Skip to content
EU Parl Watch

report parliamentary committee draft, 18 September 2026

On the proposal for a regulation of the European Parliament and of the Council on the European Union Agency for Cybersecurity (ENISA), the European cybersecurity certification framework, and ICT supply chain security and repealing Regulation (EU) 2019/881 (The Cybersecurity Act 2)

Document ITRE-PR-792222 · (COM(2026)0011 – C100015/2026 – 2026/0011(COD))

Committee on Industry, Research and Energy · Rapporteur: Markéta Gregorová

On Parliament’s site PDF Word

AI:In short

This is the rapporteur's draft report on the proposed Cybersecurity Act 2, which would replace Regulation (EU) 2019/881, broaden ENISA's mandate, reform European cybersecurity certification and set Union rules on ICT supply chain security. It proposes a single entry point for incident reporting, an early alert service that reaches national CSIRTs first, and a free Union ransomware helpdesk in all official languages. It would make European cybersecurity certification mandatory unless Union law expressly provides otherwise, with deadlines for certifying entities' cyber posture and for certified ICT components in key assets. It would identify high-risk suppliers through an evaluation matrix, ban them from key ICT assets, phase out their components from mobile networks within 24 months, and set minimum and maximum penalties.

Position. The rapporteur welcomes the Commission proposal and supports its three objectives, proposing amendments to make certification mandatory by default, to identify high-risk suppliers through an evidence-based evaluation matrix, and to shorten phase-out periods.

Key points

  1. A new Article 15a would create a single entry point for incident reporting, so one submission fulfils reporting duties under several Union acts, with national authorities and CSIRTs as sole addressees.
  2. Early alerts would go to the CSIRTs concerned before or at the same time as to entities, under a procedure agreed with the CSIRTs network and reviewed every two years.
  3. ENISA would run a free, uniform ransomware helpdesk in all official languages, offering triage, decryption tools, guidance and referral, and reporting annually to Parliament and the Council.
  4. At least 60% of the EU Cybersecurity Reserve's pre-committed capacity would be procured from providers established in the Union and not controlled by a third country.
  5. European cybersecurity certification would become mandatory unless Union law expressly provides otherwise, and certificates at 'substantial' or 'high' level would confer a presumption of conformity with named Union acts.
  6. Entities in Annex I to Directive (EU) 2022/2555 would have to certify their cyber posture within 12 months of a scheme's availability, and key ICT assets would need certified components within 36 months.
  7. These certification duties would start only after the Commission confirms sufficient conformity assessment capacity; SMEs get an extra 12 months and reduced fees.
  8. Member States could not add national certification or conformity assessment for products, services or processes already holding a valid European certificate covering the same subject matter.
  9. ENISA could draft technical specifications only where no harmonised standard exists or a standardisation request has failed, and they would cease to apply once a standard is cited.
  10. The Commission would identify high-risk suppliers using an evaluation matrix in a new annex, based on specific and substantiated evidence, with the right to be heard and judicial remedies.
  11. High-risk suppliers would be banned from key ICT assets, including remote access, and their components phased out of mobile networks within 24 months and fixed and satellite networks within 24 months after a risk assessment.
  12. Penalties would have minimum as well as maximum levels, up to 7% of worldwide annual turnover, plus periodic penalty payments of up to 5% of average daily turnover for continued non-compliance.

Who is affected

  • ENISA gains new tasks, including the single entry point, early alerts, the ransomware helpdesk and certification support, with resources to match.
  • Entities in sectors listed in Annexes I and II to Directive (EU) 2022/2555 face mandatory certification and procurement rules for certified ICT products.
  • Small and medium-sized enterprises get an extra 12 months for certification, reduced fees and free entry-level profiles.
  • Suppliers of ICT components face assessment, listing as high-risk and bans, with rights to be heard and to judicial remedies.
  • Grid operators may be empowered to disconnect installations that do not meet mitigating measures for high-risk components.

Figures and deadlines

  • At least 60% of the EU Cybersecurity Reserve's pre-committed capacity must come from Union-established providers.
  • Certification of cyber posture at 'substantial' level within 12 months of scheme availability, and at 'high' level within 12 months for critical sectors.
  • Certified ICT components in key ICT assets within 36 months of scheme availability.
  • SMEs get an additional 12 months for certification obligations.
  • Candidate certification schemes to be prepared within 24 months of a Commission request, extendable once by no more than 6 months.
  • Phase-out of high-risk supplier components from mobile networks within 24 months, extendable by no more than 12 months.
  • Phase-out for fixed and satellite networks not to exceed 24 months from publication of the relevant high-risk supplier list.
  • Penalties up to 7% of worldwide annual turnover, with minimum 2% or EUR 10 000 000, and periodic payments up to 5% of average daily turnover.

Legal basis. Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union.

Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 25 Sept 2026 · Report a problem

Full text

Jump to an amendment (164)
Draft european parliament legislative resolution 842 paragraphs

(COM(2026)0011 – C100015/2026 – 2026/0011(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

–having regard to the Commission proposal to Parliament and the Council (COM(2026)0011),

–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100015/2026),

–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

–having regard to the budgetary assessment by the Committee on Budgets,

–having regard to the reasoned opinions submitted, within the framework of Protocol No 2 on the application of the principles of subsidiarity and proportionality, by the Czech Chamber of Deputies and the French Senate, asserting that the draft legislative act does not comply with the principle of subsidiarity,

–having regard to the opinion of the European Economic and Social Committee of 29 April 2026,

–having regard to Rules 60 and 58 of its Rules of Procedure,

–having regard to the opinion of the Committee on the Internal Market and Consumer Protection,

–having regard to the report of the Committee on Industry, Research and Energy (A100000/2026),

Read the rest (830 paragraphs)

1.Adopts its position at first reading hereinafter set out;

2.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

3.Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Amendment 1

Proposal for a regulation

Recital 6

Text proposed by the CommissionAmendment
(6) This proposal is consistent with and complemented by the [Proposal for a Directive complementing [the revision of Regulation (EU) 2019/881] and amending Directive (EU) 2022/2555 as regards the simplification of the implementation of measures for a high common level of cybersecurity across the Union], as well as with the [Proposal for Regulation on simplification of the digital legislation (Digital Omnibus)21 which provides the obligation on ENISA to develop a single entry-point for incident reporting through which entities can simultaneously fulfil their incident reporting obligations under multiple legal acts.(6) This proposal is consistent with and complemented by the [Proposal for a Directive complementing [the revision of Regulation (EU) 2019/881] and amending Directive (EU) 2022/2555 as regards the simplification of the implementation of measures for a high common level of cybersecurity across the Union], as well as with the [Proposal for Regulation on simplification of the digital legislation (Digital Omnibus)21 which provides for the fulfilment of incident reporting obligations under multiple Union legal acts through a single submission. ENISA should establish and operate the single entry point as a Union-level channel through which entities submit one notification that is transmitted without delay to the competent authorities and CSIRTs designated by the Member States, which remain the sole addressees and retain full responsibility for its handling. National reporting systems and national entry points should be connected to the single entry point so that a submission through either channel is a single submission for the purposes of all applicable Union legal acts. The single entry point should be designed as a federated system with end-to-end encryption between the notifying entity and the addressee authority, so that no single component holds the incident data of all Member States.
21 COM/2025/837 final21 COM/2025/837 final

Or. en

Amendment 2

Proposal for a regulation

Recital 172 a (new)

Text proposed by the CommissionAmendment
(172a) Free and open-source software and hardware contribute to the Union’s technological sovereignty and constitute the basis for critical communication, commerce, healthcare, research and government services. Public availability of source code enables independent inspection, audit and vulnerability detection, facilitates peer review and coordinated remediation, and increases supply-chain transparency. The application of this Regulation should take into account the nature of the different development models under free and open-source licences and their cybersecurity benefits.

Or. en

Amendment 3

Proposal for a regulation

Recital 172 b (new)

Text proposed by the CommissionAmendment
(172b) Building on operational national precedents, in particular the Belgian CyberFundamentals framework and the Spanish Esquema Nacional de Seguridad, the entity-level certification should be based on tiered control sets, free entry-level profiles, and make organisational certification accessible to small and medium-sized enterprises while conferring presumption of conformity with Directive (EU) 2022/2555.

Or. en

Amendment 4

Proposal for a regulation

Recital 172 c (new)

Text proposed by the CommissionAmendment
(172c) This Regulation forms part of a single Union cybersecurity framework together with Directives (EU) 2022/2555 and (EU) 2022/2557, and Regulations (EU) 2022/2554 and (EU) 2024/2847. Obligations arising under those acts in respect of the same subject matter should be capable of being fulfilled once, definitions should be read consistently across those acts, conformity demonstrated under one act should be recognised under the other acts, and remaining misalignments should be identified and removed through regular review.

Or. en

Amendment 5

Proposal for a regulation

Recital 172 d (new)

Text proposed by the CommissionAmendment
(172d) The early alert service should strengthen the role of the national CSIRTs, which remain the primary points of contact for entities under Directive (EU) 2022/2555. The alerts should therefore reach the CSIRTs concerned first, follow an agreed sequencing, routing and deduplication procedure, and be subject to a recurring review on which the CSIRTs network delivers an opinion.

Or. en

Amendment 6

Proposal for a regulation

Recital 172 e (new)

Text proposed by the CommissionAmendment
(172e) Union financial support for incident response should reinforce the Union’s technological sovereignty and open strategic autonomy in the area of cybersecurity, in line with Article 1(2) of Regulation (EU) 2025/38. The selection of trusted managed security service providers should therefore ensure, through functional criteria concerning establishment, ownership, control and jurisdictional exposure, that pre-committed capacity is predominantly provided by providers established in the Union.

Or. en

Amendment 7

Proposal for a regulation

Recital 172 f (new)

Text proposed by the CommissionAmendment
(172f) The ransomware helpdesk should build on proven Union-level cooperation, in particular the No More Ransom initiative of Europol and the Dutch National High Tech Crime Unit, which since 2016 has provided free decryption tools in 37 languages through a public-private partnership, and should guarantee a uniform level of assistance to entities in all Member States, complementing national victim support services and the tasks of the CSIRTs.

Or. en

Amendment 8

Proposal for a regulation

Recital 172 g (new)

Text proposed by the CommissionAmendment
(172g) European cybersecurity skills attestation schemes should support the development of cybersecurity capacity in public administrations at all levels, including regional and local authorities, whose staff implement Union cybersecurity law on the ground. Attestations should be affordable, aligned with the European Cybersecurity Skills Framework and recognised across Member States, building on the Cybersecurity Skills Academy.

Or. en

Amendment 9

Proposal for a regulation

Recital 172 h (new)

Text proposed by the CommissionAmendment
(172h) The European Cybersecurity Skills Framework should match the level of detail of leading international workforce frameworks, which decompose role profiles into discrete task, knowledge and skill statements, and should remain anchored in the European e-Competence Framework and interoperable with the European Skills, Competences, Qualifications and Occupations (ESCO) classification, so that education, training and attestation under this Regulation and the work of the Cybersecurity Skills Academy build on one common, machine-readable vocabulary.

Or. en

Amendment 10

Proposal for a regulation

Recital 172 i (new)

Text proposed by the CommissionAmendment
(172i) In order to ensure that the views of those affected by the implementation of this Regulation are gathered in a structured, regular and transparent manner, ENISA should consult and take into account the views of relevant stakeholders, including the open-source software community and small and medium-sized enterprises, in particular when preparing its programming documents, drafting technical specifications and guidance, preparing candidate certification and skills attestation schemes, contributing to Union-level coordinated security risk assessments, and preparing the evaluation and review of this Regulation, in line with the approach established by Article 9 of Regulation (EU) 2024/2847.

Or. en

Amendment 11

Proposal for a regulation

Recital 172 j (new)

Text proposed by the CommissionAmendment
(172j) The effectiveness of the expanded operational mandate conferred on ENISA is contingent upon the allocation of resources commensurate with the tasks entrusted to it. Any new task should be conferred on ENISA only where accompanied by corresponding appropriations and establishment plan posts. The cost of each such task should be separately identifiable in ENISA's single programming document.

Or. en

Amendment 12

Proposal for a regulation

Recital 172 k (new)

Text proposed by the CommissionAmendment
(172k) The preparation of candidate schemes needs predictability and legal certainty through binding time limits. Realistic duration, prior assessment of need and feasibility, and guaranteed involvement of the European standardisation organisations and stakeholders, together with a transparent extension mechanism for duly justified cases are prerequisites for their success.

Or. en

Amendment 13

Proposal for a regulation

Recital 172 l (new)

Text proposed by the CommissionAmendment
(172l) Technical specifications drafted by ENISA are a subsidiary and temporary instrument and European standardisation, carried out by the European standardisation organisations under Regulation (EU) No 1025/2012 of the European Parliament and of the Council1a, remains the primary route for the technical content of European cybersecurity certification schemes. ENISA specifications should therefore be admissible only where no adequate standard exists, should be based on existing European and international standards wherever possible, should trigger a parallel standardisation request, and should cease to apply once the corresponding standard is cited.
1a Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12, ELI: http://data.europa.eu/eli/reg/2012/1025/oj).

