Sittings · Document
On discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022
Committee on Budgetary Control · Rapporteur: Petri Sarvamaa
PR_DEC_Agencies
1. PROPOSAL FOR A EUROPEAN PARLIAMENT DECISION
on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022
(2023/2159(DEC))
– having regard to the final annual accounts of ENISA (European Union Agency for Cybersecurity) for the financial year 2022,
– having regard to the Court of Auditors’ annual report on EU agencies for the financial year 2022, together with the agencies’ replies,
– having regard to the statement of assurance as to the reliability of the accounts and the legality and regularity of the underlying transactions provided by the Court of Auditors for the financial year 2022, pursuant to Article 287 of the Treaty on the Functioning of the European Union,
– having regard to the Council’s recommendation of … February 2024 on discharge to be given to the Agency in respect of the implementation of the budget for the financial year 2022 (00000/2024 – C90000/2024),
– having regard to Article 319 of the Treaty on the Functioning of the European Union,
– having regard to Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012, and in particular Article 70 thereof,
– having regard to Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act), and in particular Article 31 thereof,
– having regard to Commission Delegated Regulation (EU) 2019/715 of 18 December 2018 on the framework financial regulation for the bodies set up under the TFEU and Euratom Treaty and referred to in Article 70 of Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council, and in particular Article 105 thereof,
– having regard to Rule 100 of and Annex V to its Rules of Procedure,
– having regard to the report of the Committee on Budgetary Control (A90000/2024),
1. Grants the Executive Director of ENISA (European Union Agency for Cybersecurity) discharge in respect of the implementation of the Agency’s budget for the financial year 2022 / Postpones its decision on granting the Executive Director of ENISA (European Union Agency for Cybersecurity) discharge in respect of the implementation of the Agency’s budget for the financial year 2022;
2. Sets out its observations in the resolution below;
3. Instructs its President to forward this decision, and the resolution forming an integral part of it, to the Executive Director of ENISA (European Union Agency for Cybersecurity), the Council, the Commission and the Court of Auditors, and to arrange for their publication in the Official Journal of the European Union (L series).
2. PROPOSAL FOR A EUROPEAN PARLIAMENT DECISION
on the closure of the accounts of ENISA (European Union Agency for Cybersecurity) for the financial year 2022
(2023/2159(DEC))
– having regard to the final annual accounts of ENISA (European Union Agency for Cybersecurity) for the financial year 2022,
– having regard to the Court of Auditors’ annual report on EU agencies for the financial year 2022, together with the agencies’ replies,
– having regard to the statement of assurance as to the reliability of the accounts and the legality and regularity of the underlying transactions provided by the Court of Auditors for the financial year 2022, pursuant to Article 287 of the Treaty on the Functioning of the European Union,
– having regard to the Council’s recommendation of … February 2024 on discharge to be given to the Agency in respect of the implementation of the budget for the financial year 2022 (00000/2024 – C90000/2024),
– having regard to Article 319 of the Treaty on the Functioning of the European Union,
– having regard to Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012, and in particular Article 70 thereof,
– having regard to Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act), and in particular Article 31 thereof,
– having regard to Commission Delegated Regulation (EU) 2019/715 of 18 December 2018 on the framework financial regulation for the bodies set up under the TFEU and Euratom Treaty and referred to in Article 70 of Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council, and in particular Article 105 thereof,
– having regard to Rule 100 of and Annex V to its Rules of Procedure,
– having regard to the report of the Committee on Budgetary Control (A90000/2024),
1. Approves the closure of the accounts of ENISA (European Union Agency for Cybersecurity) for the financial year 2022 / Postpones the closure of the accounts of ENISA (European Union Agency for Cybersecurity) for the financial year 2022;
2. Instructs its President to forward this decision to the Executive Director of ENISA (European Union Agency for Cybersecurity), the Council, the Commission and the Court of Auditors, and to arrange for its publication in the Official Journal of the European Union (L series).
