions carried out supporting preparedness and response to cybersecurity incidents under the Cybersecurity Emergency Mechanism. The extent to which recommendations of preparedness tests have been implemented and carried out by the user as well as the mean time for the Commission to acknowledge, the EU Cybersecurity Reserve to respond, and the user to recover from incidents.’