Or. en

Amendment 14

Proposal for a regulation

Recital 172 m (new)

Text proposed by the CommissionAmendment
(172m) Whereas certification delivers its simplification value where a single certificate demonstrates compliance across the corresponding cybersecurity requirements of Union law, certificates issued at assurance levels ‘substantial’ and ‘high’ should confer a presumption of conformity with such requirements by default, mapped explicitly in the scheme, accepted by authorities without renewed audit of the elements covered, and recognised in public procurement.

Or. en

Amendment 15

Proposal for a regulation

Recital 172 n (new)

Text proposed by the CommissionAmendment
(172n) Entities that generate and store energy connected to Union grids need effective Union-level supply chain security measures. The measures of this Regulation should therefore extend to grid-connected generation and storage equipment, apply irrespective of the corporate form through which components are supplied, and be reflected in the conditions of public support schemes.

Or. en

Amendment 16

Proposal for a regulation

Recital 172 o (new)

Text proposed by the CommissionAmendment
(172o) The designation of third countries and the listing of high-risk suppliers require uniform conditions of implementation throughout the Union and are indivisible in their effect. The committee procedure should therefore ensure that Member States are consulted on every draft act while preserving the capacity of the Commission to act rapidly and uniformly, including through immediately applicable acts where the security of ICT supply chains so requires.

Or. en

Amendment 17

Proposal for a regulation

Recital 172 p (new)

Text proposed by the CommissionAmendment
(172p) Customer premises equipment such as internet access routers constitutes a mass-deployed attack surface at the edge of fixed networks. In the electricity sector, power conversion equipment is a documented systemic risk: inverters are remotely accessible control points, undocumented communication devices have been found in such equipment, and one Member State has already legislated to cut remote access by manufacturers from countries designated as security threats, empowering grid operators to disconnect non-compliant installations. A prohibition of remote access is a proportionate intermediate measure between unrestricted use and full replacement, consistent with the requirement that restrictions be the least intrusive measure adequate to the risk.

Or. en

Amendment 18

Proposal for a regulation

Recital 172 q (new)

Text proposed by the CommissionAmendment
(172q) In order to ensure a high common level of security for the Union’s electronic communications networks, it is necessary to prohibit network operators from deploying specific critical equipment sourced from high-risk suppliers. However, in accordance with the principle of proportionality and the protection of consumer rights enshrined in Union law, such restrictions should not impose an undue financial burden on end-users. Consequently, this prohibition should not extend to terminal equipment, such as routers, that is the personal property of the consumer, provided such equipment has been lawfully placed on the Union market in compliance with relevant Union harmonisation legislation. Consumers should remain free to use legally acquired devices without interference. Furthermore, to ensure that that regulatory framework remains resilient against evolving technological threats, the Commission should be empowered to designate additional categories of connected devices subject to that restriction, to which those consumer safeguards shall apply mutatis mutandis.

Or. en

Amendment 19

Proposal for a regulation

Recital 172 r (new)

Text proposed by the CommissionAmendment
(172r) Exemptions from the prohibitions under this Regulation should remain limited for cases in which the Union interest so requires, should be granted individually, limited in time, subject to verifiable commitments and to revocation, and visible to the co-legislators. They should not develop into a parallel regime that undermines the uniform application of this Regulation.

Or. en

Amendment 20

Proposal for a regulation

Recital 172 s (new)

Text proposed by the CommissionAmendment
(172s) The obligations to phase out components of high-risk suppliers from fixed and satellite electronic communications networks should follow the sequence applied to mobile networks, in which a Union-level coordinated security risk assessment preceded coordinated mitigation and binding obligations. Time periods for such phase-outs should be laid down in this Regulation in order to provide legal certainty to operators and suppliers alike.

Or. en

Amendment 21

Proposal for a regulation

Recital 172 t (new)

Text proposed by the CommissionAmendment
(172t) Divergent national penalty practice invites establishment-based arbitrage. In order to ensure that penalties are dissuasive throughout the Union and that no Member State can become a low-enforcement jurisdiction of choice, this Regulation sets minimum as well as maximum penalty levels, provides for periodic penalty payments for continued non-compliance, and establishes Union-level transparency of national penalty practice.

Or. en

Amendment 22

Proposal for a regulation

Recital 172 u (new)

Text proposed by the CommissionAmendment
(172u) In accordance with the established case law of the Court of Justice of the European Union, the fact that a measure concerns national security does not render Union law inapplicable. Divergent national measures concerning suppliers of ICT products and services have created obstacles to the internal market, including diverging restrictions, timelines and compensation regimes that are the subject of litigation in several Member States. A harmonised Union framework is therefore necessary for the establishment and functioning of the internal market.

Or. en

Amendment 23

Proposal for a regulation

Recital 172 v (new)

Text proposed by the CommissionAmendment
(172v) Communities and projects that openly develop, maintain and distribute software, where no contractual relationship exists beyond adherence to a standardised licence, or where the relationship is with an open-source software steward as defined in Regulation (EU) 2024/2847, should not be considered suppliers for the purposes of this Regulation and their software should not be considered to form part of the ICT supply chain. Free and open-source software can serve as a mitigating measure in ICT supply chains, diversifying supply and limiting vendor lock-in.

Or. en

Amendment 24

Proposal for a regulation

Article 1 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. The mere fact that a Member State invokes its responsibility for safeguarding national security shall not, in itself, render this Regulation, or any measure adopted pursuant to it, inapplicable, nor relieve that Member State of its obligations thereunder.

Or. en

Amendment 25

Proposal for a regulation

Article 2 – paragraph 1 – point 16

Text proposed by the CommissionAmendment
(16) ‘ICT product’ means an element or a group of elements of a network or information system;(16) ‘ICT product’ means an element or a group of elements of a network and information system made available on the Union market in the course of a commercial activity;

Or. en

Amendment 26

Proposal for a regulation

Article 2 – paragraph 1 – point 38 a (new)

Text proposed by the CommissionAmendment
(38a) ‘supplier’ means any natural or legal person who, in the course of a commercial activity and in the context of a contractual relationship, supplies an ICT component or a component that includes ICT components for distribution or use on the Union market, whether in return for payment or free of charge;

Or. en

Amendment 27

Proposal for a regulation

Article 2 – paragraph 1 – point 39 – introductory part

Text proposed by the CommissionAmendment
(39) ‘high-risk supplier’ means either of the following:(39) ‘high-risk supplier’ means a supplier that is either of the following:

Or. en

Amendment 28

Proposal for a regulation

Article 2 – paragraph 1 – point 39 – point a

Text proposed by the CommissionAmendment
(a) an entity established in a third country posing cybersecurity concerns designated in accordance with Article 100, or controlled by such third country, by an entity established in such third country, or by a national of such third country;(a) an entity in respect of which the assessment referred to in Article 104, completed on the basis of the evaluation matrix set out in Annex IV, has established a high risk;

Or. en

Amendment 29

Proposal for a regulation

Article 2 – paragraph 1 – point 40

Text proposed by the CommissionAmendment
(40) ‘ICT supply chain’ means a sum of ICT services, ICT products and ICT processes that encompass activities and actors involved at all stages upstream of a product being made available or a service being delivered on the market;(40) ‘ICT supply chain’ means a sum of ICT services, ICT products and ICT processes that encompass activities and actors connected by contractual relationships at all stages upstream of a product being made available or a service being delivered on the market;

Or. en

Amendment 30

Proposal for a regulation

Article 12 – paragraph 2

Text proposed by the CommissionAmendment
2. Early alerts referred to in Article 11(1), first subparagraph, point (b), shall be issued as soon as possible to the CSIRT or CSIRTs concerned, and, where appropriate, to the CSIRTs network and EU-CyCLONe.2. Early alerts referred to in Article 11(1), first subparagraph, point (b), shall be issued as soon as possible to the CSIRT or CSIRTs concerned and, to the CSIRTs network and EU-CyCLONe.

Or. en

Amendment 31

Proposal for a regulation

Article 12 – paragraph 3

Text proposed by the CommissionAmendment
3. ENISA shall offer an early alert service to entities operating in sectors listed in Annexes I and II to Directive (EU) 2022/2555.3. ENISA shall offer an early alert service to entities operating in sectors listed in Annexes I and II to Directive (EU) 2022/2555. That service shall complement the tasks of the CSIRTs. Every alert disseminated under the service shall be transmitted to the CSIRTs concerned before or simultaneously with its dissemination to entities. Where the CSIRT concerned has issued an advisory on the same threat or vulnerability, the alert shall reference that advisory.

Or. en

Amendment 32

Proposal for a regulation

Article 12 – paragraph 4

Text proposed by the CommissionAmendment
4. The service referred to in paragraph 3 shall be provided upon a request of the entity and in a machine-readable format made publicly available. That service shall include sharing of information on cyber threat indicators and recommendations on mitigation measures.4. The service referred to in paragraph 3 shall be provided upon a request of the entity, without prejudice to notification channels and obligations established under Directive (EU) 2022/2555, and in a machine-readable format made publicly available. That service shall include sharing of information on cyber threat indicators and recommendations on mitigation measures. Participation shall be voluntary and shall not lead to any form of detrimental treatment of entities that do not participate.

Or. en

Amendment 33

Proposal for a regulation

Article 12 – paragraph 5

Text proposed by the CommissionAmendment
5. ENISA shall establish a procedure to disseminate the early alerts to entities referred to in paragraph 3.5. ENISA shall establish, by … [six months after the entry into force of this Regulation] and in agreement with the CSIRTs network, a procedure to disseminate the early alerts to entities referred to in paragraph 3. That procedure shall include rules on sequencing, routing and deduplication between alerts issued by ENISA and advisories issued by the CSIRTs, and shall be made publicly available.

Or. en

Amendment 34

Proposal for a regulation

Article 12 – paragraph 5 a (new)

Text proposed by the CommissionAmendment
5a. By … [two years after the entry into force of this Regulation] and every two years thereafter, ENISA shall review the functioning of the early alert service. The CSIRTs network shall deliver an opinion on that review, which shall be transmitted, together with the review, to the European Parliament and to the Council.

Or. en

Amendment 35

Proposal for a regulation

Article 13 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. When operating and administering the EU Cybersecurity Reserve, ENISA shall ensure that at least 60% of the pre-committed capacity of the EU Cybersecurity Reserve is procured from providers that are established in the Union and are not controlled by a third country or by an entity of a third country. ENISA shall report the share achieved, disaggregated by Member State of establishment and by service category, to the European Parliament and to the Council annually and in a machine-readable format.

Or. en

Amendment 36

Proposal for a regulation

Article 13 – paragraph 3

Text proposed by the CommissionAmendment
3. ENISA shall assist, in cooperation with Europol and CSIRTs or other competent authorities as applicable, individual essential and important entities listed in Annexes I and II to Directive (EU) 2022/2555 in preparing, responding to and recovering from a ransomware incident. For that purpose, ENISA shall establish a helpdesk and in particular make use of the enhanced shared situational awareness of the cyber threat and incident landscape pursuant to Article 11(1), first subparagraph, points (a) and (g) of this Regulation.3. ENISA shall assist, in cooperation with Europol and CSIRTs or other competent authorities as applicable, in preparing, responding to and recovering from a ransomware incident. For that purpose, ENISA shall establish a helpdesk as a single, uniform Union-level service, available in all official languages of the institutions of the Union and free of charge for the entities referred to in this paragraph, and in particular make use of the enhanced shared situational awareness of the cyber threat and incident landscape pursuant to Article 11(1), first subparagraph, points (a) and (g) of this Regulation.

Or. en

Amendment 37

Proposal for a regulation

Article 13 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
3a. The helpdesk referred to in paragraph 3 shall provide at least:
(a) initial triage of ransomware incidents;
(b) access to a repository of decryption keys and tools, integrating the repository of the No More Ransom initiative;
(c) guidance on containment, mitigation and recovery;
(d) referral of the entity to the CSIRT concerned and to the applicable reporting channels under Directive (EU) 2022/2555;
(e) guidance on the legal and practical implications of ransom payment.
ENISA shall conclude a working arrangement with Europol for the purposes of point (b) of the first subparagraph by… [six months after the entry into force of this Regulation].

Or. en

Amendment 38

Proposal for a regulation

Article 13 – paragraph 3 b (new)

Text proposed by the CommissionAmendment
3b. The helpdesk referred to in paragraph 3 shall be interoperable with national ransomware victim-support services where such services exist, and shall ensure that entities in Member States without such services receive an equivalent level of assistance. The use of the helpdesk shall be without prejudice to the tasks of CSIRTs.

Or. en

Amendment 39

Proposal for a regulation

Article 13 – paragraph 3 c (new)

Text proposed by the CommissionAmendment
3c. ENISA shall report annually to the European Parliament and to the Council on the functioning of the helpdesk referred to in paragraph 3, including the number of requests handled and the assistance provided, disaggregated by Member State and by sector, in a machine-readable format.

Or. en

Amendment 40

Proposal for a regulation

Article 13 – paragraph 3 d (new)

Text proposed by the CommissionAmendment
3d. The notification of a ransomware incident, including of a ransom payment, made to a competent authority, a CSIRT or through the single entry point referred to in Article 15a, shall not in itself give rise to liability of the notifying entity or of its management bodies and shall not constitute the sole basis for supervisory or enforcement action against them. This paragraph shall be without prejudice to liability for the underlying infringement of Union or national law.

