Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 31 Mar 2023

ITRE-PR-745538

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

To · plenary report· 27 Jul 2023

A-9-2023-0253

on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+850 added · −171 removed · 3 changed paragraphs, packaging included.

Part 6 of 20: Paragraphs 242–301

Removed:This horizontal regulation presents a high degree of complexity, particularly for SMEs. The Commission should ensure comprehensive support to undertakings, including by providing them with guidelines and guidance on how to apply this Regulation.

Added:(69a) This Regulation will generate additional costs for microenterprises and small and medium-sized enterprises, including start-ups. In order to support these enterprises, the Commission should establish financial and technical support that enable these enterprises to contribute to the growth of the European economy and the European cybersecurity landscape, including by streamlining the financial support from the Digital Europe Programme and other relevant Union programmes as well as supporting companies and public sector organisations through European Digital Innovation Hubs. Furthermore, Member States should consider all possible complementary actions aiming to providing guidance and support for microenterprises and for small and medium-sized enterprises, including via the establishment of regulatory sandboxes, cybersecurity hubs and start-up accelerators.

Removed:Article 19 – paragraph 1: 1. The Commission is empowered to adopt delegated acts in accordance with Article 50 to establish common specifications that cover technical requirements providing a means to comply with the requirements set out in Annex I for products within the scope of this Regulation where the following conditions have been fulfilled: / (a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the essential requirements set out in Annex I and the request has not been accepted or the European standardisation deliverables addressing that request is not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012 or European standardisation deliverables do not comply with the request; and / (b) no reference to harmonised standards covering the relevant essential requirements set out in Annex I is published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 and no such reference is expected to be published within a reasonable period. / 2. Before preparing the delegated act, the Commission shall inform the Expert Group that it considers that the conditions in paragraph 1 are fulfilled. In preparing the delegated acts, the Commission shall take into account the opinions of the Expert Group. / 3. Where a harmonised standard is adopted by a European standardisation organisation and proposed to the …

Added:(70) Since the objective of this Regulation cannot be sufficiently achieved by the Member States but can rather, by reason of the effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.

Removed:Common specifications should only be a last-resort option for the Commission. The text is broadly in alignment with the new General Product Safety Regulation.

Added:(71) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and delivered its opinion on 9 November 2022.

Removed:Article 20 – paragraph 2: 2. The EU declaration of conformity shall have the model structure set out in Annex IV and shall contain the elements specified in the relevant conformity assessment procedures set out in Annex VI. Such a declaration shall be continuously updated. It shall be made available in a language which can be easily understood by the authorities of the Member State in which the product with digital elements is placed on the market or made available.

Added:(71a) The Commission should amend the legislative financial statement accompanying this Regulation by providing ENISA with nine additional full-time equivalent and corresponding additional appropriations in order to fulfil its additional tasks provided for in this Regulation,

Removed:It should be avoided that manufacturers of products with digital elements that often have a cross-border dimension are expected to prepare the declaration in 24 different languages.

Added:HAVE ADOPTED THIS REGULATION:

Removed:Article 23 – paragraph 2: 2. The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, during the expected product lifetime.

Added:GENERAL PROVISIONS

Removed:Alignment with the new definition of expected product lifetime.

Added:This Regulation lays down:

Removed:Article 23 – paragraph 5: 5. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation by the elements to be included in the technical documentation set out in Annex V to take account of technological developments, as well as developments encountered in the implementation process of this Regulation. The Commission shall ensure that the administrative burden on micro, small and medium sized enterprises is kept to a minimum.

Added:(a) rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;

Removed:Article 24 – paragraph 2 a (new): 2a. Harmonised standards, common specifications or European cybersecurity certification schemes shall be in place for six months before the conformity assessment procedure referred to in paragraph 2 applies. In the six months prior to the application of paragraph 2, or where, due to a cause clearly attributable to the Commission, harmonised standards, common specifications or European cybersecurity certification schemes do not exist, manufacturers shall demonstrate the conformity of the critical product with digital elements of Class I as set out in Annex III via the procedure referred to in paragraph 1.

