Adopted text, 12 March 2024
Cyber Resilience Act
Document TA-9-2024-0130 · P9_TA(2024)0130 · PE745.538
AI:In short
Parliament adopted its first-reading position on the proposed Cyber Resilience Act, which sets horizontal cybersecurity requirements for products with digital elements and amends Regulation (EU) 2019/1020 and other acts. As Parliament and Council reached agreement, Parliament's position corresponds to the final act, Regulation (EU) 2024/2847. Parliament approves a joint statement by Parliament, the Council and the Commission on resources for ENISA, the EU cybersecurity agency, annexed to the resolution. The statement says the regulation gives ENISA extra tasks and workload, so more resources, especially human resources with the right expertise, may be needed, to be assessed in the annual budget procedure for ENISA's establishment plan.
Key points
- Parliament adopts its position at first reading on the proposed regulation on horizontal cybersecurity requirements for products with digital elements.
- The proposed regulation would amend Regulation (EU) 2019/1020 and other acts; the final act is Regulation (EU) 2024/2847.
- Parliament approves the annexed joint statement by Parliament, the Council and the Commission on ENISA resources, to be published in the C series of the Official Journal.
- The three institutions consider the regulation confers additional tasks on ENISA, resulting in additional workload and requiring more resources in expertise and number.
- They consider an increase in ENISA's resources, in particular human resources with adequate expertise, may be necessary, possibly through the annual procedure on ENISA's establishment plan.
- The Commission is to assess the estimates for ENISA's establishment plan for the first year after the regulation enters into force, in view of the resources needed for ENISA to carry out its tasks.
- Parliament calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal.
Who is affected
- ENISA: the regulation gives it additional tasks and workload, and the joint statement says more resources may be needed.
- Makers of products with digital elements: the regulation sets horizontal cybersecurity requirements for such products.
- The Commission: it is to assess ENISA's establishment plan estimates for the first year after entry into force.
Legal basis. Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union
Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 26 Sept 2026 · Report a problem
Full text
Text 22 paragraphs
Committee on Industry, Research and Energy
European Parliament legislative resolution of 12 March 2024 on the proposal for a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 (COM(2022)0454 – C9-0308/2022 – 2022/0272(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
–having regard to the Commission proposal to Parliament and the Council (COM(2022)0454),
–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90308/2022),
–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
–having regard to the opinion of the European Economic and Social Committee of 14 December 2022,
–having regard to the provisional agreement approved by the committee responsible under Rule 74(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 20 December 2023 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,
–having regard to Rule 59 of its Rules of Procedure,
–having regard to the opinion of the Committee on the Internal Market and Consumer Protection,
–having regard to the report of the Committee on Industry, Research and Energy (A9-0253/2023),
Read the rest (10 paragraphs)
1.Adopts its position at first reading hereinafter set out;
2.Approves the joint statement by Parliament, the Council and the Commission annexed to this resolution, which will be published in the C series of the Official Journal of the European Union;
3.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
4.Instructs its President to forward its position to the Council, the Commission and the national parliaments.
P9_TC1-COD(2022)0272
Position of the European Parliament adopted at first reading on 12 March 2024 with a view to the adoption of Regulation (EU) 2024/… of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
(As an agreement was reached between Parliament and Council, Parliament's position corresponds to the final legislative act, Regulation (EU) 2024/2847.)
ANNEX TO THE LEGISLATIVE RESOLUTION
Joint political statement by the European Parliament, the Council and the Commission on ENISA resources, on the occasion of the adoption of Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)
The European Parliament and the Council consider that this Regulation confers additional tasks on ENISA which result in additional workload and would require additional resources in terms of both expertise and number. In view of this, in order to enable ENISA to effectively carry out the tasks under this Regulation, the European Parliament, the Council and the Commission consider that an increase in its resources, in particular its human resources with the adequate expertise, may be necessary. Such increase could be provided for in the annual procedure related to the establishment plan of ENISA. Accordingly, the Commission, which is responsible for entering in the draft general budget of the Union the estimates it deems to be necessary for ENISA’s establishment plan, in the framework of the budgetary procedure set out in Article 314 TFEU and in accordance the procedure set out in the Cybersecurity Act, shall assess the estimates for the establishment plan of ENISA entered for the first year after entry into force of this Regulation in consideration of the necessary resources, in particular human resources, to enable ENISA to adequately carry out its tasks under this Regulation.