BETA


2023/0109(COD) Measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents

Progress: Awaiting committee decision

RoleCommitteeRapporteurShadows
Lead ITRE GÁLVEZ MUÑOZ Lina (icon: S&D S&D) NIEBLER Angelika (icon: EPP EPP), GROOTHUIS Bart (icon: Renew Renew), NIINISTÖ Ville (icon: Verts/ALE Verts/ALE)
Committee Opinion AFET TUDORACHE Dragoş (icon: Renew Renew) Željana ZOVKO (icon: PPE PPE), Markéta GREGOROVÁ (icon: Verts/ALE Verts/ALE), Attila ARA-KOVÁCS (icon: S&D S&D)
Committee Opinion BUDG
Committee Opinion CONT
Committee Opinion IMCO
Committee Opinion TRAN FALCĂ Gheorghe (icon: EPP EPP) Nicola DANTI (icon: RE RE), Kosma ZŁOTOWSKI (icon: ECR ECR), Josianne CUTAJAR (icon: S&D S&D), Anne-Sophie PELLETIER (icon: GUE/NGL GUE/NGL)
Committee Opinion LIBE
Lead committee dossier:
Legal Basis:
TFEU 173-p3, TFEU 322-p1

Events

2023/10/27
   EP - Committee opinion
Documents
2023/10/25
   EP - Committee opinion
Documents
2023/09/22
   EP - Amendments tabled in committee
Documents
2023/09/18
   PT_PARLIAMENT - Contribution
Documents
2023/09/04
   EP - Committee draft report
Documents
2023/08/01
   CZ_SENATE - Contribution
Documents
2023/07/13
   ESC - Economic and Social Committee: opinion, report
Documents
2023/07/07
   EP - FALCĂ Gheorghe (EPP) appointed as rapporteur in TRAN
2023/06/29
   CZ_CHAMBER - Contribution
Documents
2023/06/16
   EP - TUDORACHE Dragoş (Renew) appointed as rapporteur in AFET
2023/06/01
   EP - Committee referral announced in Parliament, 1st reading
2023/05/02
   EP - GÁLVEZ MUÑOZ Lina (S&D) appointed as rapporteur in ITRE
2023/04/18
   EC - Legislative proposal published
Details

PURPOSE: to lay down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents (EU Cyber solidarity act).

PROPOSED ACT: Regulation of the European Parliament and of the Council.

ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council.

BACKGROUND: the magnitude, frequency and impact of cybersecurity incidents are increasing, including supply chain attacks aiming at cyberespionage, ransomware or disruption. They represent a major threat to the functioning of network and information systems. In view of the fast-evolving threat landscape, the threat of possible large-scale incidents causing significant disruption or damage to critical infrastructures demands heightened preparedness at all levels of the Union’s cybersecurity framework. That threat goes beyond Russia’s military aggression on Ukraine and is likely to persist given the multiplicity of state-aligned, criminal and hacktivist actors involved in current geopolitical tensions.

CONTENT: with this proposal, the Commission aims to set up Cyber Solidarity Act which establishes EU capabilities to make Europe more resilient and reactive in front of cyber threats, while strengthening existing cooperation mechanism. It will contribute to ensuring a safe and secure digital landscape for citizens and businesses and to protecting critical entities and essential services, such as hospitals and public utilities.

This Regulation lays down measures to strengthen capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents, in particular through the following actions:

European Cyber Shield

An interconnected pan-European infrastructure of Security Operations Centres (European Cyber Shield) will be established to develop advanced capabilities for the Union to detect, analyse and process data on cyber threats and incidents in the Union. It will be composed of Security Operations Centres (SOCs) across the EU, brought together in several multi-country SOC platforms, built with support from the Digital Europe Programme (DEP) to supplement national funding. The Cyber Shield will be tasked with improving the detection, analysis and response to cyber threats. These SOCs will use advanced technology such as Artificial Intelligence (AI) and data analytics to detect and share warnings on such threats with authorities across borders. They will allow for a more timely and efficient response to major threats.