Added:(b) essential requirements for the design, development and production of products with digital elements, and obligations for economic operators in relation to these products with respect to cybersecurity;

Removed:Manufacturers of critical products of class I should not be penalised by the lack of harmonised standards, also in order to avoid an excessive recourse to third party conformity assessments, which could create bottlenecks and delay innovation. If harmonised standards, common specifications or European cybersecurity certification schemes are not available, or in the six months following their adoption, manufacturers may be able to demonstrate compliance with this Regulation via the self-assessment procedure.

Added:(c) essential requirements for the vulnerability handling processes put in place by manufacturers to ensure the cybersecurity of products with digital elements during the whole life cycle, and obligations for economic operators in relation to these processes;

Removed:Article 24 – paragraph 5: 5. Notified bodies shall take into account the specific interests and needs of micro, small and medium sized enterprises when setting the fees for conformity assessment procedures and reduce those fees proportionately to their specific interests and needs. The Commission shall ensure appropriate financial support in the regulatory framework of existing Union programmes, in particular in order to ease the burden on micro, small and medium-sized enterprises.

Added:(d) rules on market monitoring, surveillance and enforcement of the above-mentioned rules and requirements.

Removed:It is key that the Commission puts in place financial support, to ease the compliance with this Regulation, particularly, for micro and SMEs.

Added:1. This Regulation applies to products with digital elements made available on the market that can have a direct or indirect ▌data connection to a device or network.

Removed:Article 24 a (new): Article 24a / Mutual recognition agreements / 1. In order to promote international trade, the Commission shall endeavour to conclude Mutual Recognition Agreements (MRAs) with like-minded third countries. MRAs shall be established only between the Union and third countries that are on a comparable level of technical development and have a compatible approach concerning conformity assessment. They shall ensure the same level of protection as that provided for by this Regulation. / 2. The Commission shall assess international standards and evaluate whether they provide the same level of protection as the one provided for by this Regulation, with the aim to simplify the development of harmonised European standards.

Added:2. This Regulation does not apply to products with digital elements to which the following Union legislative acts apply:

Removed:Article 29 – paragraph 7 a (new): 7a. Member States and the Commission shall put in place appropriate measures to ensure sufficient availability of skilled professionals, in order to minimise bottlenecks in the activities of conformity assessment bodies.

Added:(a) Regulation (EU) 2017/745;

Removed:Article 29 – paragraph 12: 12. Conformity assessment bodies shall operate in accordance with a set of consistent, fair and reasonable terms and conditions, in particular taking into account the interests of micro, small and medium-sized enterprises in relation to fees.

Added:(b) Regulation (EU) 2017/746;

Removed:Article 41 – paragraph 6: 6. Member States shall ensure that the designated market surveillance authorities are provided with adequate financial resources and skilled personnel to fulfil their tasks under this Regulation.

Added:(c) Regulation (EU) 2019/2144.

Removed:Article 41 – paragraph 9 a (new): 9a. Market surveillance authorities shall provide the Commission with data about the average expected product lifetime set by the manufacturers, disaggregated per category of product with digital elements. The Commission shall publish that information in a publicly accessible and user-friendly database.

Added:3. This Regulation does not apply to products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139.

Removed:Article 45 – paragraph 1: 1. Where the Commission has sufficient reasons to consider, including based on information provided by ENISA, that a product with digital elements that presents a significant cybersecurity risk is non-compliant with the requirements laid down in this Regulation, it shall request the relevant market surveillance authorities to carry out an evaluation of compliance and follow the procedures referred to in Article 43.

Added:3a. This Regulation applies to free and open-source software only where such software is made available on the market in the course of a commercial activity.

Removed:Article 45 – paragraph 2: 2. In exceptional circumstances which justify an immediate intervention to preserve the good functioning of the internal market and where the Commission has sufficient reasons to consider that the product referred to in paragraph 1 remains non-compliant with the requirements laid down in this Regulation and no effective measures have been taken by the relevant market surveillance authorities, the Commission shall request ENISA to carry out an evaluation of compliance. The Commission shall inform the relevant market surveillance authorities accordingly. The relevant economic operators shall cooperate as necessary with ENISA.

Added:4. The application of this Regulation to products with digital elements covered by other Union rules laying down requirements that address all or some of the risks covered by the essential requirements set out in Annex I may be limited or excluded, where:

Removed:Article 48 – paragraph 1: 1. Market surveillance authorities shall carry out joint activities aimed at ensuring cybersecurity and protection of consumers with respect to specific products with digital elements placed or made available on the market, in particular products that are often found to present cybersecurity risks.

