Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 7 Sept 2023
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
To · plenary report· 26 Oct 2023
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+199 added · −23 removed · 4 changed paragraphs, packaging included.
Part 1 of 7: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
5 unchanged paragraphs
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
(COM(2023)0208 – C90137/2023 – 2023/0108(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2023)0208),
Changed:– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C9 0137/2023),(C90137/2023),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
– having regard to the opinion of the European Economic and Social Committee of 13 July 2023,
– having regard to Rule 59 of its Rules of Procedure,
Changed:– having regard to the letter offrom the Committee on the Internal Market and Consumer Protection,
Changed:– having regard to the report of the Committee on Industry, Research and Energy (A90000/2023),(A9-0307/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
Removed:Recital 1 a (new): (1a) In order to ensure the Union’s resilience to cyberattacks and to prevent any vulnerabilities in the Union market, the present Regulation will complement the horizontal regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements in accordance with Regulation (EU) .../... of the European Parliament and of the Council * +, setting up essential requirements for cybersecurity managed services, their application and their trustworthiness. / *Regulation (EU) .../... of the European Parliament and of the Council of ... on ... / (OJ ...). / + OJ: Please insert in the text the number of the Regulation contained in document 2022/0272 (COD) and insert the number, date, title and OJ reference of that Regulation in the footnote.
Added:AMENDMENTS BY THE EUROPEAN PARLIAMENT*
Removed:Recital 2: (2) Managed security services, which are services consisting of carrying out, or providing assistance for, activities relating to their customers’ cybersecurity risk management, including in prevention, detection, response to or recovery from incidents, have gained increasing importance in the prevention and mitigation of cybersecurity incidents. The activities of the providers of managed security services consist of services relating to identification, protection, detection, response and recovery, including, but not limited to, cyber threat intelligence provision, real time threat monitoring through proactive techniques, including security-by-design, risk assessment, extended detection, remediation and response. Accordingly, the providers of those services are considered as essential or important entities belonging to a sector of high criticality pursuant to Directive (EU) 2022/2555 of the European Parliament and of the Council8. Pursuant to Recital 86 of that Directive, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy, play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and pose a particular risk because of their close integration in the operations of their customers. Essential and important entities within the meaning of Direc…
Added:to the Commission proposal
Removed:Recital 4 a (new): (4a) European certification schemes for managed security services should contribute to the accessibility and affordability of these services, especially for smaller actors, such as microenterprises and small and medium-sized entreprises, which are often more prone to cybersecurity breaches with financial, legal, reputational, and operational implications.
Added:---------------------------------------------------------
Removed:Recital 5 a (new): (5a) With a view to facilitating the growth of a reliable Union market, whilst also creating partnerships with likeminded third countries, including in light of the provisions of the Regulation (EU) .../... of the European Parliament and of the Council* ++with regard to the access to the EU Cybersecurity Reserve, the certification process established within the framework established by this Regulation should be streamlined to ensure international recognition and alignment with international standards. / * Regulation (EU) .../... of the European Parliament and of the Council of ... on ... / (OJ ...). / ++ OJ: Please insert in the text the number of the Regulation contained in document 2023/0109 (COD) and insert the number, date, title and OJ reference of that Regulation in the footnote.
Added:2023/0108 (COD)
Removed:Recital 5 b (new): (5b) With the aim to ensure the development of a trustworthy Union market for managed security services, the providers thereof and Member States should collaborate and contribute to the large-scale collection of data on the state and the evolution of the cybersecurity labour market.
Added:Proposal for a
Removed:Recital 5 c (new): (5c) A Union-wide coordinated approach to strengthening the resilience of critical infrastructure is based on the Member States’ capacity building. As acknowledged in the recent Commission communication of 8 April 2023 on Closing the cybersecurity talent gap to boost the EU’s competitiveness, growth and resilience, the security of the Union cannot be guaranteed without the Union’s most valuable asset: its people. Therefore, any European certification scheme should take into account assistance for the Member States, including with regard to the cybersecurity skills gaps.