Cyber Emergency Mechanism

The Cyber Emergency Mechanism will improve the Union’s resilience to major cybersecurity threats and prepare for and mitigate, in a spirit of solidarity, the short-term impact of significant and large-scale cybersecurity incidents. It provides for actions to support preparedness, including coordinated testing of entities operating in highly critical sectors, response to and immediate recovery from significant or large-scale cybersecurity incidents or mitigate significant cyber threats and mutual assistance actions.

Also set to be created is an EU Cybersecurity Reserve made up of trusted and certified private companies ready to respond to major incidents.

European Cybersecurity Incident Review Mechanism

The proposed Regulation would also establish the Cybersecurity Incident Review Mechanism to assess and review specific cybersecurity incidents. At the request of the Commission or of national authorities (the EU-CyCLONe or the CSIRTs network), the EU Cybersecurity Agency (ENISA) will be responsible for the review of specific significant or large-scale cybersecurity incident and should deliver a report that includes lessons learned, and where appropriate, recommendations to improve Union’s cyber response.

Budgetary implications

The EU Cybersecurity Shield and the Cybersecurity Emergency Mechanism of this Regulation will be supported by funding under Strategic Objective ‘Cybersecurity’ of Digital Europe Programme (DEP).

The total budget includes an increase of EUR 100 million that this Regulation proposes to re-allocate from other Strategic Objectives of DEP. This will bring the new total amount available for Cybersecurity actions under DEP to EUR 842.8 million. Part of the additional EUR 100 million will reinforce the budget managed by the ECCC to implement actions on SOCs and preparedness as part of their Work Programme(s). Moreover, the additional funding will serve to support the establishment of the EU Cybersecurity Reserve.

It complements the budget already foreseen for similar actions in the main DEP and Cybersecurity DEP WP from the period 2023-2027 which could bring the total to 551 million for 2023-2027, while 115 million were dedicated already in the form of pilots for 2021-2022. Including Member States contributions, the overall budget could amount up to EUR 1.109 billion.

Documents

AmendmentsDossier
171 2023/0109(COD)
2023/09/22 ITRE 171 amendments...
source: 753.628

History

(these mark the time of scraping, not the official date of the change)