Or. en

Amendment 41

Proposal for a regulation

Article 15 – paragraph 1

Text proposed by the CommissionAmendment
1. ENISA shall establish, provide, operate, maintain and update as necessary, operational technical tools, including platforms related to cybersecurity at Union level, in particular the single reporting platform established pursuant to Article 16(1) of Regulation (EU) 2024/2847 [and the single-entry point for incident reporting established pursuant to Article 23a of Directive (EU) 2022/2555], and testing tools to support the implementation of conformity assessment procedures in accordance with the relevant Union legislation.1. ENISA shall establish, provide, operate, maintain and update as necessary, operational technical tools, including platforms related to cybersecurity at Union level, in particular the single reporting platform established pursuant to Article 16(1) of Regulation (EU) 2024/2847 and the single entry point for incident reporting established pursuant to Article 15a of this Regulation, and testing tools to support the implementation of conformity assessment procedures in accordance with the relevant Union legislation.

Or. en

Amendment 42

Proposal for a regulation

Article 15 – paragraph 2

Text proposed by the CommissionAmendment
2. Where appropriate for the purposes of paragraph 1, ENISA shall cooperate and exchange information with the CSIRTs network and, where applicable, market surveillance authorities.2. Where appropriate for the purposes of paragraph 1, ENISA shall cooperate and exchange information with the CSIRTs network, the competent authorities designated under the Union legal acts referred to in Article 15a(1), the European Data Protection Board, the European Data Protection Supervisor, the European Supervisory Authorities established by Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010 and, where applicable, market surveillance authorities.

Or. en

Amendment 43

Proposal for a regulation

Article 15 a (new)

Text proposed by the CommissionAmendment
Article 15a
Single entry point for incident reporting
1. ENISA shall establish, operate and maintain a single entry point for incident reporting through which entities may submit the notifications required under Union legal acts, where those Union legal acts so provide, including Articles 23 and 30 of Directive (EU) 2022/2555, Article 33 of Regulation (EU) 2016/679, Article 19 of Regulation (EU) 2022/2554, Articles 19a, 24 and 45a of Regulation (EU) No 910/2014, Article 15 of Directive (EU) 2022/2557 and Article 14 of Regulation (EU) 2024/2847 (the ‘single entry point’). The single entry point shall build on the single reporting platform established pursuant to Article 16(1) of Regulation (EU) 2024/2847.
2. The single-entry point shall be designed to ensure that:
(a) a single submission by an entity fulfils all reporting obligations applicable to the same incident under the Union legal acts referred to in paragraph 1;
(b) each submission is transmitted without delay to the competent authorities and CSIRTs designated by the Member State concerned under the relevant Union legal act, which shall be the sole addressees of the submission and shall remain responsible for its handling in accordance with that act;
(c) entities can retrieve, supplement and correct information they have previously submitted;
(d) national entry points and existing national reporting systems designated by Member States are connected to the single entry point through open, documented, machine-readable interfaces, so that a submission through a connected national system is a submission to the single entry point and a submission to the single entry point is a submission to the connected national system;
(e) entities are identified and authenticated through the European Business Wallet or through electronic identification means notified pursuant to Regulation (EU) No 910/2014;
(f) submissions may be made in all official languages of the Union and the single entry point complies with the accessibility requirements of Directive (EU) 2016/2102 of the European Parliament and of the Council1a;
(g) ENISA makes available, by … [18 months after the entry into force of this Regulation], an open-source reference implementation which Member States may use to establish or connect their national entry point;
(h) the single entry point provides guided navigation identifying, for each submission, the applicable reporting obligations, definitions, thresholds, deadlines, formats, procedures, language requirements and competent authorities and CSIRTs, including their contact details, on the basis of information communicated by the Member States, which they shall keep up to date.
3. ENISA shall implement technical, operational and organisational measures ensuring the confidentiality, integrity and availability of the single entry point and of the information submitted, transmitted or retrieved through it, covering its development, establishment, maintenance and operation.
Those measures shall in all cases ensure that:
(a) the content of a submissions is encrypted end-to-end by default between the notifying entity and the addressee authorities referred to in paragraph 2, point (b);
(b) ENISA has no access to the content of submissions, unless a Union legal act referred to in paragraph 1 expressly provides so and ENISA processes only the metadata strictly necessary for the operation of the single entry point and aggregated, anonymised statistics;
(c) the content of a submission is not retained on infrastructure operated by ENISA beyond confirmation of its receipt by the addressee authorities and in any event not longer than 72 hours;
(d) the architecture is federated so that no single component holds the incident data of more than one Member State and the compromise of one component does not expose submissions addressed to the authorities of other Member States;
(e) the security measures are at least equivalent to those required under Article 21 of Directive (EU) 2022/2555 and Regulation (EU, Euratom) 2023/2841;
(f) an independent security audit is carried out before the single entry point is enabled for any Union legal act and every 2 years thereafter.
The summary of each audit referred to in the first subparagraph, point (f) shall be transmitted to the European Parliament, the Council, the Commission and the CSIRTs network.
ENISA shall consult the European Data Protection Supervisor before adopting the measures referred to in this paragraph.
4. Information submitted through the single entry point shall be shared with authorities other than the addressee authorities referred to in paragraph 2, point (b), only where the relevant Union legal act so provides or with the agreement of the Member State of the addressee authority.
5. Where a submission indicates that the incident affects or is likely to affect entities or services in another Member State, the single entry point shall notify without delay the CSIRTs of the Member States concerned of the existence, the sector and the type of the incident. The content of the submission shall be shared only in accordance with paragraph 4.
6. ENISA shall be responsible for the availability and integrity of the single entry point. The single entry point shall issue to the notifying entity a timestamped acknowledgement of receipt and of transmission to the addressee authorities. A reporting obligation under a Union legal act referred to in paragraph 1 shall be deemed fulfilled at the time indicated in the acknowledgement of transmission. The single entry point shall be available at least 99.9 per cent of the time in each calendar month. Where the single entry point is unavailable, entities shall fulfil their reporting obligations through alternative means made publicly available by the addressee authorities, and ENISA shall notify the Commission and the CSIRTs network of any unavailability exceeding one hour, stating its cause and duration.
7. ENISA shall adopt the technical, operational and organisational specifications of the single entry point in cooperation with the Commission, the CSIRTs network, the NIS Cooperation Group, the competent authorities under the Union legal acts referred to in paragraph 1, the European Data Protection Board and the European Supervisory Authorities, and after a public consultation of at least 6 weeks. ENISA shall transmit the specifications simultaneously to the European Parliament, the Council and the Commission and shall publish them.
8. ENISA shall pilot the functioning of the single entry point for each Union legal act referred to in paragraph 1 by … [12 months after the entry into force of this Regulation]. The Commission shall assess the proper functioning, reliability, integrity and confidentiality of the single entry point after consulting the CSIRTs network and the competent authorities under those acts and shall, where the assessment is positive, publish a notice to that effect in the Official Journal of the European Union by … [18 months after the entry into force of this Regulation]. Where the assessment is negative, ENISA shall take all necessary corrective measures within 3 months of the publication of that notice and the Commission shall reassess the proper functioning, reliability, integrity and confidentiality of the single entry point. Where no notice has been published by … [24 months after the entry into force of this Regulation], the Commission shall submit to the European Parliament and the Council a report stating the reasons for the failure to publish and a binding timeline for publication.
9. By … [6 months after the entry into force of this Regulation], the Commission shall submit to the European Parliament and the Council a report identifying common definitions, thresholds, deadlines, formats and procedures for the reporting obligations under the Union legal acts referred to in paragraph 1. That report shall be accompanied by a legislative proposal aligning those obligations. ENISA shall, by … [12 months after the entry into force of this Regulation] and every 2 years thereafter, adopt guidelines harmonising notification templates, sectoral thresholds and the stages of notification across those acts.
10. ENISA shall, by 31 March each year, publish in a machine-readable format and transmit to the European Parliament, the Council and the Commission a report on the single entry point containing the following:
(a) the number of submissions per Union legal act, per sector and per Member State, in aggregated form;
(b) the availability of the single entry point and a description of each period of unavailability exceeding one hour;
(c) the incidents affecting the single entry point itself and the measures taken;
(d) the national entry points and national reporting systems connected pursuant to paragraph 2, point (d), and those not yet connected, with the reasons communicated by the Member States concerned.
1a Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies (OJ L 327, 2.12.2016, p. 1, ELI: http://data.europa.eu/eli/dir/2016/2102/oj).

Or. en

Amendment 44

Proposal for a regulation

Article 17 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. By way of derogation from the threshold referred to Article 13(1a), where the capacity available from providers fulfilling the conditions set out in points (k) and (l) of paragraph 2 is demonstrably insufficient to meet the deployment needs of the EU Cybersecurity Reserve, services may be procured from providers established in trusted, like-minded international partners within the meaning of this Regulation. The Commission shall document the insufficiency, notify the European Parliament and the Council without delay, and review each such procurement at the latest every two years.

Or. en

Amendment 45

Proposal for a regulation

Article 17 – paragraph 2 b (new)

Text proposed by the CommissionAmendment
2b. ENISA shall make available, free of charge, self-assessment tools including maturity scoring, policy templates and standard-mapping tools supporting the implementation of the European cybersecurity certification schemes covering the cyber posture of entities.

Or. en

Amendment 46

Proposal for a regulation

Article 18 – paragraph 1

Text proposed by the CommissionAmendment
1. ENISA shall draft technical specifications and guidance to support the implementation of Union legislation in the field of cybersecurity. When drafting those technical specifications, ENISA shall consider existing European and international standards as well as other relevant technical specifications. ENISA shall ensure the consistency of its technical specifications and guidance.1. ENISA may draft technical specifications and guidance to support the implementation of Union legislation in the field of cybersecurity when the following conditions are fulfilled:
(a) there is no harmonised standard covering those requirements the reference of which is published in the Official Journal of the European Union and no such reference is expected to be published within a reasonable period; and
(b) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft or to revise European standards for those requirements, and:
(i) the request has not been accepted by any of the European standardisation organisations to which the request was addressed; or
(ii) the request has been accepted by at least one of the European standardisation organisations to which the request was addressed, but the European standards requested:
(1) are not delivered within the deadline set in the request;
(2) do not comply with the request; or
(3) do not satisfy the requirements they aim to cover.
When drafting the technical specifications referred to in the first subparagraph, ENISA shall take as their basis existing European and international standards as well as other relevant technical specifications. ENISA shall ensure the consistency of its technical specifications and guidance.

Or. en

Amendment 47

Proposal for a regulation

Article 19 – paragraph 2

Text proposed by the CommissionAmendment
2. The ECSF shall define profiles of cybersecurity professionals and association of specific tasks, skills and knowledge to a given role profile. The use of the ECSF shall be voluntary for public and private entities.2. The ECSF shall define profiles of cybersecurity professionals and associate specific tasks, skills and knowledge statements to each given role profile, together with competence levels aligned with the European e-Competence Framework. The ECSF shall be published in a machine-readable, versioned format. The use of the ECSF shall be voluntary for public and private entities.

Or. en

Amendment 48

Proposal for a regulation

Article 19 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. ENISA shall publish and maintain mapping tables between the ECSF and the European e-Competence Framework, the European Skills, Competences, Qualifications and Occupations (ESCO) classification, and relevant international cybersecurity workforce frameworks, and shall keep those mappings up to date with each update of the ECSF.

Or. en

Amendment 49

Proposal for a regulation

Article 19 – paragraph 3

Text proposed by the CommissionAmendment
3. ENISA may consult stakeholders in the development and uptake of the ECSF.3. ENISA shall consult stakeholders in the development and uptake of the ECSF.

Or. en

Amendment 50

Proposal for a regulation

Article 19 – paragraph 4

Text proposed by the CommissionAmendment
4. ENISA shall assess the need to update the ECSF on a regular basis and, where relevant, update it.4. ENISA shall review the ECSF by … [three years after the entry into force of this Regulation] and every two years thereafter, and shall update it where the review so indicates. ENISA shall publish a report on each review, including a machine-readable record of the changes made.

Or. en

Amendment 51

Proposal for a regulation

Article 19 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. ENISA shall make available, free of charge, a self-assessment tool enabling individuals to assess their competences against the ECSF profiles and competence levels, and a mapping tool enabling employers to align positions with ECSF profiles. Union institutions, bodies, offices and agencies shall use the ECSF profiles in their vacancy notices for cybersecurity-related positions.

Or. en

Amendment 52

Proposal for a regulation

Article 19 – paragraph 4 b (new)

Text proposed by the CommissionAmendment
4b. By … [two years after the entry into force of this Regulation] and every two years thereafter, ENISA shall transmit to the European Parliament and to the Council a report on the cybersecurity workforce gap in the Union, disaggregated by ECSF profile and by Member State, together with an assessment of the uptake of the ECSF.

Or. en

Amendment 53

Proposal for a regulation

Article 20 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. In developing and maintaining European cybersecurity skills attestation schemes, ENISA shall take into account the needs of national, regional and local public authorities, including role profiles under the ECSF relevant to the implementation of this Regulation, such as policy leads, technical evaluators, procurement officers and auditors, and shall ensure that the schemes can support training pathways coordinated under the Cybersecurity Skills Academy so that attestations are consistent and recognised across Member States.

