Sittings · Document
On the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
Committee on Industry, Research and Energy · Rapporteur: Josianne Cutajar
PR_COD_1amCom
Symbols for procedures
* Consultation procedure
*** Consent procedure
***I Ordinary legislative procedure (first reading)
***II Ordinary legislative procedure (second reading)
***III Ordinary legislative procedure (third reading)
(The type of procedure depends on the legal basis proposed by the draft act.)
Amendments to a draft act
Amendments by Parliament set out in two columns
Deletions are indicated in bold italics in the left-hand column. Replacements are indicated in bold italics in both columns. New text is indicated in bold italics in the right-hand column.
The first and second lines of the header of each amendment identify the relevant part of the draft act under consideration. If an amendment pertains to an existing act that the draft act is seeking to amend, the amendment heading includes a third line identifying the existing act and a fourth line identifying the provision in that act that Parliament wishes to amend.
Amendments by Parliament in the form of a consolidated text
New text is highlighted in bold italics. Deletions are indicated using either the ▌symbol or strikeout. Replacements are indicated by highlighting the new text in bold italics and by deleting or striking out the text that has been replaced.
By way of exception, purely technical changes made by the drafting departments in preparing the final text are not highlighted.
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2019/881 as regards managed security services
(COM(2023)0208 – C90137/2023 – 2023/0108(COD))
(Ordinary legislative procedure: first reading)
– having regard to the Commission proposal to Parliament and the Council (COM(2023)0208),
– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C9 0137/2023),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
– having regard to the opinion of the European Economic and Social Committee of 13 July 2023,
– having regard to Rule 59 of its Rules of Procedure,
– having regard to the letter of the Committee on the Internal Market and Consumer Protection,
– having regard to the report of the Committee on Industry, Research and Energy (A90000/2023),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Amendment 1
Proposal for a regulation
Recital 1 a (new)
Text proposed by the Commission
Amendment
(1a) In order to ensure the Union’s resilience to cyberattacks and to prevent any vulnerabilities in the Union market, the present Regulation will complement the horizontal regulatory framework establishing comprehensive cybersecurity requirements for all products with digital elements in accordance with Regulation (EU) .../... of the European Parliament and of the Council * +, setting up essential requirements for cybersecurity managed services, their application and their trustworthiness.
__________________
*Regulation (EU) .../... of the European Parliament and of the Council of ... on ...
(OJ ...).
+ OJ: Please insert in the text the number of the Regulation contained in document 2022/0272 (COD) and insert the number, date, title and OJ reference of that Regulation in the footnote.
Or. en
Amendment 2
Proposal for a regulation
Recital 2
Text proposed by the Commission
Amendment
(2) Managed security services, which are services consisting of carrying out, or providing assistance for, activities relating to their customers’ cybersecurity risk management, have gained increasing importance in the prevention and mitigation of cybersecurity incidents. Accordingly, the providers of those services are considered as essential or important entities belonging to a sector of high criticality pursuant to Directive (EU) 2022/2555 of the European Parliament and of the Council8 . Pursuant to Recital 86 of that Directive, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy, play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and pose a particular risk because of their close integration in the operations of their customers. Essential and important entities within the meaning of Directive (EU) 2022/2555 should therefore exercise increased diligence in selecting a managed security service provider.
(2) Managed security services, which are services consisting of carrying out, or providing assistance for, activities relating to their customers’ cybersecurity risk management, including in prevention, detection, response to or recovery from incidents, have gained increasing importance in the prevention and mitigation of cybersecurity incidents. The activities of the providers of managed security services consist of services relating to identification, protection, detection, response and recovery, including, but not limited to, cyber threat intelligence provision, real time threat monitoring through proactive techniques, including security-by-design, risk assessment, extended detection, remediation and response. Accordingly, the providers of those services are considered as essential or important entities belonging to a sector of high criticality pursuant to Directive (EU) 2022/2555 of the European Parliament and of the Council8. Pursuant to Recital 86 of that Directive, managed security service providers in areas such as incident response, penetration testing, security audits and consultancy, play a particularly important role in assisting entities in their efforts to prevent, detect, respond to or recover from incidents. Managed security service providers have however also themselves been the target of cyberattacks and pose a particular risk because of their close integration in the operations of their customers. Essential and important entities within the meaning of Directive (EU) 2022/2555 should therefore exercise increased diligence in selecting a managed security service provider.
__________________
__________________
8 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80).
8 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80).
Or. en
Amendment 3
Proposal for a regulation
Recital 4 a (new)
Text proposed by the Commission
Amendment
(4a) European certification schemes for managed security services should contribute to the accessibility and affordability of these services, especially for smaller actors, such as microenterprises and small and medium-sized entreprises, which are often more prone to cybersecurity breaches with financial, legal, reputational, and operational implications.