docs/4
date
2023-10-27T00:00:00
docs
url: https://www.europarl.europa.eu/doceo/document/AFET-AD-750145_EN.html title: PE750.145
committee
AFET
type
Committee opinion
body
EP
docs/4/date
Old
2023-06-28T00:00:00
New
2023-06-29T00:00:00
docs/5/date
Old
2023-09-17T00:00:00
New
2023-09-18T00:00:00
docs/6/date
Old
2023-07-31T00:00:00
New
2023-08-01T00:00:00
docs/3
date
2023-10-25T00:00:00
docs
url: https://www.europarl.europa.eu/doceo/document/TRAN-AD-752607_EN.html title: PE752.607
committee
TRAN
type
Committee opinion
body
EP
docs/4
date
2023-09-17T00:00:00
docs
url: https://connectfolx.europarl.europa.eu/connefof/app/exp/COM(2023)0209 title: COM(2023)0209
type
Contribution
body
PT_PARLIAMENT
docs/2
date
2023-09-22T00:00:00
docs
url: https://www.europarl.europa.eu/doceo/document/ITRE-AM-753628_EN.html title: PE753.628
type
Amendments tabled in committee
body
EP
docs/1
date
2023-09-04T00:00:00
docs
url: https://www.europarl.europa.eu/doceo/document/ITRE-PR-752795_EN.html title: PE752.795
type
Committee draft report
body
EP
docs/2
date
2023-07-31T00:00:00
docs
url: https://connectfolx.europarl.europa.eu/connefof/app/exp/COM(2023)0209 title: COM(2023)0209
type
Contribution
body
CZ_SENATE
docs/0
date
2023-07-13T00:00:00
docs
url: https://dmsearch.eesc.europa.eu/search/public?k=(documenttype:AC)(documentnumber:2408)(documentyear:2023)(documentlanguage:EN) title: CES2408/2023
type
Economic and Social Committee: opinion, report
body
ESC
committees/3/rapporteur
  • name: FALCĂ Gheorghe date: 2023-07-07T00:00:00 group: Group of European People's Party abbr: EPP
docs/0
date
2023-06-28T00:00:00
docs
url: https://connectfolx.europarl.europa.eu/connefof/app/exp/COM(2023)0209 title: COM(2023)0209
type
Contribution
body
CZ_CHAMBER
docs/0
date
2023-04-18T00:00:00
docs
type
Legislative proposal
body
EC
committees/0
type
Responsible Committee
body
EP
committee_full
Industry, Research and Energy
committee
ITRE
associated
False
rapporteur
name: GÁLVEZ MUÑOZ Lina date: 2023-05-02T00:00:00 group: Group of Progressive Alliance of Socialists and Democrats abbr: S&D
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Industry, Research and Energy
committee
ITRE
associated
False
rapporteur
name: GÁLVEZ MUÑOZ Lina date: 2023-05-02T00:00:00 group: Group of Progressive Alliance of Socialists and Democrats abbr: S&D
shadows
name: GROOTHUIS Bart group: Renew Europe group abbr: Renew
committees/1
Old
type
Committee Opinion
body
EP
committee_full
Civil Liberties, Justice and Home Affairs
committee
LIBE
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Foreign Affairs
committee
AFET
associated
False
rapporteur
name: TUDORACHE Dragoş date: 2023-06-16T00:00:00 group: Renew Europe group abbr: Renew
committees/2
Old
type
Committee Opinion
body
EP
committee_full
Internal Market and Consumer Protection
committee
IMCO
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Budgets
committee
BUDG
associated
False
opinion
False
committees/3
Old
type
Committee Opinion
body
EP
committee_full
Budgetary Control
committee
CONT
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Transport and Tourism
committee
TRAN
associated
False
committees/4
Old
type
Committee Opinion
body
EP
committee_full
Foreign Affairs
committee
AFET
associated
False
rapporteur
name: TUDORACHE Dragoş date: 2023-06-16T00:00:00 group: Renew Europe group abbr: Renew
New
type
Committee Opinion
body
EP
committee_full
Civil Liberties, Justice and Home Affairs
committee
LIBE
associated
False
opinion
False
committees/5
Old
type
Committee Opinion
body
EP
committee_full
Budgets
committee
BUDG
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Internal Market and Consumer Protection
committee
IMCO
associated
False
opinion
False
committees/6
Old
type
Committee Opinion
body
EP
committee_full
Transport and Tourism
committee
TRAN
associated
False
New
type
Committee Opinion
body
EP
committee_full
Budgetary Control
committee
CONT
associated
False
opinion
False
committees/1
type
Committee Opinion
body
EP
committee_full
Foreign Affairs
committee
AFET
associated
False
committees/1
Old
type
Committee Opinion
body
EP
committee_full
Budgets
committee
BUDG
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Civil Liberties, Justice and Home Affairs
committee
LIBE
associated
False
opinion
False
committees/2
Old
type
Committee Opinion
body
EP
committee_full
Transport and Tourism
committee
TRAN
associated
False
New
type
Committee Opinion
body
EP
committee_full
Internal Market and Consumer Protection
committee
IMCO
associated
False
opinion
False
committees/3
Old
type
Committee Opinion
body
EP
committee_full
Civil Liberties, Justice and Home Affairs
committee
LIBE
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Budgetary Control
committee
CONT
associated
False
opinion
False
committees/4
type
Committee Opinion
body
EP
committee_full
Foreign Affairs
committee
AFET
associated
False
committees/4/rapporteur
  • name: TUDORACHE Dragoş date: 2023-06-16T00:00:00 group: Renew Europe group abbr: Renew
committees/5
Old
type
Committee Opinion
body
EP
committee_full
Internal Market and Consumer Protection
committee
IMCO
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Budgets
committee
BUDG
associated
False
opinion
False
committees/6
Old
type
Committee Opinion
body
EP
committee_full
Budgetary Control
committee
CONT
associated
False
opinion
False
New
type
Committee Opinion
body
EP
committee_full
Transport and Tourism
committee
TRAN
associated
False
committees/0/shadows
