Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 4 Sept 2023

ITRE-PR-752795

on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

To · plenary report· 8 Dec 2023

A-9-2023-0426

on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+319 added · −52 removed · 1 changed paragraphs, packaging included.

Part 1 of 8: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

8 unchanged paragraphs

on the proposal for a regulation of the European Parliament and of the Council laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

(COM(2023)0209 – C90136/2023 – 2023/0109(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

– having regard to the Commission proposal to Parliament and the Council (COM(2023)0209),

– having regard to Article 294(2) and Articles 173(3) and 322(1), point (a), of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90136/2023),

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to the opinion of the European Economic and Social Committee of 13 July 2023,

Removed:– having regard to the opinion of the Committee of the Regions of ...,

– having regard to Rule 59 of its Rules of Procedure,

– having regard to the opinions of the Committee on Foreign Affairs and the Committee on Transport and Tourism,

Changed:– having regard to the report of the Committee on Industry, Research and Energy (A90000/2023),(A9-0426/2023),

4 unchanged paragraphs

1. Adopts its position at first reading hereinafter set out;

2. Approves its statement annexed to this resolution;

3. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

4. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Change 1

Removed:Recital 1: (1) The use of and dependence on information and communication technologies have become fundamental aspects in all sectors of economic activity and our democracies as our public administrations, companies and citizens are more interconnected and interdependent across sectors and borders than ever before

Added:AMENDMENTS BY THE EUROPEAN PARLIAMENT*

Removed:Recital 2: (2) The magnitude, frequency and impact of cybersecurity incidents are increasing Union-wide and globally in terms of method and impact, including supply chain attacks aiming at cyberespionage, ransomware or disruption. They represent a major threat to the functioning of network and information systems. In view of the fast-evolving threat landscape, the threat of possible large-scale incidents causing significant disruption or damage to critical infrastructures demands heightened preparedness at all levels of the Union’s cybersecurity framework. That threat goes beyond Russia’s military aggression on Ukraine, and is likely to persist given the multiplicity of state-aligned, criminal and hacktivist actors involved in current geopolitical tensions. Such incidents can impede the provision of public services and the pursuit of economic activities, including in critical or highly critical sectors, generate substantial financial losses, undermine user confidence, cause major damage to the economies and democracies of the Union, and could even have health or life-threatening consequences. Moreover, cybersecurity incidents are unpredictable, as they often emerge and evolve within very short periods of time, not contained within any specific geographical area, and occurring simultaneously or spreading instantly across many countries. Therefore, strong cooperation is needed between the public sector, the private sector, academia and the media. Moreover, the Union's response needs to be…

Added:to the Commission proposal

Removed:Recital 3: (3) It is necessary to strengthen the competitive position of industry and services sectors in the Union across the digitised economy and support their digital transformation, by reinforcing the level of cybersecurity in the Digital Single Market. As recommended in three different proposals of the Conference on the Future of Europe16 , it is necessary to increase the resilience of citizens, businesses, including the small and medium-sized enterprises (SMEs), and entities operating critical infrastructures against the growing cybersecurity threats, which can have devastating societal and economic impacts. Therefore, investment in infrastructures and services and building capabilities to develop skills and opportunities for the whole population that will support faster detection and response to cybersecurity threats and incidents is needed, and Member States need assistance in better preparing for, as well as responding to significant and large-scale cybersecurity incidents. The Union should also increase its capacities in these areas, notably as regards the collection and analysis of data on cybersecurity threats and incidents.

Added:---------------------------------------------------------

Removed:Recital 3 a (new): (3a) Cyberattacks are frequently targeted at local, regional or national public services and infrastructures. Local authorities are among the most vulnerable targets due to their lack of financial and human resources. It is therefore particularly important that leaders at local level are made aware of the need to increase digital resilience , increase their capacity to reduce the impact of cyberattacks and seize the opportunities provided for by this Regulation 1a. / 1a European Committee of the Regions, Digital Resilience, 2023. https://cor.europa.eu/en/engage/studies/Documents/Digital%20resilience.pdf

Added:2023/0109 (COD)