Added:REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
Removed:Recital 5 d (new): (5d) In light of the elaboration and implementation of the European certification scheme for managed security services, the Commission should increase the exchanges with ENISA and facilitate the dialogue with Member States, the private sector and academia, in order to better comprehend the composition of the Union cybersecurity workforce and of associated skills.
Added:amending Regulation (EU) 2019/881 as regards managed security services
Removed:Recital 5 e (new): (5e) With a view to enabling the European cybersecurity schemes to attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements, including with regard to the ongoing provision thereof with the requisite competence, expertise and experience by staff with a very high level of relevant technical knowledge and professional integrity in accordance with this Regulation, the schemes should mobilise the contribution of academia, research institutions and other stakeholders with experience in training cybersecurity professionals, and attracting, recruiting, and developing talent, as well as incentivising public-private partnerships. It should act as an enabler of the pooling of ideas and sharing of expertise on training and better assessing the necessary skills, especially during the recruitment process. Along with the contribution to the scheme, the private sector should also aim to deliver on-the-job training addressing the most in-demand skills, involving public administration and start-ups, as well as microenterprises and, small and medium-sized entreprises.
Added:(Text with EEA relevance)
Removed:Recital 5 f (new): (5f) In order to facilitate the emergence of high-quality, essential managed security services, Member States should actively pursue measures to train and retain talent, including through integrating cybersecurity in educational and training programmes, whilst ensuring access to apprenticeships and traineeships for young people, especially persons living in disadvantaged regions, such as islands, sparsely populated, rural and remote areas. Those measures should also aim to attract more women and girls in the field and contribute towards addressing the gender gap in science, technology, engineering, and math.
Added:THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Removed:Regulation (EU) 2019/881
Added:Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
Removed:Article 1 – paragraph 1 – point 2 – point b, Article 2 – point 14a: (14a) ‘managed security service’ means an outsourced service consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, including, prevention, detection, response to or recovery from incidents, penetration testing, security audits and consultancy;
Added:Having regard to the proposal from the European Commission,
Removed:Regulation (EU) 2019/881
Added:After transmission of the draft legislative act to the national parliaments,
Removed:Article 1 – paragraph 1 – point 6, Article 47 – paragraph 3 – point e a (new): (ea) prior alignment with the applicable international standards;
Added:Having regard to the opinion of the European Economic and Social Committee,
Removed:Regulation (EU) 2019/881
Added:Having regard to the opinion of the Committee of the Regions;
Removed:Article 1 – paragraph 1 – point 6, Article 47 – paragraph 3 – point e b (new): (eb) the contribution of the managed security services provider to offering training and upskilling opportunities to staff with the aim to achieve a very high level of relevant technical knowledge and professional integrity.
Added:Acting in accordance with the ordinary legislative procedure,
Removed:Regulation (EU) 2019/881
Added:Whereas:
Removed:Article 1 – paragraph 1 – point 6, Article 47 – paragraph 3 a (new): 3a. Additionally, the inclusion of specific managed security services, in the Union rolling work programme shall, where relevant, take into consideration the contribution of the managed security services providers to training and attracting talent, especially through partnerships with universities and other educational institutions.
Added:(1) Regulation (EU) 2019/881 of the European Parliament and of the Council sets up a framework for the establishment of European cybersecurity certification schemes for the purpose of ensuring an adequate level of cybersecurity for information and communications technology (ICT) products, ICT services and ICT processes in the Union, as well as for the purpose of avoiding the fragmentation of the internal market with regard to cybersecurity certification schemes in the Union.
Removed:Regulation (EU) 2019/881
Added:(1a) In order to ensure the Union’s resilience to cyberattacks and to prevent any vulnerabilities in the Union market, this Regulation is intended to complement the horizontal regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements in accordance with Regulation (EU) .../... of the European Parliament and of the Council (2022/0272(COD)), by setting up essential requirements for cybersecurity managed services, their application and their trustworthiness.
