Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 7 Sept 2023

ITRE-PR-752802

on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services

To · plenary report· 26 Oct 2023

A-9-2023-0307

on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+199 added · −23 removed · 4 changed paragraphs, packaging included.

Part 5 of 7: EXPLANATORY STATEMENT

EXPLANATORY STATEMENT

4 unchanged paragraphs

The Rapporteur supports the proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/8811 as regards managed security services, understanding its necessity to update and strengthen the European cybersecurity certification scheme by allowing it to cover important and growing industry services. Considering how individual Member States have already begun adopting certification schemes for managed security services, the Rapporteur takes the view that this amendment to the Cyber Security Act is critical to preventing significant divergences in national schemes that would result in a form of market fragmentation which is against the Union´s economic, and also strategic interests.

On this note, it is acknowledged how this proposal is envisioned to complement the Cyber Solidarity Act, particularly this specific extension to the European cybersecurity certification scheme, will allow for managed security services - corresponding to ´trusted providers´ in the Cyber Solidarity Act - to play an important role in the future EU Cybersecurity Reserve. Therefore, this proposal is one that is also of great importance in fostering broader Union cybersecurity capacity, which capacity is essential to counteract potential threats in an ever-evolving geopolitical reality.

Within the limits of the Commission´s proposal, the Rapporteur’s objective is to consolidate and add further clarity to this targeted amendment to the Cybersecurity Act. This is illustrated by the Rapporteur´s changes to the definition of managed security services, clarifying that they are ‘outsourced’, while concurrently detailing further what can be included in the definition. Tabled amendments regarding the recognition of international cybersecurity standards are intended to foster a higher caliber of confidence while simultaneously developing comprehensive EU rules.

This draft report puts stronger emphasis on addressing the skills gap and in supporting Micro, Small and Medium Enterprises. On the former, tabled amendments build on the already implicit necessity of skills in the cyber certification scheme vis-a-vis ‘the requisite competence, expertise and experience by staff with a very high level of relevant technical knowledge and professional integrity’. In the Rapporteur’s view, whilst fostering cooperation amongst all actors involved as well as between Member States, the private sector, academia and research institutions, the European certification scheme must act as an enabler of a new roadmap to training and empowering the workforce, collecting more data on the skills needed and contributing towards addressing the gender gap in STEM.

Change 2

Changed:At the same time, micro, small and medium enterprises, which form the backbone of the European economy and certainly have a positive role to play in the cybersecurity industry, should benefit from appropriate financial support in the regulatory framework of existing Union programmes to ease any disproportionate financial burden placed upon themthem.

Change 3

Added:21.9.2023