Removed:Recital 7: (7) It is necessary to strengthen the detection and situational awareness of cyber threats and incidents throughout the Union and to strengthen solidarity by enhancing Member States’ and the Union’s preparedness and capabilities to respond to significant and large-scale cybersecurity incidents. Therefore a pan-European infrastructure of SOCs (European Cyber Shield) should be deployed to build and enhance common detection and situational awareness capabilities, reinforcing the Union’s threat detection and information sharing capabilities; a Cybersecurity Emergency Mechanism should be established to support Member States in preparing for, responding to, and immediately recovering from significant and large-scale cybersecurity incidents; a Cybersecurity Incident Review Mechanism should be established to review and assess specific significant or large-scale incidents. These actions shall be without prejudice to Articles 107 and 108 of the Treaty on the Functioning of the European Union (‘TFEU’).

Added:Proposal for a

Removed:Recital 9 a (new): (9a) In order to ensure continuity with regard to activities provided for by this Regulation beyond 2027, it is necessary to ensure a specific budget line in the multiannual financial framework for 2028 to 2034. Member States should also commit themselves to supporting all necessary measures to reduce cyber threats and incidents throughout the Union and strengthening solidarity.

Added:REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Removed:Recital 14: (14) As part of the European Cyber Shield, a number of Cross-border Cybersecurity Operations Centres (‘Cross-border SOCs’) should be established. These should bring together National SOCs from at least three Member States, so that the benefits of cross-border threat detection and information sharing and management can be fully achieved. The general objective of Cross-border SOCs should be to strengthen capacities to analyse, prevent and detect cybersecurity threats and to support the production of high-quality intelligence on cybersecurity threats, notably through the sharing of data from various sources, public or private, as well as through the sharing and joint use of state-of-the-art tools, and jointly developing detection, analysis and prevention capabilities in a trusted environment, with the support of ENISA, to support operational cooperation among Member States. Cross-border SOCs should provide new additional capacity, building upon and complementing existing SOCs and computer incident response teams (‘CSIRTs’) and other relevant actors.

Added:laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents and amending Regulation (EU) 2021/694

Removed:Recital 15: (15) At national level, the monitoring, detection and analysis of cyber threats is typically ensured by SOCs of public and private entities, in combination with CSIRTs. In addition, CSIRTs exchange information in the context of the CSIRT network, in accordance with Directive (EU) 2022/2555. The Cross-border SOCs should constitute a new capability that is complementary to the CSIRTs network, by pooling and sharing data on cybersecurity threats from public and private entities, enhancing the value of such data through expert analysis and jointly acquired infrastructures and state of the art tools, and contributing to the development of Union capabilities and technological sovereignty in line with the open strategic autonomy of the Union.

Added:THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

Removed:Recital 20: (20) By collecting, sharing and exchanging data, the European Cyber Shield should enhance the Union’s technological sovereignty and open strategic autonomy. The pooling of high-quality curated data should also contribute to the development of advanced artificial intelligence and data analytics technologies. It should be facilitated through the connection of the European Cyber Shield with the pan-European High Performance Computing infrastructure established by Council Regulation (EU) 2021/117325 .

Added:Having regard to the Treaty on the Functioning of the European Union, and in particular Article 173(3) and Article 322(1), point (a) thereof,

Removed:Recital 33: (33) A Union-level Cybersecurity Reserve should gradually be set up, consisting of services from private providers of managed security services to support response and immediate recovery actions in cases of significant or large-scale cybersecurity incidents. The EU Cybersecurity Reserve should ensure the availability and readiness of services, while developing industrial capacities in the Union, including for SMEs, with investment in research and innovation (R&I) to develop state-of-the-art technologies, such as those relating to cloud and artificial intelligence. The services from the EU Cybersecurity Reserve should serve to support national authorities in providing assistance to affected entities operating in critical or highly critical sectors as a complement to their own actions at national level. When requesting support from the EU Cybersecurity Reserve, Member States should specify the support provided to the affected entity at the national level, which should be taken into account when assessing the Member State request. The services from the EU Cybersecurity Reserve may also serve to support Union institutions, bodies and agencies, under similar conditions.

