Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report of 13 Jul 2023 and the draft committee report of 2 Sept 2025

From · draft committee report· 13 Jul 2023

LIBE-PR-751547

on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

To · draft committee report· 2 Sept 2025

LIBE-PR-776837

on the proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Changes to the text itself, in document order. Cover page, citations and punctuation-only edits are left out; they are under “Every difference”.

The changes · 11

Change 1

Changed:Recital 1 a (new): (1a) Union institutions and bodies are obliged to apply Article 15(3) TFEUof the Treaty on the Functioning of the European Union(‘TFEU’) in line with democratic principles, in particular those laid down in Article 10(3) TEUof the Treaty on European Union (‘TEU’) and Article 42 of the Charter of Fundamental Rights of the European Union (‘the Charter’). Therefore, the creation and classification of European Union classified information (‘EUCI’)(EUCI) should take place in line with the principles of minimisation of the use of classification and limiting in time the duration of such a classification.

Change 2

Changed:Recital 5 a (new): (5a) Sharing of EUCI in a transparent and timely manner is of key importance for the proper functioning of Union institutions and bodies. When implementing this Regulation, Union institutions and bodies should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against the use of classification in a manner that would prevent Union entitiesinstitutions and bodies from fulfilling their mission, and should ensure that whistle-blowers are adequately protected, and that there is a high level of protection of information in line with Union law and best practices.

Change 3

Changed:Recital 21: (21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.

Change 4

Changed:Recital 21 a (new): (21a) The informationInformation held by the Union entitiesinstitutions and bodies is also exchanged through the ICTinformation and communication technology (‘ICT’) environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes, as well as networks and information systemssystems, whether owned and operated by a Union entityinstitution or body or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment.

7 more changes

Change 5

Changed:Article 4 – paragraph 1: 1. Each Union institution and body shall be responsible for the implementation of the provisions of this Regulation within its organisation taking account of its own information security risk management process. When developing and implementing their document security framework, Union institutions and bodies shall safeguard the integrity of the Union’s democratic processes. They shall adopt, inter alia, specific provisions in tender procedures to curb the risk of foreign interference in their functioning. Such provisions shall atas leasta minimum address the acquisition and maintenance of security infrastructure, the vetting of third partythird-party organisations and security clearance procedures in respect of staff.

Change 6

Changed:Article 4 – paragraph 6 – subparagraph 2: Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entitiesinstitutions and bodies shall, not later than ...[six... [six months after the date of entry into force of this Regulation], design and implement effective and appropriate training courses commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI.

Change 7

Changed:Article 5 – paragraph 3 – point f: (f) business continuity, disastercontinuity,disaster recovery and crisis management;management ;

Change 8

Changed:Article 41 – paragraph 1 – point f a (new): (fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards for reporting vulnerabilities ,vulnerabilities, as appropriate; thatappropriate, processwhich shall be complemented by regular audits and penetration tests where appropriate.

Change 9

Changed:Article 52 – paragraph 2: 2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That subgroup shall ensure synergy between the need to protect EUCI and Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure.

Change 10

Changed:Article 54 – paragraph 1 – point -a (new): (-a) there is a legal obligation under Union law or an interinstitutional agreement concluded between Union institutions; or

Change 11

Changed:Article 54 – paragraph 1 – point a: (a) there is a proven need for the exchange includingexchange, in line with the ‘need-to-know’ principle;