Or. en
Amendment 4
Proposal for a regulation
Recital 5 a (new)
Text proposed by the Commission
Amendment
(5a) With a view to facilitating the growth of a reliable Union market, whilst also creating partnerships with likeminded third countries, including in light of the provisions of the Regulation (EU) .../... of the European Parliament and of the Council* ++with regard to the access to the EU Cybersecurity Reserve, the certification process established within the framework established by this Regulation should be streamlined to ensure international recognition and alignment with international standards.
__________________
* Regulation (EU) .../... of the European Parliament and of the Council of ... on ...
(OJ ...).
++ OJ: Please insert in the text the number of the Regulation contained in document 2023/0109 (COD) and insert the number, date, title and OJ reference of that Regulation in the footnote.
Or. en
Amendment 5
Proposal for a regulation
Recital 5 b (new)
Text proposed by the Commission
Amendment
(5b) With the aim to ensure the development of a trustworthy Union market for managed security services, the providers thereof and Member States should collaborate and contribute to the large-scale collection of data on the state and the evolution of the cybersecurity labour market.
Or. en
Amendment 6
Proposal for a regulation
Recital 5 c (new)
Text proposed by the Commission
Amendment
(5c) A Union-wide coordinated approach to strengthening the resilience of critical infrastructure is based on the Member States’ capacity building. As acknowledged in the recent Commission communication of 8 April 2023 on Closing the cybersecurity talent gap to boost the EU’s competitiveness, growth and resilience, the security of the Union cannot be guaranteed without the Union’s most valuable asset: its people. Therefore, any European certification scheme should take into account assistance for the Member States, including with regard to the cybersecurity skills gaps.
Or. en
Amendment 7
Proposal for a regulation
Recital 5 d (new)
Text proposed by the Commission
Amendment
(5d) In light of the elaboration and implementation of the European certification scheme for managed security services, the Commission should increase the exchanges with ENISA and facilitate the dialogue with Member States, the private sector and academia, in order to better comprehend the composition of the Union cybersecurity workforce and of associated skills.
Or. en
Amendment 8
Proposal for a regulation
Recital 5 e (new)
Text proposed by the Commission
Amendment
(5e) With a view to enabling the European cybersecurity schemes to attest that managed security services that have been evaluated in accordance with such schemes comply with specified security requirements, including with regard to the ongoing provision thereof with the requisite competence, expertise and experience by staff with a very high level of relevant technical knowledge and professional integrity in accordance with this Regulation, the schemes should mobilise the contribution of academia, research institutions and other stakeholders with experience in training cybersecurity professionals, and attracting, recruiting, and developing talent, as well as incentivising public-private partnerships. It should act as an enabler of the pooling of ideas and sharing of expertise on training and better assessing the necessary skills, especially during the recruitment process. Along with the contribution to the scheme, the private sector should also aim to deliver on-the-job training addressing the most in-demand skills, involving public administration and start-ups, as well as microenterprises and, small and medium-sized entreprises.
Or. en
Amendment 9
Proposal for a regulation
Recital 5 f (new)
Text proposed by the Commission
Amendment
(5f) In order to facilitate the emergence of high-quality, essential managed security services, Member States should actively pursue measures to train and retain talent, including through integrating cybersecurity in educational and training programmes, whilst ensuring access to apprenticeships and traineeships for young people, especially persons living in disadvantaged regions, such as islands, sparsely populated, rural and remote areas. Those measures should also aim to attract more women and girls in the field and contribute towards addressing the gender gap in science, technology, engineering, and math.
Or. en
Amendment 10
Proposal for a regulation
Article 1 – paragraph 1 – point 2 – point b
Regulation (EU) 2019/881
Article 2 – point 14a
Text proposed by the Commission
Amendment
(14a) ‘managed security service’ means a service consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, including incident response, penetration testing, security audits and consultancy;
(14a) ‘managed security service’ means an outsourced service consisting of carrying out, or providing assistance for, activities relating to cybersecurity risk management, including, prevention, detection, response to or recovery from incidents, penetration testing, security audits and consultancy;
Or. en
Amendment 11
Proposal for a regulation
Article 1 – paragraph 1 – point 6
Regulation (EU) 2019/881
Article 47 – paragraph 3 – point e a (new)
Text proposed by the Commission
Amendment
(ea) prior alignment with the applicable international standards;
Or. en
Amendment 12
Proposal for a regulation
Article 1 – paragraph 1 – point 6
Regulation (EU) 2019/881
Article 47 – paragraph 3 – point e b (new)
Text proposed by the Commission
Amendment
(eb) the contribution of the managed security services provider to offering training and upskilling opportunities to staff with the aim to achieve a very high level of relevant technical knowledge and professional integrity.
