Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 7 Sept 2023
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
To · plenary report· 26 Oct 2023
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+199 added · −23 removed · 4 changed paragraphs, packaging included.
Part 4 of 7: Paragraphs 181–207
Added:(b) paragraph 9 is replaced by the following:
Added:‘9. National cybersecurity certification authorities shall cooperate with each other and with the Commission, in particular, by exchanging information, experience and good practices as regards cybersecurity certification and technical issues concerning the cybersecurity of ICT products, ICT services, ICT and managed security services processes.’;
Added:(16) in Article 59 (3), points (b) and (c) are replaced by the following:
Added:‘(b) the procedures for supervising and enforcing the rules for monitoring the compliance of ICT products, ICT services, ICT processes and managed security services with European cybersecurity certificates pursuant to Article 58(7), point (a);
Added:(c) the procedures for monitoring and enforcing the obligations of manufacturers or providers of ICT products, ICT services, ICT processes or managed security services pursuant to Article 58(7), point (b);’
Added:(16a) the following article is inserted:
Added:‘Article 65a Exercise of the delegation
Added:1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.
Added:2. The power to adopt delegated acts referred to in Article 49(7) shall be conferred on the Commission for a period of five years from … [date of entry into force of the amended regulation]. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.
Added:3. The delegation of power referred to in Article 49(7) may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.
Added:4. Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making.
Added:5. As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.
Added:6. A delegated act adopted pursuant to Article 49(7) shall enter into force only if no objection has been expressed either by the European Parliament or by the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by [two months] at the initiative of the European Parliament or of the Council.;’
Added:(17) Article 67 is replaced by the following:
Added:‘Article 67
Added:Evaluation and review
Added:1. By 28 June 2024, and every three years thereafter, the Commission shall assess the impact, effectiveness and efficiency of ENISA and of its working practices, the possible need to modify ENISA’s mandate and the financial implications of any such modification. The evaluation shall take into account any feedback provided to ENISA in response to its activities. Where the Commission considers that the continued operation of ENISA is no longer justified in light of the objectives, mandate and tasks assigned to it, the Commission may propose that this Regulation be amended with regard to the provisions related to ENISA.
Added:2. The evaluation shall assess the impact, effectiveness and efficiency of the provisions of Title III of this Regulation with regard to the objectives of ensuring an adequate level of cybersecurity of ICT products, ICT services, ICT processes and managed security services in the Union and improving the functioning of the internal market,
Added:3. The evaluation shall also assess:
Added:(a) the efficiency and effectiveness of the procedures leading to consultation, preparation and adoption of European cybersecurity certification schemes, as well as ways to improve and accelerate those procedures;
Added:(b) whether essential cybersecurity requirements for access to the internal market are necessary in order to prevent ICT products, ICT services, ICT processes and managed security services which do not meet basic cybersecurity requirements from entering the Union market.
Added:4. By 28 June 2024, and every three years thereafter, the Commission shall transmit a report on the evaluation together with its conclusions to the European Parliament, to the Council and to the Management Board. The findings of that report shall be made public.’
Added:This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Added:This Regulation shall be binding in its entirety and directly applicable in all Member States.
Added:Done at ...,
Added:For the European Parliament For the Council
Added:The President The President