3. MOTION FOR A EUROPEAN PARLIAMENT RESOLUTION
with observations forming an integral part of the decision on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022
(2023/2159(DEC))
– having regard to its decision on discharge in respect of the implementation of the budget of ENISA (European Union Agency for Cybersecurity) for the financial year 2022,
– having regard to Rule 100 of and Annex V to its Rules of Procedure,
– having regard to the Special Report No 05/2022 of the Court of Auditors;
– having regard to the report of the Committee on Budgetary Control (A90000/2024),
A. whereas, according to its statement of revenue and expenditure, the final budget of the European Union Agency for Cybersecurity (ENISA) (the ‘Agency’) for the financial year 2022 was EUR 39 207 625 representing an increase of 67,03 % compared to 2021; whereas the increase in the Agency’s budget is mainly explained by additional tasks related to the pilot implementation of the Cybersecurity Support Action programme; whereas the budget of the Agency derives mainly from the Union budget;
B. whereas the Court of Auditors (the ‘Court’), in its report on the Agency’s annual accounts for the financial year 2022 (the ‘Court’s report’), states that it has obtained reasonable assurance that the Agency’s annual accounts are reliable and that the underlying transactions are legal and regular;
Budget and financial management
1. Notes with appreciation that the budget monitoring efforts during the financial year 2022 resulted in a budget implementation of current year commitment appropriations rate of 99,93 %, representing an increase of 0,42 % compared to 2021; notes furthermore that the current year payment appropriations execution rate was 52,02 % representing a decrease of 25,38 % compared to 2021;
2. Highlights that the amount of the Agency’s final budget is the result of an amendment of EUR 15 000 000 adopted by the Management Board on 5 August 2022 due to the implementation of a cybersecurity support action aiming to strengthen the Agency’s response in supporting Member States in accordance with its mandate; notes that the majority of the commitments under the cybersecurity support action were signed late in the year, which explains the relatively low payment rate (and the subsequent large carry-forward);
Performance
3. Commends that the Agency implemented 100 % of its work programme in 2022; welcomes that the Agency uses Key Performance Indicators to assess its activities and the results towards its objectives of the work programme; observes that certain outputs did not achieve their objectives in full due to the reprioritisation of resources in order to provide the cybersecurity support action in response to the illegal and unprovoked invasion against Ukraine; notes that some of the outputs more affected due to the before mentioned reprioritisation were outputs 4.2 “Develop and enhance standard operating policies, procedures, methodologies and tools for cyber crisis”,and 5.3 “Initiate the development of a trusted network of vendors/suppliers” among others;
4. Is aware that the illegal and unprovoked Russian invasion against Ukraine dominated the EU’s security agenda in 2022; notes with satisfaction that the Agency stepped up its coordination and preparedness, and contributed to the EU’s shared situational awareness by providing regular situational reports of cyber activity; notes that there was also intensified coordination and exchange of information with cybersecurity networks, such as the European cyber crisis liaison organisation network (EU-CyCLONe) – which consists of national cybersecurity crisis management authorities – and numerous sectorial communities supported by the Agency; welcomes the efforts realised by the Agency to ensure channels of communication between political, operational and technical levels, and enhanced cooperation with the computer security incident response teams’ network;
5. Notes with satisfaction that in 2022 the agency piloted the Union heat map, which aimed to provide a quick overview of cyberincidents and cyberevents affecting the EU’s critical sectors as a result of the cyberactivity related to the Russian war of aggression against Ukraine; notes that these sectors contributed to the integrated situational awareness and analysis report from the Commission, with 52 updates on the current situation and incidents in regard to the Russian war of aggression against Ukraine, contributing to the Union’s Crisis Management Mechanism;
6. Takes note that according to the Court Special Report Special report 05/2022: “Cybersecurity of EU institutions, bodies and agencies”, the number of cyberattacks on EU bodies is increasing sharply and the level of cybersecurity preparedness within EU bodies varies and is overall not commensurate with the growing threats; observes that since EU bodies are strongly interconnected, a weakness in one can expose others to security threats; highlights that the Court recommends that the Agency together with CERT-EU should increase their focus on those EU bodies that have less experience in managing cybersecurity by: (a) identifying priority areas where EU institutions, bodies and agencies need most support, for example through maturity assessments, and (b) implementing capacity-building actions, in line with their Memorandum of Understanding; calls on the Agency to address the issues raised by the Court and report back to the discharge authority on any measures taken on this matter;
