Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 31 Mar 2023
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
To · plenary report· 27 Jul 2023
on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+850 added · −171 removed · 3 changed paragraphs, packaging included.
Part 7 of 20: Paragraphs 302–361
Removed:Article 53 – paragraph 2: 2. Member States shall, without delay, notify the Commission of those rules and of those measures and shall notify it without delay of any subsequent amendment affecting them. The Commission shall ensure that those rules and measures are applied in a uniform and consistent manner across the Union.
Added:(5) ‘operational technology’ means programmable digital systems or devices that interact with the physical environment or manage devices that interact with the physical environment;
Removed:Article 53 a (new): Article 53a / Allocation of the revenue from the penalties to support cybersecurity in the Union / 1. The revenue from the penalties referred to in Article 53(1) shall be allocated to projects raising the level of cybersecurity within the Union. Those projects shall aim to: / (i) increase the number of skilled professionals in the field of cybersecurity; / (ii) enhance capacity-building for micro, small and medium-sized enterprises in order to enable them to better comply with this Regulation; / (iii) improve collective situational awareness of cyber threats; / (iv) develop tools to increase the resilience of Union undertakings to cyber-enabled intellectual property theft. / 2. The revenue referred to in paragraph 1 shall be allocated to the Digital Europe Programme referred to in Article 6 of Regulation (EU) 2021/694. It shall be earmarked to improve the cybersecurity of the Union. It shall constitute externally assigned revenue in accordance with Article 21(5) of Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council1 and shall be implemented in accordance with the rules applicable to the Digital Europe Programme. It shall be considered to be a budgetary top-up and shall not be used to decrease the contribution from the Union budget. / 3. The Commission is empowered to adopt delegated acts in accordance with Article 50 to supplement this Regulation concerning the modalities for the payment of the penalties referred to in Article 53. / 1 Regulation …
Added:(6) ‘software’ means the part of an electronic information system which consists of computer code;
Removed:Article 55 – paragraph 3 a (new): 3a. Until ... [40 months after the date of entry into force of this Regulation], manufacturers may comply with the requirements of this Regulation on a voluntary basis. Where manufacturers comply with this Regulation with regard to their products with digital elements , they shall be considered also to comply with Delegated Regulation (EU) 2022/30. / After … [40 months after the date of entry into force of this Regulation, the Commission shall repeal Commission Delegated Regulation (EU) 2022/30.
Added:(7) ‘hardware’ means a physical electronic information system, or parts thereof capable of processing, storing or transmitting of digital data;
Removed:In order to encourage early compliance with the CRA, a presumption of conformity with the Delegated Regulation pursuant to the Radio Equipment Directive should be granted.
Added:(8) ‘component’ means software or hardware intended for integration into an electronic information system;
Removed:Article 56 – paragraph 1 a (new): Every year when presenting the Draft Budget for the following year, the Commission shall submit a detailed assessment of ENISA's tasks under this Regulation as set out in Annex VIa and other relevant Union law and shall detail the financial and human resources needed to fulfil those tasks.
Added:(9) ‘electronic information system’ means any system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;
Removed:Article 57 – paragraph 2: It shall apply from … [40 months after the date of entry into force of this Regulation]. However Article 11 shall apply from [20 months after the date of entry into force of this Regulation].
Added:(10) ‘logical connection’ means a virtual representation of a data connection implemented through a software interface;
Removed:Sufficient time should be provided to economic operators to adapt to this Regulation, in light of its horizontal nature, broad scope and complexity.
Added:(11) ‘physical connection’ means any connection between electronic information systems or components implemented using physical means, including through electrical or mechanical interfaces, wires or radio waves;
Removed:Annex I – Part 1 – point 2: deleted
Added:(12) ‘indirect connection’ means a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network;
Removed:Moved under point (3) - on the basis of the risk assessment
Added:(13) ‘privilege’ means an access right granted to particular users or programmes to perform security-relevant operations within an electronic information system;
Removed:Annex I – Part 1 – point 3 – point -a (new): (-a) be delivered without known exploitable vulnerabilities;
Added:(14) ‘elevated privilege’ means an access right granted to particular users or programmes to perform an extended set of security-relevant operations within an electronic information system that, if misused or compromised, could allow a malicious actor to gain wider access to the resources of a system or organisation;
Removed:As some vulnerabilities may present very low or no cybersecurity risk, the obligation to deliver products without known exploitable vulnerabilities should be risk-based.