Or. en

Amendment 54

Proposal for a regulation

Article 21 – paragraph 5 – point e

Text proposed by the CommissionAmendment
(e) ensure that, at the request of the individual, electronic attestations of European individual cybersecurity skills attestations are issued as electronic attestations of attributes in a format that can be stored in the European Digital Identity Wallets set out in Regulation (EU) No 910/2014.(e) ensure that, at the request of the individual, electronic attestations of European individual cybersecurity skills attestations are also issued as electronic attestations of attributes in a format that can be stored in the European Digital Identity Wallets set out in Regulation (EU) No 910/2014.

Or. en

Amendment 55

Proposal for a regulation

Article 22 – paragraph 1

Text proposed by the CommissionAmendment
1. Applicants shall pay a fee to ENISA for the examination of their application. Authorised attestation providers shall pay a fee to ENISA for the maintenance of their authorisation.1. Applicants shall pay a fee to ENISA for the examination of their application. Authorised attestation providers shall pay a fee to ENISA for the maintenance of their authorisation. Fees shall be proportionate and shall not exceed the costs incurred. Reduced fees shall apply to applications concerning staff of public authorities, including regional and local authorities.

Or. en

Amendment 56

Proposal for a regulation

Article 35 – paragraph 5

Text proposed by the CommissionAmendment
5. The ENISA Advisory Group shall advise ENISA in respect of the performance of ENISA’s tasks, except for the application of the provisions of Titles III, IV and V of this Regulation. It shall in particular advise the Executive Director on the drawing up of a proposal for ENISA’s annual work programme, and on ensuring communication with the relevant stakeholders on issues related to the annual work programme.5. The ENISA Advisory Group shall advise ENISA in respect of the performance of ENISA’s tasks. It shall in particular advise the Executive Director on the drawing up of a proposal for ENISA’s annual work programme, and on ensuring communication with the relevant stakeholders on issues related to the annual work programme.

Or. en

Amendment 57

Proposal for a regulation

Article 44 – paragraph 8 a (new)

Text proposed by the CommissionAmendment
8a. The single programming document shall set out, for each task assigned by this Regulation, the appropriations and posts allocated to its performance in the year concerned, presented so that changes against the previous year are identifiable.

Or. en

Amendment 58

Proposal for a regulation

Article 45 – paragraph 9 a (new)

Text proposed by the CommissionAmendment
9a. The resources entered in ENISA’s budget and establishment plan shall be commensurate with the tasks assigned ENISA by this Regulation and by other Union legal acts. Where a Union legal act assigns a new task to ENISA, the accompanying financial statement shall identify the appropriations and posts required for its performance.

Or. en

Amendment 59

Proposal for a regulation

Article 45 – paragraph 9 b (new)

Text proposed by the CommissionAmendment
9b. ENISA shall report annually to the European Parliament, the Council and the Commission on the adequacy of its resources for the performance of its tasks, identifying:
(a) tasks whose performance is limited by available appropriations or posts;
(b) the appropriations and posts that would be required for full performance;
(c) the effect on the establishment plan;
(d) the measures taken to prioritise within existing resources.
The report shall be transmitted together with the draft single programming document and shall be published.

Or. en

Amendment 60

Proposal for a regulation

Article 69 – paragraph 1

Text proposed by the CommissionAmendment
1. Where necessary to achieve the objectives of this Regulation, ENISA shall cooperate with relevant stakeholders, such as the cybersecurity industry, the ICT industry, SMEs, entities operating in sectors listed in Annexes I and II to Directive (EU) 2022/2555, manufacturers, importers or distributors of products with digital elements within the meaning of Regulation (EU) 2024/2847, conformity assessment bodies notified under the European cybersecurity certification framework and Regulation (EU) 2024/2847, entities operating in the area of electronic identification means, consumer groups, and academic experts in the field of cybersecurity. To that end, ENISA may establish public-private partnerships.1. ENISA shall cooperate with relevant stakeholders, such as relevant Member State authorities, the cybersecurity industry, the ICT industry, SMEs, entities operating in sectors listed in Annexes I and II to Directive (EU) 2022/2555, manufacturers, importers or distributors of products with digital elements within the meaning of Regulation (EU) 2024/2847, the open-source software community, conformity assessment bodies notified under the European cybersecurity certification framework and Regulation (EU) 2024/2847, entities operating in the area of electronic identification means, consumer groups, academic experts in the field of cybersecurity, and relevant Union bodies, offices and agencies as well as expert groups established at Union level. To that end, ENISA may establish public-private partnerships.

Or. en

Amendment 61

Proposal for a regulation

Article 69 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. When preparing measures for the implementation of this Regulation, ENISA shall consult and take into account the views of the stakeholders referred to in paragraph 1. In particular, ENISA shall, in a structured manner, consult and seek the views of those stakeholders when:
(a) preparing the single programming document referred to in Article 44;
(b) drafting technical specifications and guidance referred to in Article 18 and Article 77;
(c) preparing a candidate European cybersecurity certification scheme referred to in Article 74 or a European individual cybersecurity skills attestation scheme referred to in Article 20;
(d) contributing to Union-level coordinated security risk assessments referred to in Article 99;
(e) undertaking preparatory work for the evaluation and review of this Regulation referred to in Article 120.

Or. en

Amendment 62

Proposal for a regulation

Article 69 – paragraph 1 b (new)

Text proposed by the CommissionAmendment
1b. A summary of the outcome of each consultation shall be made publicly available, without prejudice to Article 54. ENISA shall organise structured consultation sessions with stakeholders at least once a year.

Or. en

Amendment 63

Proposal for a regulation

Article 71 – paragraph 3

Text proposed by the CommissionAmendment
3. European cybersecurity certification shall be voluntary, unless otherwise specified in Union or national law.3. European cybersecurity certification shall be mandatory, unless otherwise expressly provided in Union law.

Or. en

Amendment 64

Proposal for a regulation

Article 71 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
3a. Entities of the type referred to in Annex I to Directive (EU) 2022/2555 shall obtain certification of their cyber posture of entities at assurance level ‘substantial’ within 12 months of the availability of the relevant European cybersecurity certification scheme, and at assurance level ‘high’ within 12 months where the Commission has identified their sector as critical pursuant to Article 99.

Or. en

Amendment 65

Proposal for a regulation

Article 71 – paragraph 3 b (new)

Text proposed by the CommissionAmendment
3b. ICT components deployed in key ICT assets shall hold a European cybersecurity certificate at assurance level ‘substantial’ or ‘high’, as specified in the relevant scheme, within 36 months of the availability of that scheme.

Or. en

Amendment 66

Proposal for a regulation

Article 71 – paragraph 3 c (new)

Text proposed by the CommissionAmendment
3c. Where a European cybersecurity certification scheme has applied to a category of ICT products, ICT services or ICT processes for at least [24] months, entities of the type referred to in Annexes I and II to Directive (EU) 2022/2555 shall procure and deploy within that category only ICT products, ICT services and ICT processes certified under that scheme.

Or. en

Amendment 67

Proposal for a regulation

Article 71 – paragraph 3 d (new)

Text proposed by the CommissionAmendment
3d. Compliance with paragraphs 3a, 3b and3c shall be supervised in accordance with Chapter VII of Directive (EU) 2022/2555. Certificates and EU statements of conformity shall be accepted as evidence of compliance in accordance with Article 78 of this Regulation.

Or. en

Amendment 68

Proposal for a regulation

Article 71 – paragraph 3 e (new)

Text proposed by the CommissionAmendment
3e. The obligations in paragraphs 3a, 3b and 3c shall apply only from the date on which the Commission has published a notice in the Official Journal of the European Union confirming, on the basis of a report by ENISA, that sufficient conformity assessment capacity is available for the category concerned. Small and medium-sized enterprises shall benefit from an additional period of 12 months and from the fee reductions provided for in the relevant scheme.

Or. en

Amendment 69

Proposal for a regulation

Article 71 a (new)

Text proposed by the CommissionAmendment
Article 71a
Certification costs, competition and support measures
1. The cost of obtaining, maintaining and renewing a European cybersecurity certificate or EU statement of conformity shall be reasonable and proportionate to the assurance level and the risk addressed, and shall not constitute an unjustified barrier to participation of undertakings, in particular SMEs, in the internal market.
2. The Commission, assisted by ENISA and the ECCG, shall monitor for each scheme, on the basis of data reported annually by Member States and their national accreditation bodies:
(a) the evolution of certification costs;
(b) the number and geographic distribution of accredited conformity assessment bodies;
(c) average waiting times for conformity assessment.
3. Member States and their national accreditation bodies shall facilitate the accreditation of additional conformity assessment bodies where monitoring indicates insufficient competition, and shall remove unjustified barriers to cross-border conformity assessment. Where, for a given scheme, fewer than three accredited bodies operate in the Union or average waiting times exceed six months, the Member States concerned shall ensure the accreditation of additional bodies within 12 months.
4. Where certification costs become disproportionate to its demonstrable benefits, the Commission may request that ENISA prepare a revised candidate scheme (simplified evaluation methods, reduced documentation, adjusted assurance levels) without lowering assurance.
5. The Commission and Member States shall encourage support measures reducing effective certification costs for SMEs such as shared testing infrastructure, pooled assessments, sector-led cost-sharing, financed as a priority through market-based or industry-led mechanisms.

Or. en

Amendment 70

Proposal for a regulation

Article 73 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. Every request shall be accompanied by a published assessment of the need for and feasibility of the envisaged scheme, including a mapping of existing European and international standards, an estimate of implementation costs for the entities concerned and an assessment of the availability of conformity assessment capacity.

Or. en

Amendment 71

Proposal for a regulation

Article 74 – paragraph 1

Text proposed by the CommissionAmendment
1. No later than 12 months after receiving a request from the Commission pursuant to Article 73, unless otherwise specified in the request, ENISA shall prepare a candidate European cybersecurity certification scheme that meets the requirements set out in Articles 80 and 81.1. No later than 24 months after receiving a request from the Commission pursuant to Article 73, unless a longer period is otherwise specified in the request, ENISA shall prepare a candidate European cybersecurity certification scheme that meets the requirements set out in Articles 80 and 81.

Or. en

Amendment 72

Proposal for a regulation

Article 74 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. Upon a reasoned request by ENISA, the Commission may extend the period referred to in paragraph 1 once, by no more than 6 months. The Commission shall inform the European Parliament and the Council of any extension and justification thereof without delay.

Or. en

Amendment 73

Proposal for a regulation

Article 74 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. The consultation process referred to in paragraph 4 shall include an open public consultation of no less than 60 days on the draft candidate scheme, which shall be published for that purpose.

Or. en

Amendment 74

Proposal for a regulation

Article 77 – paragraph 1

Text proposed by the CommissionAmendment
1. ENISA may develop technical specifications in view of a future European cybersecurity certification scheme or in support of the maintenance of a European cybersecurity certification scheme.1. ENISA may develop technical specifications in view of a future European cybersecurity certification scheme or in support of the maintenance of a European cybersecurity certification scheme, only where no European standard or harmonised standard covering the requirements concerned exists, or where the Commission, after consulting the European standardisation organisations, concludes by reasoned and published decision that existing standards do not adequately cover those requirements. When developing such technical specifications, ENISA shall take existing European and international standards as their basis wherever possible.

Or. en

Amendment 75

Proposal for a regulation

Article 77 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. Where ENISA develops technical specifications pursuant to paragraph 1, the Commission shall, without delay, request one or more European standardisation organisations to draft a European standard covering the same requirements in accordance with Regulation (EU) No 1025/2012. Upon the citation of such a standard, the corresponding technical specifications shall cease to apply for new certifications at the latest 12 months thereafter, and the scheme shall be updated accordingly.

Or. en

Amendment 76

Proposal for a regulation

Article 77 – paragraph 2

Text proposed by the CommissionAmendment
2. The technical specifications referred to in paragraph 1 of this Article shall be developed in a timely manner, with the support of the ECCG and its maintenance sub-groups and, where applicable, the corresponding ad hoc working group as referred to in Article 75(3). For this purpose, ENISA shall also seek contributions from relevant stakeholder groups taking into account the maintenance strategy referred to in Article 75(1).2. The technical specifications referred to in paragraph 1 of this Article shall be developed in a timely manner, with the support of the ECCG and its maintenance sub-groups and, where applicable, the corresponding ad hoc working group as referred to in Article 75(3). For this purpose, ENISA shall seek contributions from relevant stakeholder groups, including the European standardisation organisations, taking into account the maintenance strategy referred to in Article 75(1). ENISA shall publish a summary of the contributions received and of their treatment.

Or. en

Amendment 77

Proposal for a regulation

Article 78 – paragraph 1

Text proposed by the CommissionAmendment
1. Where a specific Union legal act so provides, a certificate issued under a European cybersecurity certification scheme shall demonstrate compliance and confer a presumption of conformity with corresponding requirements set out in that legal act.1. A certificate issued under a European cybersecurity certification scheme at assurance level ‘substantial’ or ‘high’ shall demonstrate compliance and confer a presumption of conformity with corresponding cybersecurity requirements set out in Union legal acts, in particular Article 21(2) of Directive (EU) 2022/2555, the essential cybersecurity requirements of Regulation (EU) 2024/2847 and the ICT risk management requirements of Regulation (EU) 2022/2554, unless the legal act concerned expressly provides otherwise.