Added:(a) such limitation or exclusion is consistent with the overall regulatory framework applying to those products; and

Removed:Article 48 – paragraph 2: 2. The Commission or ENISA shall propose joint activities for checking compliance with this Regulation to be conducted by market surveillance authorities based on indications or information of potential non-compliance across several Member States of products falling in the scope of this Regulation with the requirements laid down by the latter.

Added:(b) the sectoral rules achieve the same level of protection as the one provided for by this Regulation.

Removed:Article 49 – paragraph 1: 1. Market surveillance authorities shall regularly conduct simultaneous coordinated control actions (“sweeps”) of particular products with digital elements or categories thereof to check compliance with or to detect infringements to this Regulation. Such sweeps shall prioritise products with digital elements placed on the market by manufacturers that maypresent a security risk for the Union. They shall include inspections of products acquired under a cover identity and shall aim to verify the compliance of those products with this Regulation, in particular with regard to identifying potential embedded backdoors or other exploitable vulnerabilities.

Added:The Commission is empowered to adopt delegated acts in accordance with Article 50 to amend this Regulation specifying whether such limitation or exclusion is necessary, the concerned products and rules, as well as the scope of the limitation, if relevant.

Removed:It is important to place a specific focus on manufacturers that can present cybersecurity risks to the integrity of the Union.

Added:4a. This Regulation does not apply to spare parts that are exclusively manufactured to replace identical parts and that are supplied by the manufacturer of the original products with digital elements.

Removed:Article 49 – paragraph 2: 2. Unless otherwise agreed upon by the market surveillance authorities involved, sweeps shall be coordinated by the Commission. The coordinator of the sweep shall make the aggregated results publicly available.

Added:5. This Regulation does not apply to products with digital elements developed exclusively for national security or military purposes or to products specifically designed to process classified information.

Removed:Article 49 – paragraph 3: 3. ENISA shall identify, in the performance of its tasks, including based on the notifications received according to Article 11(1) and (2), categories of products for which sweeps shall be organised. The proposal for sweeps shall be submitted to the potential coordinator referred to in paragraph 2 for the consideration of the market surveillance authorities.

Added:For the purposes of this Regulation, the following definitions apply:

Removed:Article 49 – paragraph 5: 5. Market surveillance authorities shall invite Commission officials, and other accompanying persons authorised by the Commission, to participate in sweeps.

Added:(1) ‘product with digital elements’ means any software or hardware product and its remote data processing solutions, including software or hardware components to be placed on the market separately;

Removed:Article 50 – paragraph 2: 2. The power to adopt delegated acts referred to in Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 19(1), Article 20(5), Article 23(5) and Article 53a shall be conferred on the Commission.

Added:(2) ‘remote data processing’ means any data processing at a distance for which the software is designed and developed by or on behalf of the manufacturer▌, and the absence of which would prevent the product with digital elements from performing one of its functions;

Removed:Article 50 – paragraph 3: 3. The delegation of power referred to in Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 19(1), Article 20(5), Article 23(5) and Article 53a may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

Added:(3) ‘critical product with digital elements’ means a product with digital elements that presents a cybersecurity risk in accordance with the criteria laid down in Article 6(2) and whose core functionality is set out in Annex III;

Removed:Article 50 – paragraph 6: 6. A delegated act adopted pursuant to Article 2(4), Article 6(2), Article 6(3), Article 6(5), Article 10(15), Article 11(5), Article 19(1), Article 20(5), Article 23(5) and Article 53a shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and to the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or of the Council.

Added:(4) ‘highly critical product with digital elements’ means a product with digital elements that presents a cybersecurity risk in accordance with the criteria laid down in Article 6(5);

Removed:Article 53 – paragraph 1: 1. Member States shall lay down the rules on penalties applicable to infringements by economic operators of this Regulation and shall take all measures necessary to ensure that they are enforced. The penalties provided for shall be effective, proportionate and dissuasive. They shall ensure that those rules take into account the financial capabilities of micro, small and medium-sized enterprises.

Added:(4a) ‘cybersecurity’ means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881;