Added:(15) ‘endpoint’ means any device that is connected to a network and serves as an entry point to that network;
Removed:Annex I – Part 1 – point 3 – point a: (a) be delivered with a secure by default configuration, including the possibility to reset the product to its original state while retaining all security updates;
Added:(16) ‘networking or computing resources’ means data or hardware or software functionality that is accessible either locally or through a network or another connected device;
Removed:Annex I – Part 2 – paragraph 1 – point 2: (2) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates, installed automatically where applicable;
Added:(17) ‘economic operator’ means the manufacturer, the authorised representative, the importer, the distributor, or any other natural or legal person who is subject to obligations laid down by this Regulation;
Removed:Annex II – paragraph 1 – point 8: 8. the expected product lifetime, the type of technical security support offered by the manufacturer and until when it will be provided, at the very least until when users can expect to receive security updates, and, where possible and applicable, a notification of the end of security updates;
Added:(18) ‘manufacturer’ means any natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under his or her name or trademark, whether for payment, monetisation or free of charge;
Removed:Annex III – Part I – point 18: deleted
Added:(19) ‘authorised representative’ means any natural or legal person established within the Union who has received a written mandate from a manufacturer to act on his or her behalf in relation to specified tasks;
Removed:Moved fully under class II - routers and modems are key for cybersecurity
Added:(20) ‘importer’ means any natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union;
Removed:Annex III – Part I – point 22: 22. Industrial Automation & Control Systems (IACS) not covered by class II, such as programmable logic controllers (PLC), distributed control systems (DCS), computerised numeric controllers for machine tools (CNC), industrial robots and their control systems, mobile machinery and supervisory control and data acquisition systems (SCADA);
Added:(21) ‘distributor’ means any natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties;
Removed:Annex III – Part I – point 23 a (new): 23a. Home automation systems;
Added:(21a) ‘microenterprises’, ‘small enterprises’ and ‘medium sized enterprises’ means microenterprises, small enterprises and medium-sized enterprises as defined in Commission Recommendation 2003/361/EC;
Removed:Home automation systems play a key role in citizens' houses and should thus be deemed as critical products.
Added:(21b) 'consumer' means any natural person who, under the circumstances of this Regulation, is acting for purposes which are outside their trade, business, craft or profession;
Removed:Annex III – Part I – point 23 b (new): 23b. Private security devices.
Added:(21c) ‘support period’ means the period during which the manufacturer ensures that vulnerabilities of the product with digital elements are handled effectively and in accordance with the essential requirements set out in Annex I, Section 2;
Removed:Security cameras or smart locks are essential to the safety of citizens and should thus be deemed as critical products.
Added:(22) ‘placing on the market’ means the first making available of a product with digital elements on the Union market;
Removed:Annex III – Part II – point 7: 7. Routers, modems intended for the connection to the internet, and switches;
Added:(23) ‘making available on the market’ means any supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
Removed:Annex III – Part II – point 14: deleted
Added:(24) ‘intended purpose’ means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;
Removed:Annex VI – Part A – point 4 – point 4.2: 4.2. The manufacturer shall draw up a written EU declaration of conformity for each product with digital elements in accordance with Article 20 and keep it together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or the expected product lifetime, whichever is longer. The EU declaration of conformity shall identify the product with digital elements for which it has been drawn up. A copy of the EU declaration of conformity shall be made available to the relevant authorities upon request.
Added:(25) ‘reasonably foreseeable use’ means use that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions;
Removed:Annex VI – Part B – point 9: 9. The manufacturer shall keep a copy of the EU-type examination certificate, its annexes and additions together with the technical documentation at the disposal of the national authorities for 10 years after the product has been placed on the market or for the expected product lifetime, whichever is longer.
Added:(26) ‘reasonably foreseeable misuse’ means the use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems;
Removed:Annex VI – Part C – point 3 – point 3.2: 3.2. The manufacturer shall draw up a written declaration of conformity for a product model and keep it at the disposal of the national authorities for 10 years after the product has been placed on the market or for the expected product lifetime, whichever is longer. The declaration of conformity shall identify the product model for which it has been drawn up. A copy of the declaration of conformity shall be made available to the relevant authorities upon request.
Added:(27) ‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;
Removed:Annex VI – Part H – point 5 – point 5.2 – paragraph 1: The manufacturer shall draw up a written declaration of conformity for each product model and keep it at the disposal of the national authorities for 10 years after the product has been placed on the market or for the expected product lifetime, whichever is longer. The declaration of conformity shall identify the product model for which it has been drawn up.
Added:(28) ‘conformity assessment’ means the process of verifying whether the essential requirements set out in Annex I have been fulfilled;
Removed:Annex VI – Part H – point 6 – introductory part: 6. The manufacturer shall, for a period ending at least 10 years after the product has been placed on the market or for the expected product lifetime, whichever is longer, keep at the disposal of the national authorities:
Added:(29) ‘conformity assessment body’ means a body defined in Article 2(13) of Regulation (EU) No 765/2008;
Removed:Annex VI a (new): Capacity needs of the European Union Agency for Cybersecurity (ENISA) / In order to fulfil its obligations under this Regulation and in order not to compromise existing obligations of the Agency under other Union law, the adequate staffing and financing of ENISA shall be ensured. Therefore additional tasks for ENISA under this Regulation shall be accompanied by additional human and financial resources. 8,5 additional full-time posts and corresponding additional appropriations will be needed to cover the additional tasks under this Regulation.
Added:(30) ‘notified body’ means a conformity assessment body designated in accordance with Article 33 of this Regulation and other relevant Union harmonisation legislation;
Added:(31) ‘substantial modification’ means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential requirements set out in Section 1 of Annex I or results in a modification to the intended use for which the product with digital elements has been assessed, excluding necessary security updates that aim to mitigate vulnerabilities;
Added:(32) ‘CE marking’ means a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential requirements set out in Annex I and other applicable Union legislation harmonising the conditions for the marketing of products (‘Union harmonisation legislation’) providing for its affixing;