Or. en

Amendment 78

Proposal for a regulation

Article 78 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. The implementing act adopting a European cybersecurity certification scheme shall identify, for each Union legal act concerned, the requirements with which certificates issued under the scheme confer a presumption of conformity, mapped to the security objectives and requirements of the scheme.

Or. en

Amendment 79

Proposal for a regulation

Article 78 – paragraph 1 b (new)

Text proposed by the CommissionAmendment
1b. Certification of the cyber posture of entities at the assurance levels corresponding to their categories shall confer a presumption of conformity with the cybersecurity risk-management measures laid down in Article 21(1) and (2) of Directive (EU) 2022/2555, in accordance with the corresponding provision of that Directive.

Or. en

Amendment 80

Proposal for a regulation

Article 78 – paragraph 1 c (new)

Text proposed by the CommissionAmendment
1c. Competent and supervisory authorities shall accept valid European cybersecurity certificates as evidence of the elements they cover and shall not subject those elements to renewed audit or verification in the absence of specific indications of non-conformity.

Or. en

Amendment 81

Proposal for a regulation

Article 78 – paragraph 1 d (new)

Text proposed by the CommissionAmendment
1d. In procurement procedures under Directives 2014/24/EU and 2014/25/EU, valid European cybersecurity certificates shall be deemed to satisfy the corresponding cybersecurity-related technical specifications and selection criteria.

Or. en

Amendment 82

Proposal for a regulation

Article 78 – paragraph 2

Text proposed by the CommissionAmendment
2. Evaluation activities under a European cybersecurity certification scheme shall be consistent with the corresponding Union legal act setting out the demonstration of compliance and the presumption of conformity. Where such evaluation activities are not specified in the corresponding Union legal act, the scheme shall specify them. A conformity assessment for certification granting the presumption of conformity with requirements set out in Union legislation shall be conducted by a third-party body.2. Evaluation activities under a European cybersecurity certification scheme shall be consistent with the corresponding Union legal act setting out the demonstration of compliance and the presumption of conformity. Where such evaluation activities are not specified in the corresponding Union legal act, the scheme shall specify them. A conformity assessment for certification granting the presumption of conformity with requirements set out in Union legislation shall be conducted by a third-party body except where the Union legal act concerned provides for conformity self-assessment, in which case the scheme may allow conformity self-assessment in accordance with Article 83 for the corresponding assurance level.

Or. en

Amendment 83

Proposal for a regulation

Article 81 – paragraph 1 – point d a (new)

Text proposed by the CommissionAmendment
(da) for schemes covering the cyber posture of entities: tiered sets of security controls scaled to the size, category and risk profile of the entity, including an entry-level profile with a limited set of controls available free of charge to microenterprises and small enterprises; machine-readable mapping tables linking each control to relevant European standards, and comparable international frameworks; and a maturity-scoring methodology for the assessment of each control;

Or. en

Amendment 84

Proposal for a regulation

Article 81 – paragraph 3 – point e a (new)

Text proposed by the CommissionAmendment
(ea) for schemes covering the cyber posture of entities: the conditions under which certificates issued against equivalent international standards, are recognised as fulfilling the requirements of the scheme, on the basis of a statement of applicability demonstrating equivalence of the control set.

Or. en

Amendment 85

Proposal for a regulation

Article 82 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. A European cybersecurity certification scheme covering the cyber posture of entities shall specify all three assurance levels. The scheme shall provide that certification at assurance level “high” corresponds to the risk profile of essential entities and certification at assurance level “substantial” corresponds to the risk profile of important entities within the meaning of Directive (EU) 2022/2555, and that the entry-level profile referred to in Article 81(1), point (da), of this Regulation corresponds to assurance level “basic”.

Or. en

Amendment 86

Proposal for a regulation

Article 83 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. A European cybersecurity certification scheme covering the cyber posture of entities may provide for the verification of conformity by self-assessment or by a conformity assessment body. Verified self-assessments shall be identified by a distinct mark or label, clearly distinguishable from the marks or labels referring to third-party certification.

Or. en

Amendment 87

Proposal for a regulation

Article 86 – paragraph 2

Text proposed by the CommissionAmendment
2. Member States shall not introduce new national cybersecurity certification schemes or related procedures for the ICT products, ICT services, ICT processes, managed security services and cyber posture of entities already covered by the subject matter and scope of a European cybersecurity certification scheme.2. Member States shall not introduce new national cybersecurity certification schemes or related procedures for the ICT products, ICT services, ICT processes, managed security services and cyber posture of entities already covered by the subject matter and scope of a European cybersecurity certification scheme or of a request made pursuant to Article 73.

Or. en

Amendment 88

Proposal for a regulation

Article 86 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. Member States shall not impose additional cybersecurity certification requirements, or require additional national conformity assessments, as a condition for the placing on the market, the provision or the use of ICT products, ICT services, ICT processes or managed security services holding a valid European cybersecurity certificate covering the subject matter concerned. Measures maintained or adopted pursuant to Article 117a shall not take the form of certification requirements covering the same subject matter as a European cybersecurity certificate. This paragraph is without prejudice to the supervisory powers of competent authorities under Directive (EU) 2022/2555 and shall not apply to requirements concerning information systems handling classified information or to procurement falling within the scope of Directive 2009/81/EC of the European Parliament and of the Council1a or to which Article 346 TFEU applies.
1a Directive 2009/81/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of procedures for the award of certain works contracts, supply contracts and service contracts by contracting authorities or entities in the fields of defence and security, and amending Directives 2004/17/EC and 2004/18/EC (OJ L 216 20.8.2009, p. 76, ELI: http://data.europa.eu/eli/dir/2009/81/oj)

Or. en

Amendment 89

Proposal for a regulation

Article 86 – paragraph 3

Text proposed by the CommissionAmendment
3. Existing certificates that were issued under national cybersecurity certification schemes and are covered by the subject matter and scope of a European cybersecurity certification scheme shall remain valid until their expiry date.3. Existing certificates that were issued under national cybersecurity certification schemes and are covered by the subject matter and scope of a European cybersecurity certification scheme shall remain valid until their expiry date. European cybersecurity certification schemes shall provide for a simplified assessment procedure for holders of such national certificates, giving credit for evaluation results already obtained where the underlying requirements are equivalent to those of European cybersecurity certification schemes.

Or. en

Amendment 90

Proposal for a regulation

Article 86 – paragraph 4

Text proposed by the CommissionAmendment
4. Member States shall notify the Commission and the ECCG before adopting new national cybersecurity certification schemes for ICT products, ICT services, ICT processes, managed security services and cyber posture of entities.4. Member States shall notify the Commission and the ECCG of any draft national cybersecurity certification scheme at least 3 months before adopting such a scheme. The Commission and the ECCG may issue an opinion within that period, of which the Member State concerned shall take utmost account.

Or. en

Amendment 91

Proposal for a regulation

Article 86 – paragraph 5

Text proposed by the CommissionAmendment
5. The Commission may suggest to a Member State to withdraw a national cybersecurity certification scheme for ICT products, ICT services, ICT processes, managed security services or cyber posture of entities, where the development of a European cybersecurity certification scheme covering such products, services, processes or cyber posture has already been requested in accordance with Article 73, taking into account the development plan of such scheme.5. Where a request has been made pursuant to Article 73, Member States shall suspend the development and adoption of national cybersecurity certification schemes covering the same subject matter and scope. National schemes covering such subject matter shall be withdrawn no later than 12 months after the date of application of the European cybersecurity certification scheme concerned.

Or. en

Amendment 92

Proposal for a regulation

Article 98 – paragraph 3

Text proposed by the CommissionAmendment
3. The provisions laid down in this Chapter shall not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity in ICT supply chains, provided that such provisions are consistent with their obligations under in Union law.3. The provisions laid down in this Chapter shall not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity in ICT supply chains, provided that such provisions are consistent with their obligations under in Union law. For entities subject to Regulation (EU) 2022/2554, the obligations under this Title shall apply without duplication of supervision. Competent authorities shall coordinate with the authorities designated under that Regulation, and documentation produced to comply with the ICT risk management requirements of that Regulation shall be accepted as demonstrating compliance with the corresponding requirements of this Title.

Or. en

Amendment 93

Proposal for a regulation

Article 99 – paragraph 1

Text proposed by the CommissionAmendment
1. The Commission or a group of at least three Member States may request the Cooperation Group established by Article 14 of Directive (EU) 2022/2555 (‘NIS Cooperation Group’) to conduct the Union-level coordinated security risk assessments in accordance with Article 22 of that Directive. Where a security risk assessment is conducted following such request, it shall include in particular the proposed identification of the key ICT assets of the respective ICT supply chain as well as the main threat actors, risks and vulnerabilities affecting those assets. The Union-level coordinated security risk assessments shall develop risk scenarios and propose measures to mitigate the identified risks.1. The Commission or a Member State may request the Cooperation Group established by Article 14 of Directive (EU) 2022/2555 (‘NIS Cooperation Group’) to conduct the Union-level coordinated security risk assessments in accordance with Article 22 of that Directive. Where a security risk assessment is conducted following such request, it shall include in particular the proposed identification of the key ICT assets of the respective ICT supply chain as well as the main threat actors, risks and vulnerabilities affecting those assets. The Union-level coordinated security risk assessments shall develop risk scenarios and propose measures to mitigate the identified risks.

Or. en

Amendment 94

Proposal for a regulation

Article 99 – paragraph 2

Text proposed by the CommissionAmendment
2. The Union-level coordinated security risk assessments shall be completed within six months from the request referred to in paragraph 1. Upon request of the Commission, the NIS Cooperation Group may agree to a shorter period.2. The Union-level coordinated security risk assessments shall be completed within three months from the request referred to in paragraph 1. Upon request of the Commission, the NIS Cooperation Group may agree to a shorter period. Where the NIS Cooperation Group does not complete the assessment within the applicable period, the Commission shall finalise it without delay on the basis of the information available.

Or. en

Amendment 95

Proposal for a regulation

Article 99 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. Each Union-level coordinated security risk assessment shall be reviewed and, where necessary, updated two years after its completion and every two years thereafter, and without delay upon any significant development affecting the risks assessed.

Or. en

Amendment 96

Proposal for a regulation

Article 99 – paragraph 3 – point b

Text proposed by the CommissionAmendment
(b) conduct a security risk assessment, taking into account the consultation of the Member States. The security risk assessment shall include the proposed identification of the key ICT assets as well as the main threat actors, risks and vulnerabilities affecting those assets. The security risk assessment shall develop risk scenarios and propose measures to mitigate the identified risks.(b) conduct a security risk assessment, taking into account the consultation of the Member States, which shall be completed within one month. The security risk assessment shall include the proposed identification of the key ICT assets as well as the main threat actors, risks and vulnerabilities affecting those assets. The security risk assessment shall develop risk scenarios and propose measures to mitigate the identified risks.

Or. en

Amendment 97

Proposal for a regulation

Article 100 – title

Text proposed by the CommissionAmendment
Designation of third countries posing cybersecurity concernsIdentification of high risk suppliers

Or. en

Amendment 98

Proposal for a regulation

Article 100 – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
1. Where, as a result of the security risk assessment referred to in Article 99, or based on other sources, such as a public statement on behalf of the Union or a Member State, it appears that a third country poses a serious and structural non-technical risk to ICT supply chains, the Commission shall verify the risk posed by that country, taking into account the following elements:1. Where, as a result of the security risk assessment referred to in Article 99, it appears that a serious and structural non-technical risk to ICT supply chains exists, the Commission shall complete the evaluation matrix based on the criteria set in Annex IV and create a list of high-risk suppliers in accordance with Article 104(1).

Or. en

Amendment 99

Proposal for a regulation

Article 100 – paragraph 1 – point a

Text proposed by the CommissionAmendment
(a) the existence of laws in the third country which require entities under their jurisdiction to report information on software or hardware vulnerabilities to authorities of that third country prior to those vulnerabilities being known to have been exploited;deleted

Or. en

Amendment 100

Proposal for a regulation

Article 100 – paragraph 1 – point b

Text proposed by the CommissionAmendment
(b) existing practices in the third country, demonstrated by independent sources, that require entities under the jurisdiction of the third country to report information on software or hardware vulnerabilities to authorities of that third country prior to those vulnerabilities being known to have been exploited;deleted

Or. en

Amendment 101

Proposal for a regulation

Article 100 – paragraph 1 – point c

Text proposed by the CommissionAmendment
(c) the absence of effective judicial remedies, and independent and democratic control mechanisms, that can correct the identified security concerns, including about existing practices referred to in point (b);deleted

Or. en

Amendment 102

Proposal for a regulation

Article 100 – paragraph 1 – point d

Text proposed by the CommissionAmendment
(d) substantiated information about one or more incidents of threat actors controlled from that country and operating out of the territory of that country carrying out malicious cyber activities or campaigns, and the lack of ability or willingness of the third country to cooperate with the Commission or Member States to address the risk stemming from the operation of such threat actors;deleted

Or. en

Amendment 103

Proposal for a regulation

Article 100 – paragraph 1 – point e

Text proposed by the CommissionAmendment
(e) relevant information stemming from Union-level coordinated security risk assessments or reports by Member States or international organisations.deleted

Or. en

Amendment 104

Proposal for a regulation

Article 100 – paragraph 2

Text proposed by the CommissionAmendment
2. When the Commission, following the verification referred to in paragraph 1, concludes that a third country poses serious and structural non-technical risks to ICT supply chains, it may, by means of an implementing act, designate that third country as a country posing cybersecurity concerns to ICT supply chains. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 118(2).2. When the Commission, in accordance with the evaluation matrix referred to in paragraph 1, establishes the list of high-risk suppliers, it shall apply the process described in Article 104.