  • name: GROOTHUIS Bart group: Renew Europe group abbr: Renew
committees/6/opinion
False
committees/4/opinion
False
commission
  • body: EC dg: Communications Networks, Content and Technology commissioner: BRETON Thierry
events/1
date
2023-06-01T00:00:00
type
Committee referral announced in Parliament, 1st reading
body
EP
procedure/dossier_of_the_committee
  • ITRE/9/11824
procedure/stage_reached
Old
Preparatory phase in Parliament
New
Awaiting committee decision
committees/5/opinion
False
events/0/summary
  • PURPOSE: to lay down measures to strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents (EU Cyber solidarity act).
  • PROPOSED ACT: Regulation of the European Parliament and of the Council.
  • ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council.
  • BACKGROUND: the magnitude, frequency and impact of cybersecurity incidents are increasing, including supply chain attacks aiming at cyberespionage, ransomware or disruption. They represent a major threat to the functioning of network and information systems. In view of the fast-evolving threat landscape, the threat of possible large-scale incidents causing significant disruption or damage to critical infrastructures demands heightened preparedness at all levels of the Union’s cybersecurity framework. That threat goes beyond Russia’s military aggression on Ukraine and is likely to persist given the multiplicity of state-aligned, criminal and hacktivist actors involved in current geopolitical tensions.
  • CONTENT: with this proposal, the Commission aims to set up Cyber Solidarity Act which establishes EU capabilities to make Europe more resilient and reactive in front of cyber threats, while strengthening existing cooperation mechanism. It will contribute to ensuring a safe and secure digital landscape for citizens and businesses and to protecting critical entities and essential services, such as hospitals and public utilities.
  • This Regulation lays down measures to strengthen capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents, in particular through the following actions:
  • European Cyber Shield
  • An interconnected pan-European infrastructure of Security Operations Centres (European Cyber Shield) will be established to develop advanced capabilities for the Union to detect, analyse and process data on cyber threats and incidents in the Union. It will be composed of Security Operations Centres (SOCs) across the EU, brought together in several multi-country SOC platforms, built with support from the Digital Europe Programme (DEP) to supplement national funding. The Cyber Shield will be tasked with improving the detection, analysis and response to cyber threats. These SOCs will use advanced technology such as Artificial Intelligence (AI) and data analytics to detect and share warnings on such threats with authorities across borders. They will allow for a more timely and efficient response to major threats.
  • Cyber Emergency Mechanism
  • The Cyber Emergency Mechanism will improve the Union’s resilience to major cybersecurity threats and prepare for and mitigate, in a spirit of solidarity, the short-term impact of significant and large-scale cybersecurity incidents. It provides for actions to support preparedness, including coordinated testing of entities operating in highly critical sectors, response to and immediate recovery from significant or large-scale cybersecurity incidents or mitigate significant cyber threats and mutual assistance actions.
  • Also set to be created is an EU Cybersecurity Reserve made up of trusted and certified private companies ready to respond to major incidents.
  • European Cybersecurity Incident Review Mechanism
  • The proposed Regulation would also establish the Cybersecurity Incident Review Mechanism to assess and review specific cybersecurity incidents. At the request of the Commission or of national authorities (the EU-CyCLONe or the CSIRTs network), the EU Cybersecurity Agency (ENISA) will be responsible for the review of specific significant or large-scale cybersecurity incident and should deliver a report that includes lessons learned, and where appropriate, recommendations to improve Union’s cyber response.
  • Budgetary implications
  • The EU Cybersecurity Shield and the Cybersecurity Emergency Mechanism of this Regulation will be supported by funding under Strategic Objective ‘Cybersecurity’ of Digital Europe Programme (DEP).
  • The total budget includes an increase of EUR 100 million that this Regulation proposes to re-allocate from other Strategic Objectives of DEP. This will bring the new total amount available for Cybersecurity actions under DEP to EUR 842.8 million. Part of the additional EUR 100 million will reinforce the budget managed by the ECCC to implement actions on SOCs and preparedness as part of their Work Programme(s). Moreover, the additional funding will serve to support the establishment of the EU Cybersecurity Reserve.
  • It complements the budget already foreseen for similar actions in the main DEP and Cybersecurity DEP WP from the period 2023-2027 which could bring the total to 551 million for 2023-2027, while 115 million were dedicated already in the form of pilots for 2021-2022. Including Member States contributions, the overall budget could amount up to EUR 1.109 billion.
committees/2/opinion
False
committees/0/rapporteur
  • name: GÁLVEZ MUÑOZ Lina date: 2023-05-02T00:00:00 group: Group of Progressive Alliance of Socialists and Democrats abbr: S&D