7. Takes note that the Agency conducted various activities in 2022 to fulfil its role in supporting the European Union; notes that while the Agency was able to offer its support to several policy files, such as Network and Information Security Directives (NISD2), Cyber Resilience Act (CRA) and Digital Operational Resilience Act (DORA), resource constraints prevented the Agency from actively supporting policy files with cybersecurity provisions, such as the European Health Data Space, and other key files, such as the Digital Markets Act and the Digital Services Act; notes that other activities included informing policymakers about the effectiveness of existing cybersecurity frameworks and providing support to critical sectors; notes furthermore that the adoption of new Network and Information Security Directives (NISD2) stands out as a measure to address challenges and harmonize policies across the EU; understands that the lack of harmonization in NIS1D implementation led to a fragmented policy landscape, addressed by NISD2; is aware that the latter expands its scope introducing new horizontal tasks for the Agency, such as the EU register for digital entities; highlights that the Agency adjusted its services and resources with a new strategy to meet the evolving demands of the cybersecurity landscape;
Efficiency and gains
8. Notes that the Agency sought to increase its use of services shared with other agencies and/or the Commission, including, for example, through interagency and interinstitutional procurement processes, and sharing services with European Centre for the Development of Vocational Training (Cedefop) and the European Cybersecurity Competence Centre (ECCC); notes furthermore that in 2022, the Agency signed a service-level agreement with the newly established European Cybersecurity Industrial, Technology and Research Competence Centre, for the provision to the centre of data protection officer and accountant services, to be implemented in 2023;
9. Takes note of the steps taken by the Agency to move away from the traditional headcount methodology to a strategic workforce planning to anticipating and addressing staffing gaps in order to build an agile workforce and allocate resources to priority areas;
10. Welcomes the Agency’s contribution to the promotion of shared services among agencies through several networks in the areas of procurement, HR, ICT, risk management, performance management, data protection, information security and accounting; points out the horizontal benefits of working together and adapting best practices and that joint initiatives bring together diverse perspectives, reduce duplication of effort, enhance learning and strengthen relationships between the participants; encourages the Agency to find internal procedures that could be streamlined via new IT tools;
11. Notes with satisfaction the involvement of the Agency in the pilot exercise within the EU Agencies Network intended to support EU agencies to increase their preparedness for the upcoming new cybersecurity regulation;
Staff policy
12. Notes that on 31 December 2022, the establishment plan was 89,02 % implemented, with 73 temporary agents appointed out of 82 authorised under the Union budget (compared to 76 authorised posts in 2021); notes that, in addition, 27 contract agents, 10 seconded national experts, 10 interim staff and 16 contractors worked for the Agency in 2022;
13. Notes the gender balance within the Agency’s senior and middle management with 12 out of 17 being men (71 %) and within the Agency’s management board, with 41 out of 55 (75 %) being men; however, understands that the gender balance of the management board depends to a large extent on the fact that its members are seconded by the Member States;further notes the balanced gender distribution within the Agency’s staff overall, with 57 men (52%) and 48 women (53%); takes note of the steps taken by the Agency with the aim to tackle issues with gender balance which includes the revision of its recruitment policy to encourage applications from women; notes furthermore that the Agency has planned in its Corporate Strategy to obtain EU Agency’s Network Certificate of Excellence in Diversity and Inclusion by the end of 2025;
14. Notes with concern that during the development of the 2023 work program, the Agency identified a resource shortfall of EUR 734 000 and two FTEs in operations, and EUR 2,5 million in corporate services; notes furthermore that a thorough evaluation of human resource needs for 2023-2025 revealed a significant gap, particularly in critical activities and without additional posts, the Agency may need to prioritize and adjust future work programs to offset the resource shortfall; takes note that the Management Board has also expressed the need to increase staffing posts for the Agency to be able to fully deliver its mandate in a sustainable manner;
15. Welcomes the Agency’s efforts to integrate persons with disabilities setting accessible infrastructure and support services;
16. Notes that the Agency in 2022 continued with its complementary support to staff in vouchers, internet reimbursement and fit@work programme and developed its code of conduct, outlining Agency’s expectation regarding staff members’ behaviour and conduct;
Procurement
17. Notes with concern, that the Court found two cases where the Agency had awarded low-value contracts (below EUR 15 000) without issuing an evaluation report and an award decision duly approved and signed by the authorising officer which contravenes points 30.3 and 30.4 of Annex I to the Financial Regulation; recalls in this regard that the Court made a similar observation in their 2021 report and the Agency’s reply stating that it had already taken the necessary steps to address this concern; insists on the importance to implementing procedures to ensure full compliance with the Financial Regulation; calls on the Agency to address the issues raised by the Court and report back to the discharge authority;