Or. en

Amendment 105

Proposal for a regulation

Article 100 – paragraph 3

Text proposed by the CommissionAmendment
3. The Commission shall review regularly the implementing acts adopted in accordance with paragraph 2.3. The Commission shall review regularly the lists established in accordance with Article 104(1), according to relevant information stemming from Union-level coordinated security risk assessments.

Or. en

Amendment 106

Proposal for a regulation

Article 100 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. Where an exemption is granted pursuant to Article 106 in respect of a high-risk supplier or specific ICT components, the exclusions provided for in paragraph 4 shall not apply to the extent and for the duration of that exemption.

Or. en

Amendment 107

Proposal for a regulation

Article 102 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. The Commission shall initiate the identification of key ICT assets pursuant to paragraph 1 for each category listed in Annex IIa by … [12 months of the entry into force of this Regulation], and shall inform the European Parliament and the Council of the outcome of each assessment. The Commission is empowered to adopt delegated acts in accordance with Article 119 to amend Annex IIa in the light of Union-level coordinated security risk assessments.

Or. en

Amendment 108

Proposal for a regulation

Article 103 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. The implementing acts referred to in paragraph 1 may, instead of or in addition to a prohibition on use, prohibit high-risk suppliers, and entities acting on their behalf, from maintaining remote access to key ICT assets, including for the purposes of software updates, maintenance or configuration, unless such access takes place under the control and supervision of the entity concerned.

Or. en

Amendment 109

Proposal for a regulation

Article 103 – paragraph 10 a (new)

Text proposed by the CommissionAmendment
10a. Key ICT assets connected to transmission or distribution systems shall not contain ICT components provided by high-risk suppliers. For installations existing on … [the date of application of this Regulation], the implementing acts referred to in paragraph 1 shall provide for mitigating measures, including:
(a) prohibition of transfers of data to third countries and of remote data processing from a third country;
(b) disabling of remote and non-essential access to key ICT assets;
(c) on-device processing and specific segmentation of network systems;
(d) operational network monitoring and testing of hardware and software;
(e) third-party audits of the measures under points (a) to (d).
Grid operators may be empowered to disconnect installations that do not comply with the measures referred to in the first subparagraph, points (a)–(e).

Or. en

Amendment 110

Proposal for a regulation

Article 103 – paragraph 10 b (new)

Text proposed by the CommissionAmendment
10b. The prohibitions and mitigating measures under this Title shall apply irrespective of licensing arrangements, white-labelling, local assembly, minority shareholdings, intermediaries or any other arrangement having the effect of supplying ICT components originating from a high-risk supplier. The Commission shall extend the application of the relevant measures to entities participating in such arrangements.

Or. en

Amendment 111

Proposal for a regulation

Article 104 – paragraph 1

Text proposed by the CommissionAmendment
1. By way of implementing acts, the Commission shall establish lists of high-risk suppliers relevant for the prohibitions laid down in the implementing acts adopted in accordance with Article 103(1), Article 103(7) or the prohibition referred to in Article 111(1).1. The Commission shall adopt delegated acts in accordance with Article 119, establishing lists of high-risk suppliers relevant for the prohibitions laid down in the implementing acts adopted in accordance with Article 103(1), Article 103(7) or the prohibition referred to in Article 111(1)and establishing the evaluation matrix template.

Or. en

Amendment 112

Proposal for a regulation

Article 104 – paragraph 2

Text proposed by the CommissionAmendment
2. For that purpose, the Commission shall map the suppliers providing ICT components and components that include ICT components relevant for the prohibition referred to in paragraph 1.deleted
On this basis, the Commission shall do an initial assessment to identify which of the mapped suppliers are potentially established in a third country designated in accordance with Article 100 or controlled by such third country, by an entity established in such third country or by a national of such third country. The Commission shall also do an initial mapping on suppliers potentially controlled by the entity referred to in Article 103(6).

Or. en

Amendment 113

Proposal for a regulation

Article 104 – paragraph 3

Text proposed by the CommissionAmendment
3. The Commission shall assess the place of establishment as well as the ownership and control structure of the suppliers initially identified in accordance with the second subparagraph of paragraph 2.deleted

Or. en

Amendment 114

Proposal for a regulation

Article 104 – paragraph 4

Text proposed by the CommissionAmendment
4. For the purpose of the assessment referred to in paragraph 3, the Commission shall be entitled to request the necessary information from the suppliers. In case the supplier does not provide the necessary information within the established deadline, the Commission may conclude that the supplier is established in a third country designated in accordance with Article 100 or controlled by such third country, by entities from that third country or by nationals of such third country. Where the Commission is carrying out an assessment for the purpose of Article 103(7) and the supplier does not provide the necessary information within the established deadline, the Commission may conclude that the supplier is controlled by an entity designated in line with that Article. The competent authorities referred to in Article 112 shall also share relevant information with the Commission upon request.4. For the purpose of the assessment referred to in paragraph 1, the Commission shall be entitled to request the necessary information from the suppliers. The deadline for suppliers to respond shall not exceed 30 working days. In case the supplier does not provide the necessary information within the established deadline, the Commission may conclude based on the available information. Where the Commission is carrying out an assessment for the purpose of Article 103(7) and the supplier does not provide the necessary information within the established deadline, the Commission may conclude that the supplier is controlled by an entity designated in line with that Article. The competent authorities referred to in Article 112 shall also share relevant information with the Commission upon request.

Or. en

Amendment 115

Proposal for a regulation

Article 104 – paragraph 5

Text proposed by the CommissionAmendment
5. The Commission shall share preliminary findings concerning the establishment, control and ownership assessment with the concerned supplier. The Commission shall grant the supplier an opportunity to be heard on those preliminary findings.5. The Commission shall share preliminary findings with the supplier concerned. The Commission shall grant the supplier an opportunity to be heard on those preliminary findings.

Or. en

Amendment 116

Proposal for a regulation

Article 104 – paragraph 6

Text proposed by the CommissionAmendment
6. The Commission may ask a competent authority to carry out the initial establishment, ownership and control assessment of a supplier, where justified in view of the characteristics of the operation of this supplier. A competent authority may offer to carry out such initial assessment. The Commission shall verify these initial findings in view of deciding whether the supplier should be included in the list of high-risk suppliers.6. The Commission may ask a competent authority to carry out the initial assessment of a supplier, where justified in view of the characteristics of the operation of this supplier. A competent authority may offer to carry out such initial assessment. The Commission shall verify these initial findings in view of deciding whether the supplier should be included in the list of high-risk suppliers.

Or. en

Amendment 117

Proposal for a regulation

Article 104 – paragraph 7

Text proposed by the CommissionAmendment
7. The Commission shall regularly update the list of high-risk suppliers in view of removing or adding high-risk suppliers. High-risk suppliers included in the list may request the Commission to re-assess their establishment, control and ownership structure upon provision of evidence that there have been relevant changes.7. The Commission shall regularly update the list of high-risk suppliers in view of removing or adding high-risk suppliers.

Or. en

Amendment 118

Proposal for a regulation

Article 104 – paragraph 8

Text proposed by the CommissionAmendment
8. Where a competent authority becomes aware, including on the basis of information provided by an entity of the type referred to in Annexes I and II to Directive (EU) 2022/2555 that a supplier may need to be included in a list of high-risk suppliers, it shall inform the Commission without undue delay.8. Where a competent authority becomes aware, including on the basis of information provided by an entity of the type referred to in Annexes I and II to Directive (EU) 2022/2555 that a supplier may need to be included in a list of high-risk suppliers, it shall notify the Commission without undue delay, together with the objective and substantiated information on which its concern is based. Upon receipt of such information, the Commission shall initiate the assessment provided for in this Article and, where relevant, in Article 99. A supplier shall not be included in a list of high-risk suppliers on the basis of such information alone. Any inclusion shall be subject to the assessment, evidentiary and procedural requirements laid down in this Article, including the right to be heard provided for in paragraph 5.

Or. en

Amendment 119

Proposal for a regulation

Article 104 – paragraph 8 a (new)

Text proposed by the CommissionAmendment
8a. The Commission shall inform the notifying competent authority of the follow-up of its notification. An aggregated overview of the notifications received under paragraph 8 and of their follow-up shall be included in the annual report to the European Parliament and the Council.

Or. en

Amendment 120

Proposal for a regulation

Article 104 – paragraph 8 b (new)

Text proposed by the CommissionAmendment
8b. In the assessments referred to in this Article, the public availability of the source code of the ICT components concerned, together with documented independent audit and coordinated vulnerability-handling practices, shall be considered as reducing the risk presented by a supplier.

Or. en

Amendment 121

Proposal for a regulation

Article 104 – paragraph 8 c (new)

Text proposed by the CommissionAmendment
8c. Where an entity has been designated as a high-risk supplier pursuant to this Article, the Commission shall, without undue delay and in consultation with ENISA, initiate a targeted assessment of the products with digital elements manufactured by that entity. That assessment shall be conducted within the framework of Regulation (EU) 2024/2847 to determine whether the continued availability of such products on the Union market, and in particular the consumer side, presents a significant cybersecurity risk. Should the assessment conclude that such a risk exists and cannot be adequately mitigated, the Commission shall, in cooperation with the competent market surveillance authorities, invoke the relevant safeguard procedures set out in Regulation (EU) 2024/2847, including the adoption of implementing acts to restrict the placing on the market, withdrawal or recall of the affected products from the Union market.

Or. en

Amendment 122

Proposal for a regulation

Article 105 – title

Text proposed by the CommissionAmendment
Exemption for entities established in or controlled by entities from a third country posing cybersecurity concernsExemptions for high-risk suppliers

Or. en

Amendment 123

Proposal for a regulation

Article 105 – paragraph 1 – introductory part

Text proposed by the CommissionAmendment
1. An entity established in or controlled by entities from a third country posing cybersecurity concerns designated in accordance with Article 100 may make a reasoned request to the Commission to be exempted:1. A high-risk supplier included in a list referred to in Article 104(1) may make a reasoned request to the Commission to be exempted:

Or. en

Amendment 124

Proposal for a regulation

Article 105 – paragraph 2 – point a

Text proposed by the CommissionAmendment
(a) specify the interest of the entity established in or controlled by entities from a third country posing cybersecurity concerns designated in accordance with Article 100 in being granted the exemption referred to in paragraph 1 of this Article; and(a) specify the interest of the high-risk supplier included in a list referred to in Article 104(1) in being granted the exemption referred to in paragraph 1 of this Article; and

Or. en

Amendment 125

Proposal for a regulation

Article 105 – paragraph 2 – point b

Text proposed by the CommissionAmendment
(b) demonstrate with clear evidence that effective mitigating measures will be put in place to address non-technical risks and ensure the absence of any possible exercise of undue interference by the third country designated pursuant to Article 100 in relation to the provision of ICT components or components that include ICT components for the use, installation or integration in key ICT assets of an entity of the type referred to in Annexes I and II to Directive (EU) 2022/2555.(b) demonstrate with clear evidence that effective mitigating measures will be put in place to address non-technical risks and ensure the absence of any possible exercise of undue interference by a third country in respect of which indicators in Part A of Annex IV are established in relation to the provision of ICT components or components that include ICT components for the use, installation or integration in key ICT assets of an entity of the type referred to in Annexes I and II to Directive (EU) 2022/2555.

Or. en

Amendment 126

Proposal for a regulation

Article 105 – paragraph 4 – point a

Text proposed by the CommissionAmendment
(a) the circumstances and additional elements referred to in Article 100(1) and (2) in relation to the designated country posing cybersecurity concerns to ICT supply chains where the entity is established or from where it is controlled;(a) the findings of the evaluation matrix set out in Annex IV in relation to the supplier and to the third country where it is established or from where it is controlled;

Or. en

Amendment 127

Proposal for a regulation

Article 105 – paragraph 4 – point c

Text proposed by the CommissionAmendment
(c) whether the exemption for the entity established in or controlled by entities from a third country posing cybersecurity concerns to ICT supply chains would not be detrimental to the Union’s interest.(c) whether the exemption for the high-risk supplier would not be detrimental to the Union’s interest.

Or. en

Amendment 128

Proposal for a regulation

Article 105 – paragraph 6 a (new)

Text proposed by the CommissionAmendment
6a. Exemptions shall be granted for a period not exceeding 24 months. They may be renewed once, upon a new reasoned request submitted no later than six months before expiry, where the conditions for granting them continue to be fulfilled.

Or. en

Amendment 129

Proposal for a regulation

Article 105 – paragraph 6 b (new)

Text proposed by the CommissionAmendment
6b. Every exemption decision shall specify the commitments of the entity concerned and the deadlines for their fulfilment. The beneficiary shall report to the Commission every six months on compliance. The Commission shall revoke the exemption where the commitments are not fulfilled or where the conditions for granting it cease to exist.