Removed:Article 1 – paragraph 1 – point 7, Article 49 – paragraph 7 a (new): 7a. The candidate scheme shall be developed taking into consideration any input given by the European system for technical standardisation or by the Union’s sectoral agencies.
Added:(2) Managed security services, which are services consisting of carrying out, or providing assistance for, activities relating to their customers’ cybersecurity risk management, including detection, response to or recovery from incidents, have gained increasing importance in the prevention and mitigation of cybersecurity incidents. The activities of the providers of managed security services consist of services relating to prevention, identification, protection, detection, analysis, containment, response and recovery, including, but not limited to, cyber threat intelligence provision, real time threat monitoring through proactive techniques, including security-by-design, risk assessment, extended detection, remediation and response. Accordingly, the providers of those services are considered as essential or important entities belonging to a sector of high criticality pursuant to Directive (EU) 2022/2555 of the European Parliament and of the Council. Pursuant to Recital 86 of that Directive, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy, play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and pose a particular risk because of their close integration in the operations of their customers. Essential and important entities within the meaning of Directive (EU) 2022/2555 should therefore exercise increased diligence in selecting a managed security service provider.
Removed:Regulation (EU) 2019/881
Added:(3) Managed security services providers also play an important role in the EU Cybersecurity Reserve whose gradual set-up is supported by Regulation (EU) …/…. [laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents]. The EU Cybersecurity Reserve is to be used to support response and immediate recovery actions in case of significant and large-scale cybersecurity incidents. Regulation (EU) …/…[laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents] lays down a selection process for the providers forming the EU Cybersecurity Reserve, which should, inter alia, take into account whether the provider concerned has obtained a European or national cybersecurity certification. The relevant services provided by trusted providers according to Regulation (EU) …./…..[laying down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents] correspond to managed security services in accordance with this Regulation.
Removed:Article 1 – paragraph 1 – point 9, Article 51a – paragraph 1 – point b: (b) ensure that the provider has appropriate internal procedures in place to ensure that the managed security services are provided at a very high level of quality and reliability at all times;
Added:(4) Certification of managed security services is not only relevant in the selection process for the EU Cybersecurity Reserve but it is also an essential quality indicator for private and public entities that intend to purchase such services. In light of the criticality of the managed security services and the sensitivity of the data they process, certification could provide potential customers with important guidance and assurance about the trustworthiness of these services. European certification schemes for managed security services contribute to avoiding fragmentation of the single market. This Regulation therefore aims at enhancing the functioning of the internal market.
Removed:Regulation (EU) 2019/881
Added:(4a) European certification schemes for managed security services should lead to the uptake of those services and to increased competition in the field, taking into account the specific needs of both providers and beneficiaries. Those schemes should, therefore, strike a balance between the their objective and the potential regulatory, administrative and financial burden that providers, especially microenterprises or small and medium-sized enterprises (SMEs), could encounter. Additionally, the schemes should encourage the use of certified managed security services by contributing to the accessibility thereof, especially for smaller actors, such as microenterprises and SMEs, as well as local and regional authorities which have limited capacity and resources, but which are more prone to cybersecurity breaches with financial, legal, reputational, and operational implications.
Removed:Article 1 – paragraph 1 – point 13 – point b – point ii – point bb, Article 56 – paragraph 3 – point d: (d) take into account any implementation deadlines, transitional measures and periods, in particular with regard to the possible impact of the measure on the manufacturers or providers of ICT products, ICT services, ICT processes or managed security services, including the specific interests and needs of microenterprises and small and medium-sized enterprises. The Commission shall ensure appropriate financial support in the regulatory framework of existing Union programmes, in particular in order to ease the financial burden on microenterprises and on small and medium-sized enterprises;