Skip to content
EU Parl Watch

Adopted text, 24 April 2024

Managed security services

Document TA-9-2024-0354 · P9_TA(2024)0354 · PE752.802

On Parliament’s site PDF Word

AI:In short

Parliament adopted its first-reading position on a regulation amending Regulation (EU) 2019/881 to cover managed security services. The amended text allows European cybersecurity certification schemes to be developed for managed security services. Parliament takes note of a Commission statement that a thorough review of the Cybersecurity Act is important, covering how certification schemes are prepared, adopted and reviewed, and that the review should assess impact, effectiveness and efficiency. The statement says the review should include ongoing scheme work such as the European cybersecurity certification scheme for cloud services (EUCS) and adopted schemes such as the European Common Criteria-based cybersecurity certification scheme (EUCC). The review should identify strengths and weaknesses of the procedures for certification schemes, recommend future improvements, and address stakeholder consultations and transparency. The Commission must take these elements into account when presenting the review.

Key points

  1. Parliament adopts its first-reading position on the proposal to amend Regulation (EU) 2019/881 as regards managed security services.
  2. The amended regulation adds the possibility to develop European certification cybersecurity schemes for managed security services.
  3. Parliament takes note of the Commission's annexed statement, to be published in the C series of the Official Journal.
  4. The Commission statement acknowledges that a thorough review of the Cybersecurity Act is of utmost importance.
  5. The review should assess the procedures for preparing, adopting and reviewing European cybersecurity certification schemes.
  6. The review should be based on deep analysis and broad consultation on the impact, effectiveness and efficiency of the European cybersecurity certification framework.
  7. The evaluation under Article 67 of the Cybersecurity Act should include ongoing scheme development such as the European cybersecurity certification scheme for cloud services (EUCS) and adopted schemes such as the European Common Criteria-based cybersecurity certification scheme (EUCC).
  8. The review should identify strengths and weaknesses of the procedures leading to certification schemes and recommend future improvements.
  9. The review should address stakeholder consultations and transparency of the process.
  10. The Commission, responsible for the review, must ensure it takes into account the necessary elements in light of Article 67 when presenting the review to the co-legislators.

Who is affected

  • Providers of managed security services, which may be covered by new European cybersecurity certification schemes.
  • The Commission, which must carry out the review of the Cybersecurity Act and present it to the co-legislators.
  • Stakeholders involved in consultations on the certification framework.

Figures and deadlines

  • Article 67 of the Cybersecurity Act, which establishes the evaluation.

Legal basis. Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union.

Written by AI from the full text · every figure comes from the text · ¶ opens the paragraph · 26 Sept 2026 · Report a problem

Full text

Text 24 paragraphs

Committee on Industry, Research and Energy

European Parliament legislative resolution of 24 April 2024 on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services (COM(2023)0208 – C9-0137/2023 – 2023/0108(COD))

(Ordinary legislative procedure: first reading)

The European Parliament,

–having regard to the Commission proposal to Parliament and the Council (COM(2023)0208),

–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90137/2023),

–having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

–having regard to the opinion of the European Economic and Social Committee of 13 July 2023,

–having regard to the provisional agreement approved by the committee responsible under Rule 74(4) of its Rules of Procedure and the undertaking given by the Council representative by letter of 21 March 2024 to approve Parliament’s position, in accordance with Article 294(4) of the Treaty on the Functioning of the European Union,

–having regard to Rule 59 of its Rules of Procedure,

–having regard to the letter from the Committee on the Internal Market and Consumer Protection,

–having regard to the report of the Committee on Industry, Research and Energy (A9-0307/2023),

Read the rest (12 paragraphs)

1.Adopts its position at first reading hereinafter set out;

2.Takes note of the statement by the Commission annexed to this resolution, which will be published in the C series of the Official Journal of the European Union;

3.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

4.Instructs its President to forward its position to the Council, the Commission and the national parliaments.

P9_TC1-COD(2023)0108

Position of the European Parliament adopted at first reading on 24 April 2024 with a view to the adoption of Regulation (EU) 2025/… of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services

(As an agreement was reached between Parliament and Council, Parliament's position corresponds to the final legislative act, Regulation (EU) 2025/37.)

ANNEX TO THE LEGISLATIVE RESOLUTION

Political statement by the Commission on the occasion of the adoption of Regulation (EU) 2025/37 of the European Parliament and of the Council of 19 December 2024 amending Regulation (EU) 2019/881 as regards managed security services

This Regulation amending the Cybersecurity Act adds the possibility to develop European certification cybersecurity schemes for managed security services. At the same time, it is acknowledged that a thorough review of the Cybersecurity Act is of utmost importance, including the assessment of the procedures leading to the preparation, adoption and review of European cybersecurity certification schemes. This review should be based on a deep analysis and broad consultation on the impact, effectiveness and efficiency of the functioning of the European cybersecurity certification framework. The analysis carried out as part of the evaluation established in Article 67 of the Cybersecurity Act should include on-going scheme development activities, such as the one concerning European cybersecurity certification scheme for cloud services (EUCS) as well as those of adopted schemes such as the one concerning the European Common Criteria-based cybersecurity certification scheme (EUCC).

In particular, the review should identify the strengths and weaknesses of the procedures leading to cybersecurity certification schemes and formulate recommendations for future improvements. It should also address aspects relating to stakeholder consultations and transparency of the process.

Accordingly, the Commission, which is responsible for the review of the Cybersecurity Act, shall ensure that the review takes into account as appropriate the necessary elements mentioned in light of Article 67 when presenting the review to the co-legislators.