18. Takes note that according to the Court, during 2022 , the Agency offered its managers a professional appraisal performed by an external provider, designated by the Agency; notes that in three cases, the Agency paid the provider directly for these services, while in the remaining 23 cases, it reimbursed its managers, who had paid the provider themselves; observes that the total amount paid by the Agency for the 26 appraisals was EUR 120 276; regrets that the Agency selected the provider without launching an open procurement procedure, and for this reason the Court concluded that these payments were irregular; calls on the Agency to address the issues raised by the Court and report back to the discharge authority on any measures taken on this matter;
19. Insists that the objective of public procurement rules is to enable procuring entities to obtain the goods and services they need at best price, while ensuring fair competition between tenderers and compliance with the principles of transparency, proportionality, equal treatment and non-discrimination; calls on the Agency to further improve its public procurement procedures, ensuring full compliance with the applicable rules, so that they achieve the best possible value for money;
Prevention and management of conflicts of interest and transparency
20. Notes the Agency’s existing measures and ongoing efforts to secure transparency, prevention and management of conflicts of interest, and notes that the CVs of the members of the management board, and their declaration of commitment and declarations of interests are being published on its website, although some of the CVs are missing;
21. Notes that the Agency has not reported any cases of conflict of interest in 2022; further notes the Agency’s adoption of the Management Board Decision 15/2021 on the prevention of conflict of interest and the update of the templates for the declarations; insists on the importance of having procedures in place for monitoring compliance with the rules related to ‘revolving door’ and actively monitoring the professional activity of their senior staff members (including those that have left the agency within the last two years) in order to be able to detect undeclared ‘revolving door’ situations;
22. Takes note that the calendar of the meetings between the Agency's Management and external stakeholders is publicly available on its website;
Internal control
23. Notes that the IAS conducted in 2021 an audit on strategic planning programming and performance management and issued its final audit report in April 2022, with three important recommendations notes further the Agency’s agreement with the audit observations and having taken the necessary steps to address these concerns;
24. Observes that according to the Court the Agency has no pre-determined model assessment (i.e. guidelines) to help the evaluation committee to assess the tenders; notes that this entails the risk that the tenders may not be evaluated consistently by each member of the evaluation committee; calls on the Agency to address this issue raised by the Court and report back to the discharge authority;
25. Takes note that in 2022, the Agency performed ex post controls of financial transactions made during 2021 financial year as per Article 45(8) and (9) of the ENISA financial regulation; draws attention to the fact that three weaknesses were identified, leading to three recommendations on financial transactions, none of which was deemed critical; observes that to address the main weakness, weekly monitoring of time to payment was introduced in 2022 to alert the relevant financial staff to urgent transactions remaining to be processed, to comply with the legal framework on payment time limits;
26. Notes that in 2022, the assessment of the effectiveness of the internal control systems of the Agency was based on the indicators of the framework, and also additional information from specific (risk) assessment reports, audit findings and other relevant sources; observes that the assessment of the Agency's internal controls indicates reasonable assurance in facilitating effective and efficient operations, ensuring quality reporting, and compliance with regulations but some improvements are needed in relation to certain principles to increase effectiveness and ensure proper implementation of the internal controls; calls on the Agency to report back to the discharge Authority on the follow up on the improvements assessment;
Other comments
27. Notes that the Agency has implemented important measures in order to increase cyber security protection, such as secure email solution (SECEM2), red team exercise and follow-up fixes & hardening, decommissioning of legacy systems, update of internal cybersecurity policy framework, among others;
28. Welcomes that the Management Board of the Agency added to the Agency's Single Programming Document 2022-2024 the goal for the Agency to achieve climate neutrality across all its operations by 2030; notes that with the adoption of ENISA’s corporate strategy, the EMAS certification and green public procurement are key objectives of the Agency; takes note that the certification process is expected to be completed in the course of 2024;
°
° °
29. Refers, for other observations of a cross-cutting nature accompanying its decision on discharge, to its resolution of ... on the performance, financial management and control of the agencies.