Added:Having regard to the proposal from the European Commission,

Removed:Recital 35: (35) To support the establishment of the EU Cybersecurity Reserve, the Commission should request ENISA to prepare a candidate certification scheme pursuant to Regulation (EU) 2019/881 for managed security services in the areas covered by the Cyber Emergency Mechanism. In order to fulfil the additional tasks deriving from this provision, ENISA should receive adequate, additional funding.

Added:After transmission of the draft legislative act to the national parliaments,

Removed:A certification scheme would serve to build long standing and trusted partnerships with the private sector.

Added:Having regard to the opinion of the Court of Auditors

Removed:Recital 37 a (new): (37a) Third countries can access resources and support from the EU Cyber Solidarity Act, using the incident response support from the EU Cybersecurity Reserve, and as third-country actors from the private sector are needed for the cyber reserve. In order to safeguard the Union’s strategic assets, interests, autonomy or security, specific conditions may limit the participation of legal entities established in non-associated third countries. The external dimension of this Regulation should be in line with the provisions established in the Association Agreement under the Digital Europe Programme. The participation of third countries should be subject to public scrutiny, with the participation of the legislative powers, to guarantee that citizens can participate in the process.

Added:Having regard to the opinion of the European Economic and Social Committee,

Removed:Recital 38 a (new): (38a) A central pillar of this Regulation is the development of skills and competences. Therefore, a strengthened link is needed with the EU Cybersecurity Skills Academy to close the cybersecurity talent gap by bringing together private and public initiatives and providing training and certification for citizens that need to be accompanied by investment in access for all citizens in all territories to be trained in these skills. The strengthened link requires safeguards to avoid a ‘brain drain’ and should not pose a risk to labour mobility.

Added:Having regard to the opinion of the Committee of the Regions,

Removed:Recital 38 b (new): (38b) Increased investment and active measures to develop skills in this sector are needed, taking into account that 2023 is the European Year of Skills, as well as increasing citizens’ awareness, without prejudice to the need for geographical balance.

Added:Acting in accordance with the ordinary legislative procedure,

Removed:Recital 38 c (new): (38c) Reinforcement of specialised, interdisciplinary and general skills and competences across the Union is needed, with a special focus on women, as the gender gap persists in cybersecurity with women comprising 20 % of the average worldwide presence1a. Women must be present and part of the design of the digital future and its governance. / 1a European Parliament resolution of 10 June 2021 on promoting gender equality in science, technology, engineering and mathematics (STEM) education and careers (2019/2164(INI)) https://www.europarl.europa.eu/doceo/document/TA-9-2021-0296_EN.html#def_1_22

Added:Whereas:

Removed:Recital 38 d (new): (38d) In order to develop skills and competences in cybersecurity, a reinforcement of the triangle between national competence centres, the European Cybersecurity Competence Centre (ECCC) and ENISA is needed. Including the participation of industry and creating partnerships with academia and civil society actors, counting with the regional experience, knowledge and specialisation in developing skills.

Added:(1) The use of and dependence on information and communication technologies have become fundamental aspects, but have, simultaneously introduced possible vulnerabilities, in all sectors of economic activity and democracy as our public administrations, companies and citizens are more interconnected and interdependent across sectors and borders than ever before.

Removed:Recital 38 e (new): (38e) Strengthening R&I in cybersecurity will increase the resilience and the open strategic autonomy of the Union. Likewise, ensuring synergies with R&I programmes and with existing instruments and institutions and to reinforce the triangle of knowledge to bridge the skills gap across the Union by creating opportunities and investing in capacities will also help achieve the necessary resilience.