Or. en

Amendment 130

Proposal for a regulation

Article 105 – paragraph 6 c (new)

Text proposed by the CommissionAmendment
6c. Exemptions shall be granted only in respect of individual entities and specified key ICT assets. No exemption shall be granted for categories of entities or categories of ICT components.

Or. en

Amendment 131

Proposal for a regulation

Article 106 – paragraph 1

Text proposed by the CommissionAmendment
The Commission shall ensure that before it adopts an implementing act pursuant to Article 103(7) or before it adopts a decision refusing the granting of exemption pursuant to Article 105(7) on the basis of elements not submitted by the applicant or before it withdraws a decision pursuant to Article 105(8), the entity concerned is given the opportunity of being heard, taking into account the need, in some cases, for an urgency procedure.The Commission shall ensure that before it adopts an implementing act pursuant to Article 103(7) or before it adopts a decision refusing the granting of exemption pursuant to Article 105(7) on the basis of elements not submitted by the applicant or before it withdraws a decision pursuant to Article 105(8), the entity concerned is given the opportunity of being heard, taking into account the need, in some cases, for an urgency procedure. Entities subject to prohibitions or phase-out obligations under this Title, and high-suppliers included in the list referred to in Article 104(1), shall have access to effective judicial remedies. Decisions and implementing acts under this Title shall state the reasons on which they are based and shall be notified to their addressees.

Or. en

Amendment 132

Proposal for a regulation

Article 110 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. With regard to fixed and satellite electronic communications networks, the obligation laid down in the paragraph 1 shall apply only following the completion of a Union-level coordinated security risk assessment covering the network category concerned pursuant to Article 99. The Commission shall request that assessment by … [12 months after the entry into force of this Regulation].

Or. en

Amendment 133

Proposal for a regulation

Article 110 – paragraph 3

Text proposed by the CommissionAmendment
3. The time period for the phasing out the ICT components or components that include ICT components provided by high-risk suppliers with regard to mobile electronic communications networks shall not exceed 36 months from the publication of the list of high-risk suppliers referred to in Article 104 relevant for the mobile electronic communications networks.3. The time period for the phasing out the ICT components or components that include ICT components provided by high-risk suppliers with regard to mobile electronic communications networks shall not exceed 24 months from the publication of the list of high-risk suppliers referred to in Article 104 relevant for the mobile electronic communications networks.

Or. en

Amendment 134

Proposal for a regulation

Article 110 – paragraph 3 a (new)

Text proposed by the CommissionAmendment
3a. By way of exception, the competent authority may, by reasoned decision notified to the Commission without delay and made public, extend the period referred to in paragraph 3 by no more than 12 months for a given entity, where the entity demonstrates that compliance within that original period would impose a disproportionate burden within the meaning of Article 111a and that the extension does not create a serious risk to security. The Commission may object to that extension within two months.

Or. en

Amendment 135

Proposal for a regulation

Article 110 – paragraph 4

Text proposed by the CommissionAmendment
4. The Commission is empowered to adopt implementing acts in accordance with Article 118(2) to specify the time periods for the phasing out the ICT components or components that include ICT components provided by high-risk suppliers with regard to fixed and satellite electronic communications networks.4. The time period for the phasing out of the ICT components or components that include ICT components provided by high-risk suppliers with regard to fixed and satellite electronic communications networks shall not exceed 24 months from the publication of the relevant list of high-risk suppliers referred to in Article 104(1), without prejudice to paragraph 2, second subparagraph.

Or. en

Amendment 136

Proposal for a regulation

Article 110 – paragraph 4 a (new)

Text proposed by the CommissionAmendment
4a. Before adopting any act pursuant to paragraph 4 and before any time period pursuant to that paragraph begins to run, the Commission shall submit to the European Parliament and to the Council a report setting out, for each network category concerned, disaggregated data on the presence of ICT components provided by high-risk suppliers. Draft implementing acts pursuant to this Article shall be transmitted to the European Parliament at the same time as to the committee referred to in Article 118.

Or. en

Amendment 137

Proposal for a regulation

Article 110 – paragraph 5

Text proposed by the CommissionAmendment
5. The Commission is empowered to adopt delegated acts in accordance with Article 119 to amend Annex II to this Regulation in order to adapt it to technological developments by taking into account the elements referred to in Article 103(4).5. The Commission is empowered to adopt delegated acts in accordance with Article 119 to amend Annex II and IIa to this Regulation in order to adapt it to technological developments by taking into account the elements referred to in Article 103(4).

Or. en

Amendment 138

Proposal for a regulation

Article 111 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. Where compliance with a prohibition or phase-out obligation under this Title imposes a disproportionate burden on an entity, in particular in respect of ICT components lawfully acquired and deployed in good faith before … [the date of entry into force of this Regulation], Member States may provide for proportionate compensation mechanisms, as referred to in Article 17(1) of the Charter of Fundamental Rights.

Or. en

Amendment 139

Proposal for a regulation

Article 111 – paragraph 1 b (new)

Text proposed by the CommissionAmendment
1b. The assessment of disproportionality shall take into account the remaining depreciation period of the components concerned, the length of the applicable phase-out period, and the foreseeability of the restriction.

Or. en

Amendment 140

Proposal for a regulation

Article 111 – paragraph 1 c (new)

Text proposed by the CommissionAmendment
1c. The Commission shall adopt guidelines on the application of this Article by … [12 months after the entry into force of this Regulation] and shall report to the European Parliament and to the Council, every two years, on compensation granted under this Article, disaggregated by Member State.

Or. en

Amendment 141

Proposal for a regulation

Article 111 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. Member States shall make participation in support schemes, capacity mechanisms and tendering procedures for electricity generation and storage conditional upon the compliance of the equipment concerned with this Title.

Or. en

Amendment 142

Proposal for a regulation

Article 111 a (new)

Text proposed by the CommissionAmendment
Article 111a
1. Where compliance with a prohibition or phase-out obligation under this Title imposes a disproportionate burden on an entity, in particular in respect of ICT components lawfully acquired and deployed in good faith before … [the date of entry into force of this Regulation], Member States may provide for proportionate compensation mechanisms, as referred to in Article 17(1) of the Charter of Fundamental Rights.
2. Costs incurred by entities in replacing key ICT assets pursuant to Article 103 or Article 111 shall be eligible for support under relevant Union programmes, in particular the Digital Europe Programme and the Connecting Europe Facility, within their respective budgetary envelopes and award conditions. The Commission shall adopt guidelines on the assessment of disproportionate burden and on the calculation of compensation by … [12 months after the entry into force of this Regulation]. Member States shall take utmost account of those guidelines and shall report annually to the Commission on compensation granted, which the Commission shall publish in a machine-readable format.
3. The assessment of disproportionality shall take into account the remaining depreciation period of the components concerned, the length of the applicable phase-out period, and the foreseeability of the restriction.
4. The Commission shall adopt guidelines on the application of this Article by … [12 months after the entry into force of this Regulation] and shall report to the European Parliament and to the Council, every two years, on compensation granted under this Article, disaggregated by Member State.
5. Where the implementation of measures pursuant to Article 103 or Article 111 imposes a disproportionate burden on an entity, the Member State concerned shall provide compensation proportionate to the unrecoverable residual value of the assets concerned, as referred to in Article 17(1) of the Charter.

Or. en

Amendment 143

Proposal for a regulation

Article 114 – paragraph 7

Text proposed by the CommissionAmendment
7. The competent authorities shall cooperate with each other and with the Commission for the purposes of supervision and enforcement under this Title in accordance with Article 116.7. The Commission shall issue guidelines on the uniform application of this Article.

Or. en

Amendment 144

Proposal for a regulation

Article 114 – paragraph 7 a (new)

Text proposed by the CommissionAmendment
7a. The Commission shall have the power to overturn the competent authorities’ decisions that contravene the harmonised approach established through the guidelines pursuant to paragraph 7.

Or. en

Amendment 145

Proposal for a regulation

Article 115 – paragraph 5

Text proposed by the CommissionAmendment
5. Infringements of Article 103(2), point (a), shall, in accordance with paragraph 3 of this Article, be subject to penalties of a maximum of 1 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs.5. Infringements of Article 103(2), point (a), shall, in accordance with paragraph 3 of this Article, be subject to penalties of a maximum of 1 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, and of a minimum of 0,2 % of that turnover or EUR 1 000 000, whichever is higher.

Or. en

Amendment 146

Proposal for a regulation

Article 115 – paragraph 6

Text proposed by the CommissionAmendment
6. Infringements of Article 103(2), points (b) to (g), shall, in accordance with paragraph 3 of this Article, be subject to penalties of a maximum of 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs.6. Infringements of Article 103(2), points (b) to (g), shall, in accordance with paragraph 3 of this Article, be subject to penalties of a maximum of 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, and of a minimum of 0,5 % of that turnover or EUR 2 500 000, whichever is higher.

Or. en

Amendment 147

Proposal for a regulation

Article 115 – paragraph 7

Text proposed by the CommissionAmendment
7. Infringements of Article 103(1), and of Article 111 shall, in accordance with paragraph 3, of this Article be subject to penalties of a maximum of 7 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs.7. Infringements of Article 103(1), and of Article 111 shall, in accordance with paragraph 3, of this Article be subject to penalties of a maximum of 7 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the entity belongs, and of a minimum of 2 % of that turnover or EUR 10 000 000, whichever is higher. A reduction below the minimum shall be permitted only where the competent authority establishes, by reasoned and published decision, that the minimum would be disproportionate in the individual case.

Or. en

Amendment 148

Proposal for a regulation

Article 115 – paragraph 7 a (new)

Text proposed by the CommissionAmendment
7a. Where an entity fails to terminate an infringement of Article 103(1) or Article 111, the competent authority shall impose periodic penalty payments of up to 5 % of the average daily worldwide turnover of the undertaking concerned for each day of continued non-compliance, calculated from the date set in the decision establishing the infringement.

Or. en

Amendment 149

Proposal for a regulation

Article 115 – paragraph 7 b (new)

Text proposed by the CommissionAmendment
7b. The Commission shall adopt guidelines on the calculation and consistent application of penalties under this Article. Competent authorities shall report annually to the Commission all penalties imposed under this Title, including their amount, the infringement concerned and the turnover basis applied, and the Commission shall publish an annual overview disaggregated by Member State. Where the penalties imposed in a Member State deviate systematically from the guidelines, the Commission may address a recommendation to that Member State, and shall inform the European Parliament and the Council thereof.

Or. en

Amendment 150

Proposal for a regulation

Article 118 – paragraph 1

Text proposed by the CommissionAmendment
1. The Commission shall be assisted by a committee. That committee shall have two configurations. In respect of Titles II and III, the Commission shall be assisted by a committee in the first configuration, whereas in respect of Title IV, the Commission shall be assisted by a committee in the second configuration. That committee shall be committee within the meaning of Regulation (EU) No 182/2011.1. Implementing powers under this Regulation shall be exercised by the Commission. The Commission shall be assisted by a committee. That committee shall have two configurations. In respect of Titles II and III, the Commission shall be assisted by a committee in the first configuration, whereas in respect of Title IV, the Commission shall be assisted by a committee in the second configuration. That committee shall be committee within the meaning of Regulation (EU) No 182/2011.

Or. en

Amendment 151

Proposal for a regulation

Article 118 – paragraph 1 a (new)

Text proposed by the CommissionAmendment
1a. Where reference is made to this paragraph, Article 4 of Regulation (EU) No 182/2011 shall apply.

Or. en

Amendment 152

Proposal for a regulation

Article 118 – paragraph 2 – subparagraph 1 a (new)

Text proposed by the CommissionAmendment
Where the committee delivers no opinion, the Commission shall adopt the draft implementing act. The third subparagraph of Article 5(4) of Regulation (EU) No 182/2011 shall not apply.

Or. en

Amendment 153

Proposal for a regulation

Article 118 – paragraph 2 a (new)

Text proposed by the CommissionAmendment
2a. On duly justified imperative grounds of urgency relating to the security of ICT supply chains, the Commission shall adopt immediately applicable implementing acts in accordance with Article 8 of Regulation (EU) No 182/2011.

Or. en

Amendment 154

Proposal for a regulation

Article 120 – paragraph 1

Text proposed by the CommissionAmendment
1. By [DD MM YYYY], and every five years thereafter, the Commission shall commission an evaluation which shall be conducted in accordance with the Commission’s guidelines.1. By [DD MM YYYY], and every three years thereafter, the Commission shall commission an evaluation of ENISA’s performance. The evaluation shall include an assessment of the single entry point established pursuant to Article 15a, in particular the reduction of the reporting burden achieved for entities, the share of submissions fulfilling more than one reporting obligation, and the security of the single entry point.

Or. en

Amendment 155

Proposal for a regulation

Article 120 – paragraph 5 a (new)

Text proposed by the CommissionAmendment
5a. By … [18 months after the date of application of this Regulation] and every 2 years thereafter, the Commission shall assess the coherence of this Regulation with Directive (EU) 2022/2555, Regulation (EU) 2024/2847, Regulation (EU) 2022/2554, Directive (EU) 2022/2557 and the incident notification requirements of Regulation (EU) 2016/679, identifying duplications, divergent definitions, thresholds and time limits, and conflicting obligations. The assessment shall be transmitted to the European Parliament and the Council and shall be accompanied, where misalignments are identified, by legislative proposals to remove them.

