Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 31 Mar 2023

ITRE-PR-745538

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

To · plenary report· 27 Jul 2023

A-9-2023-0253

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+850 added · −171 removed · 3 changed paragraphs, packaging included.

Part 19 of 20: Paragraphs 1022–1037

Added:4.3. The notified body shall carry out periodic audits to make sure that the manufacturer maintains and applies the quality system and shall provide the manufacturer with an audit report.

Added:5. Conformity marking and declaration of conformity

Added:5.1. The manufacturer shall affix the CE marking, and, under the responsibility of the notified body referred to in point 3.1, the latter's identification number to each individual product that satisfies the requirements set out in Section 1 of Annex I to this Regulation.

Added:5.2. The manufacturer shall draw up a written declaration of conformity for each product model and keep it at the disposal of the national authorities for 10 years after the product has been placed on the market or for the support period. The declaration of conformity shall identify the product model for which it has been drawn up.

Added:A copy of the declaration of conformity shall be made available to the relevant authorities upon request.

Added:6. The manufacturer shall, for a period ending at least 10 years after the product has been placed on the market or for the support period or the period during which vulnerabilities are handled, keep at the disposal of the national authorities:

Added:– the technical documentation referred to in point 3.1;

Added:– the documentation concerning the quality system referred to in point 3.1;

Added:– the change referred to in point 3.5, as approved;

Added:– the decisions and reports of the notified body referred to in points 3.5, 4.3 and 4.4.

Added:7. Each notified body shall inform its notifying authorities of quality system approvals issued or withdrawn, and shall, periodically or upon request, make available to its notifying authorities the list of quality system approvals refused, suspended or otherwise restricted.

Added:Each notified body shall inform the other notified bodies of quality system approvals which it has refused, suspended or withdrawn, and, upon request, of quality system approvals which it has issued.

Added:8. Authorised representative

Added:The manufacturer's obligations set out in points 3.1, 3.5, 5 and 6 may be fulfilled by his authorised representative, on his behalf and under his responsibility, provided that they are specified in the mandate.

Added:CAPACITY NEEDS OF THE EUROPEAN UNION AGENCY FOR CYBERSECURITY (ENISA)

Added:In order to fulfil its obligations under this Regulation and in order not to compromise existing obligations of the Agency under other Union law, the adequate staffing and financing of ENISA shall be ensured. Therefore additional tasks for ENISA under this Regulation shall be accompanied by additional human and financial resources. Nine additional full-time equivalent and corresponding additional appropriations will be needed to cover the additional tasks under this Regulation.