Added:(2) The magnitude, frequency and impact of cybersecurity incidents are increasing at a Union-wide and global level in terms of their method and impact, including supply chain attacks aiming at cyberespionage, ransomware or disruption. They represent a major threat to the functioning of network and information systems. In view of the fast-evolving threat landscape, the threat of possible large-scale incidents causing significant disruption or damage economies and democracies to critical infrastructures across the Union demands heightened preparedness at all levels of the Union’s cybersecurity framework. That threat goes beyond Russia’s military aggression on Ukraine, and is likely to persist given the multiplicity of state-aligned, and criminal ▌actors involved in current geopolitical tensions. Such incidents can impede the provision of public services and the pursuit of economic activities, including in critical or highly critical sectors, generate substantial financial losses, undermine user confidence, cause major damage to the economy of the Union, and could even have health or life-threatening consequences. Moreover, cybersecurity incidents are unpredictable, as they often emerge and evolve within very short periods of time, not contained within any specific geographical area, and occurring simultaneously or spreading instantly across many countries. Close and coordinated cooperation is therefore needed between the public sector, the private sector, academia, civil society and the media. Moreover, the Union's response needs to be coordinated with international institutions as well as trusted and like-minded international partners. Trusted and like-minded international partners are countries that share the Union’s values of democracy, commitment to human rights, effective multilateralism, and rules-based order, in line with the international cooperation frameworks and agreements. To ensure cooperation with trusted and like-minded international partners and protection against systemic rivals, entities established in third countries that are not parties to the GPA should not be allowed to participate in procurement under this Regulation.

Removed:Recital 38 f (new): (38f) Moreover, this Regulation will increase the resilience of the Union, directly by means of cybersecurity and cyber resilience law and indirectly by means of the impact it can have for the exponential development of law with regard to artificial intelligence, data privacy and data regulation.

Added:(3) It is necessary to strengthen the competitive position of industry and services sectors in the Union across the digitised economy and support their digital transformation, by reinforcing the level of cybersecurity in the Digital Single Market. As recommended in three different proposals of the Conference on the Future of Europe , it is necessary to increase the resilience of citizens, businesses, in particular microenterprises, small and medium-sized enterprises (SMEs) including startups and entities operating critical infrastructures, including local and regional authorities against the growing cybersecurity threats, which can have devastating societal and economic impacts. Therefore, investment in infrastructures and services and building capabilities to develop cybersecurity skills that will support faster detection and response to cybersecurity threats and incidents is needed, and Member States need assistance in better preparing for, as well as responding to significant and large-scale cybersecurity incidents. The Union should also increase its capacities in these areas, notably as regards the collection and analysis of data on cybersecurity threats and incidents.

Removed:Recital 38 g (new): (38g) This Regulation is intended to achieve the commitment of the European Declaration on Digital Rights and Principles for the Digital Decade linked to protect the interests of our democracies, people, businesses and public institutions against cybersecurity risks and cybercrime including data breaches and identity theft or manipulation.

Added:(3a) Cyberattacks are frequently targeted at local, regional or national public services and infrastructures. Local authorities are among the most vulnerable targets of cyberattacks due to their lack of financial and human resources. It is therefore particularly important that decision-makers at local level are made aware of the need to increase digital resilience, increase their capacity to reduce the impact of cyberattacks and seize the opportunities provided for by this Regulation.

Removed:Recital 38 h (new): (38h) Increasing Cybersecurity Culture which comprehends security, including that of the digital environment, as a public good will be key for the successful implementation of this Regulation. Therefore, developing measures to include and increase citizens’ awareness should be another means of guaranteeing the safeguard of our democracies and fundamental values.

Added:(4) The Union has already taken a number of measures to reduce vulnerabilities and increase the resilience of critical infrastructures and entities against cybersecurity risks, in particular Directive (EU) 2022/2555 of the European Parliament and of the Council, Commission Recommendation (EU) 2017/1584, Directive 2013/40/EU of the European Parliament and of the Council and Regulation (EU) 2019/881 of the European Parliament and of the Council. In addition, the Council Recommendation on a Union-wide coordinated approach to strengthen the resilience of critical infrastructure invites Member States to take urgent and effective measures, and to cooperate loyally, efficiently, in solidarity and in a coordinated manner with each other, the Commission and other relevant public authorities as well as the entities concerned, to enhance the resilience of critical infrastructure used to provide essential services in the internal market.

Removed:Recital 38 i (new): (38i) In order to supplement certain non-essential elements of this Regulation, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission to specify the conditions for interoperability between the Cross-border SOCs, establish the procedural arrangements for the information sharing between the Cross-border SOCs on the one hand and EU-CyCLONe, the CSIRTs network and the Commission on the other, specify the types and number of response services required for the EU Cybersecurity Reserve, and specify further the detailed arrangements for allocating the EU Cyersecurity Reserve support services. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making1. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. / 1. OJ L 123, 12.5.2016, p. 1.