Or. en

Amendment 156

Proposal for a regulation

Article 120 – paragraph 5 b (new)

Text proposed by the CommissionAmendment
5b. The report shall include an assessment of the functioning of the internal market for the ICT products and services concerned, of the divergence of national measures notified pursuant to Article 117a and of their effects, and shall be transmitted to the European Parliament and to the Council simultaneously.

Or. en

Amendment 157

Proposal for a regulation

Article 120 – paragraph 5 c (new)

Text proposed by the CommissionAmendment
5c. The report shall assess the interaction between this Regulation and [the Regulation establishing a framework of measures for strengthening Europe’s cloud and AI ecosystem (Cloud and AI Development Act)], in particular its cloud sovereignty framework, and shall verify that European cybersecurity certification schemes neither duplicate nor conflict with requirements adopted under that framework.

Or. en

Amendment 158

Proposal for a regulation

Annex II – subheading 1

Text proposed by the CommissionAmendment
Key ICT assets for mobile and fixed electronic communications networksKey ICT assets in critical infrastructure

Or. en

Amendment 159

Proposal for a regulation

Annex II – table 1

Text proposed by the Commission
Critical infrastructureKey ICT assets
1. 5G electronic communications networks (non-standalone and standalone)Core network functions of mobile communications networks
Network function virtualisation (NFV) and management and network orchestration (MANO)
Radio access network
2. Fixed electronic communications networksCore network functions of fixed electronic communications networks
Network management system
Transport and transmission network
Access network
3. Satellite electronic communications networksCore network function of satellite electronic communications networks
Network management system
Cryptographic products for the protection of telecommand/telemetry
Ground stations and complementary ground stations
Amendment
Critical infrastructureKey ICT assets
1. 5G electronic communications networks (non-standalone and standalone)Core network functions of mobile communications networks
Network function virtualisation (NFV) and management and network orchestration (MANO)
Radio access network
2. Fixed electronic communications networksCore network functions of fixed electronic communications networks
Network management system
Transport and transmission network
Access network
Customer premises equipment provided by or on behalf of providers of electronic communications networks or services, including internet access routers and modems, not including those that have been lawfully placed on the Union market and are the property of the end-user
3. Satellite electronic communications networksCore network function of satellite electronic communications networks
Network management system
Cryptographic products for the protection of telecommand/telemetry
Ground stations and complementary ground stations
Ground segment infrastructure of Union secure connectivity and infrastructure for governmental satellite communications programmes, including telemetry, tracking and command stations
4. Grid-connected OEM equipmentGrid-connected electricity generation and storage equipment and its control systems, including wind turbine control and monitoring systems, SCADA systems, inverters, battery management systems and remote monitoring and maintenance platforms not including those that have been lawfully placed on the Union market and are the property of the end-user

Or. en

Justification

This amendment modifies Annex II

Amendment 160

Proposal for a regulation

Annex IIa (new)

Text proposed by the Commission
Amendment
ANNEX IIa
Priority ICT asset categories for assessment under Article 102
Ref.Priority ICT asset category
PART A — Energy
A1power conversion and control equipment for electricity generation, storage and charging, including photovoltaic and wind power inverters and converters, battery energy storage control systems, and converters and management systems of recharging infrastructure for electric vehicles
A2grid-scale electricity storage systems, including their battery management systems
A3smart metering systems and grid edge devices
PART B — Electronic communications and connected devices
B1customer premises equipment for internet access, including routers and modems
B2cellular IoT modules
B3IoT connectivity modules and cloud platforms underlying connected devices marketed in the Union, irrespective of the brand under which such devices are sold
B4telematics and connected-vehicle platforms
PART C — Transport and logistics
C1automated cargo-handling and port-logistics equipment, including ship-to-shore cranes
C2ship-to-shore and yard cranes and their control and remote diagnostic systems
C3security screening and scanning equipment deployed at ports, airports and other transport hubs
C4connected control and fleet management systems of electric buses and rail rolling stock
C5logistics data platforms aggregating Union port, cargo or freight flows
C6unmanned aircraft systems used by entities of the type referred to in Annexes I and II to Directive (EU) 2022/2555, including their flight control and data platforms
PART D — Health
D1networked medical imaging and hospital devices
D2genomic sequencing platforms and their data processing systems
PART E — Physical security and surveillance
E1connected surveillance equipment
E2video surveillance and access control systems installed in the premises or networks of entities of the type referred to in Annexes I and II to Directive (EU) 2022/2555

Or. en

Justification

This amendment introduces a new Annex IIa

Amendment 161

Proposal for a regulation

Annex III a (new)

Text proposed by the CommissionAmendment
ANNEX IIIa
Evaluation matrix for the identification of high-risk suppliers referred to in Article 100(1) and Article 104
1. Function and scope.
For the purposes of Article 100(1) and Article 104, the Commission shall complete this evaluation matrix for each third country or supplier under assessment, and shall document, for every criterion applied, the evidence on which its conclusion is based. The matrix consolidates the country-risk criteria referred to in Article 100(1), the establishment, ownership and control assessment referred to in Article 104, and the evidentiary conditions of Article 104(3b). It applies, mutatis mutandis, to the identification of an entity under Article 103(6) and (7), independently of any finding under Part A.
2. Evidentiary standard.
A finding that one or more criteria in Parts A to C are met does not by itself result in a listing. Inclusion shall be based on specific and substantiated evidence relating to the supplier concerned.
3. The matrix

Or. en

Amendment 162

Proposal for a regulation

Annex III a – point 3 – table 1 (new)

Text proposed by the Commission
Amendment
Ref.Assessment factorLegal / methodological basisEffect on determination
PART A — Country-risk indicators (applied under Article 100(1))
A1Laws requiring mandatory pre-disclosure reporting of ICT vulnerabilities to the third country's authoritiesArt. 100(1)(a)Aggravating
A2Demonstrated A1 equivalent practice, evidenced by independent sourcesArt. 100(1)(b)Aggravating
A3Absence of effective judicial remedies and of independent, democratic oversight capable of correcting (A1)–(A2)Art. 100(1)(c)Aggravating
A4Use of special courts or administrative bodies outside democratic control and right to be heardArt. 100(1)(b)Aggravating
A5Existence of a centralized, decision-making system that is fundamentally adversarial to European Union objectives.Art. 100(1)(c)Aggravating
A6Substantiated incidents involving threat actors controlled from or operating out of the country, and its unwillingness to cooperateArt. 100(1)(d)Aggravating
A7Findings of Union-level coordinated security risk assessments and reports by Member States or international organisationsArt. 99; Art. 100(1)(e)Corroborating
B1Shareholding, voting or board-appointment rights held by the designated country, an entity established there, or its nationalsArt. 2(37)Establishes control
B2Special or veto rights, incl. “golden shares”, enabling decisive influence irrespective of shareholding sizeArt. 2(37)Establishes control
B3Contractual or technical control over software updates, source code, cryptographic keys or remote accessArt. 2(37)Establishes control
B4Financial dependency (debt, subsidy, procurement) capable of being leveraged for decisive influenceArt. 2(37)Aggravating
B5Overriding statutory or administrative obligations in the country of establishment (security or intelligence-cooperation laws)Cf. Art. 100(1)(a)–(b)Aggravating
B6Circumvention arrangements: licensing, white-labelling, local assembly, minority shareholdings, intermediariesAnti-circumvention principle (Title IV, by analogy)Look-through; does not defeat a finding
C1Criticality of the key ICT assets served and remote-access or update capability built into the componentsArt. 102(2); Annex II / IIaAggravating
C2Degree of market concentration or dependency the supplier's components would createArt. 103(4)(c), by analogyAggravating
C3Documented cyber incidents or threat-actor links attributable to the supplier or its supply chainArt. 100(1)(d)Aggravating
C4Failure to provide information requested under Article 104(4) within the applicable deadlineArt. 104(4)Adverse inference
D1Conformity with Regulation (EU) 2024/2847 and possession of a valid European cybersecurity certificateTitle III of this RegulationMitigating
D2Publicly available source code with documented independent audit and coordinated vulnerability-disclosure practiceArt. 104 (new para.)Mitigating – limited weight
D3Mitigation measures already effectively implemented in relation to the supplier's componentsArt. 103(2)Mitigating
E1Country of establishment/control is party to the WTO Agreement on Government Procurement or has a reciprocity agreement with the EUArt. 104(3a)(a)Presumption condition
E2That country grants Union suppliers full reciprocal access to its procurement and network marketsArt. 104(3a)(b)Presumption condition
E3That country has not been designated under Article 100Art. 104(3a)(c)Presumption condition
E4State access to data held by the supplier is subject to prior independent judicial authorisation and effective legal remediesArt. 104(3a)(d)Presumption condition; rebuttable on Part C evidence

Or. en

Amendment 163

Proposal for a regulation

Annex IIIa – point 4 (new)

Text proposed by the CommissionAmendment
4. Weighting and standard template.
The relative weighting of the criteria in Parts A to E, the scoring methodology and the standard template for completing the matrix shall be laid down by the Commission by means of a delegated act adopted in accordance with Article 119, and shall be reviewed periodically in the light of the Union-level coordinated security risk assessments referred to in Article 99. This Annex lays down the exhaustive list of criteria the Commission may take into account for that purpose. The delegated act referred to in this point shall not add new categories of criteria.

Or. en

Amendment 164

Proposal for a regulation

Annex IIIa – point 5 (new)

Text proposed by the CommissionAmendment
5. Procedural guarantees.
Before a supplier is included in a list referred to in Article 104(1), the Commission shall share its preliminary findings with the supplier concerned and grant it the opportunity to be heard, in accordance with Article 104(5). A request for information addressed to a supplier under Article 104(4) shall specify a response deadline not exceeding 30 working days. Ffailure to respond within that deadline shall be assessed in accordance with row C4. Listings shall be reviewed regularly and shall be re-assessed upon a reasoned request supported by evidence of a relevant change in circumstances, in accordance with Article 104(7).

Or. en

Explanatory statement 8 paragraphs

On 20 January 2026 the Commission presented its proposal for a Cybersecurity Act 2, Regulation COM (2026)0011, replacing Regulation (EU) 2019/881. The proposal broadens the mandate of the European Union Agency for Cybersecurity (ENISA), reforms the European cybersecurity certification framework and creates a Union framework for the security of ICT supply chains. The rapporteur welcomes the proposal and supports all three objectives. The Union needs one framework in this field rather than 27 national ones, coordination at Union level is necessary to avoid fragmentation and ensure consistent application. The draft report aims to ensure that this Regulation is implemented on the basis of evidence, within fixed deadlines, under recurring review and with Parliament informed at the same time as the Member States.

ENISA (Titles I and II)

The rapporteur supports ENISAs extended mandate and aims for a clearer scope and structure. A new article establishes the single-entry point for incident reporting: one submission fulfils the obligations under Directive (EU) 2022/2555, the GDPR, DORA, eIDAS, the CER Directive and the Cyber Resilience Act, while national authorities and the Computer Incident Response Teams (CSIRTs) remain the sole addressees. The system is federated, encrypted end to end by default, and ENISA has no access to content. Early alerts should reach the CSIRTs first. A ransomware helpdesk becomes a single Union service, free of charge and in all official languages. ENISA consults stakeholders in a structured manner, and no new task is conferred on it without the corresponding appropriations and posts.

European cybersecurity certification framework (Title III)

The rapporteur proposes to reverse the default in Article 71(3): certification becomes mandatory unless Union law expressly provides otherwise. Entities in the sectors of high criticality must certify their cyber posture within 12 months of a scheme becoming available, and the deployment of key ICT assets shall carry a certificate within 36 months. These obligations begin only once the Commission has confirmed sufficient conformity assessment capacity. SMEs will receive an additional 12 months and reduced fees. In return the certificate gains legal value: at level substantial and high it confers a presumption of conformity with Directive (EU) 2022/2555, the Cyber Resilience Act and DORA, for the specific cybersecurity requirements covered by the relevant certification scheme. Member States may not add national certification covering the same requirements and assurance objectives. European standardisation remains the primary source of technical content; ENISA drafts specifications only where no harmonised standard exists or a standardisation request has failed. The deadline for candidate schemes is set at 24 months, preceded by a published need and feasibility assessment.

Supply chain security (Title IV)

The rapporteur fully shares the objective of Article 100 and proposes to pursue it at the level of the supplier. The criteria the Commission proposed are preserved in full and applied, through an evaluation matrix in a new annex, to the supplier concerned, together with ownership and control, supplier specific evidence and mitigating factors. This gives the Commission a documented method and gives suppliers legal certainty. A listing requires specific and substantiated evidence, and a reasoned decision based on evidence and the right to be heard, will be taken. Judicial remedies are kept. Information from a national authority may initiate an assessment but will not in itself lead to a listing. Provisions against circumvention through licensing or intermediaries are introduced.

The risks addressed by Title IV extend beyond electronic communications, therefore a new Annex IIa lists priority categories to be assessed within 12 months. For mobile networks the phase out is shortened from 36 to 24 months, with one possible extension of 12 months for a specific cases. Fixed and satellite networks provisions will apply only after a Union level coordinated risk assessment. The Union and the Member States should ensure that the applicable fundamental-rights safeguards are respected and that any interference is justified, proportionate and accompanied, by appropriate remedial or compensatory measures.