Or. en
Amendment 13
Proposal for a regulation
Article 1 – paragraph 1 – point 6
Regulation (EU) 2019/881
Article 47 – paragraph 3 a (new)
Text proposed by the Commission
Amendment
3a. Additionally, the inclusion of specific managed security services, in the Union rolling work programme shall, where relevant, take into consideration the contribution of the managed security services providers to training and attracting talent, especially through partnerships with universities and other educational institutions.
Or. en
Amendment 14
Proposal for a regulation
Article 1 – paragraph 1 – point 7
Regulation (EU) 2019/881
Article 49 – paragraph 7 a (new)
Text proposed by the Commission
Amendment
7a. The candidate scheme shall be developed taking into consideration any input given by the European system for technical standardisation or by the Union’s sectoral agencies.
Or. en
Amendment 15
Proposal for a regulation
Article 1 – paragraph 1 – point 9
Regulation (EU) 2019/881
Article 51a – paragraph 1 – point b
Text proposed by the Commission
Amendment
(b) ensure that the provider has appropriate internal procedures in place to ensure that the managed security services are provided at a very high level of quality at all times ;
(b) ensure that the provider has appropriate internal procedures in place to ensure that the managed security services are provided at a very high level of quality and reliability at all times;
Or. en
Amendment 16
Proposal for a regulation
Article 1 – paragraph 1 – point 13 – point b – point ii – point bb
Regulation (EU) 2019/881
Article 56 – paragraph 3 – point d
Text proposed by the Commission
Amendment
(d) take into account any implementation deadlines, transitional measures and periods, in particular with regard to the possible impact of the measure on the manufacturers or providers of ICT products, ICT services, ICT processes or managed security services, including SMEs;;
(d) take into account any implementation deadlines, transitional measures and periods, in particular with regard to the possible impact of the measure on the manufacturers or providers of ICT products, ICT services, ICT processes or managed security services, including the specific interests and needs of microenterprises and small and medium-sized enterprises. The Commission shall ensure appropriate financial support in the regulatory framework of existing Union programmes, in particular in order to ease the financial burden on microenterprises and on small and medium-sized enterprises;
Or. en
EXPLANATORY STATEMENT
The Rapporteur supports the proposal for a Regulation of the European Parliament and of the Council amending Regulation (EU) 2019/8811 as regards managed security services, understanding its necessity to update and strengthen the European cybersecurity certification scheme by allowing it to cover important and growing industry services. Considering how individual Member States have already begun adopting certification schemes for managed security services, the Rapporteur takes the view that this amendment to the Cyber Security Act is critical to preventing significant divergences in national schemes that would result in a form of market fragmentation which is against the Union´s economic, and also strategic interests.
On this note, it is acknowledged how this proposal is envisioned to complement the Cyber Solidarity Act, particularly this specific extension to the European cybersecurity certification scheme, will allow for managed security services - corresponding to ´trusted providers´ in the Cyber Solidarity Act - to play an important role in the future EU Cybersecurity Reserve. Therefore, this proposal is one that is also of great importance in fostering broader Union cybersecurity capacity, which capacity is essential to counteract potential threats in an ever-evolving geopolitical reality.
Within the limits of the Commission´s proposal, the Rapporteur’s objective is to consolidate and add further clarity to this targeted amendment to the Cybersecurity Act. This is illustrated by the Rapporteur´s changes to the definition of managed security services, clarifying that they are ‘outsourced’, while concurrently detailing further what can be included in the definition. Tabled amendments regarding the recognition of international cybersecurity standards are intended to foster a higher caliber of confidence while simultaneously developing comprehensive EU rules.
This draft report puts stronger emphasis on addressing the skills gap and in supporting Micro, Small and Medium Enterprises. On the former, tabled amendments build on the already implicit necessity of skills in the cyber certification scheme vis-a-vis ‘the requisite competence, expertise and experience by staff with a very high level of relevant technical knowledge and professional integrity’. In the Rapporteur’s view, whilst fostering cooperation amongst all actors involved as well as between Member States, the private sector, academia and research institutions, the European certification scheme must act as an enabler of a new roadmap to training and empowering the workforce, collecting more data on the skills needed and contributing towards addressing the gender gap in STEM.
At the same time, micro, small and medium enterprises, which form the backbone of the European economy and certainly have a positive role to play in the cybersecurity industry, should benefit from appropriate financial support in the regulatory framework of existing Union programmes to ease any disproportionate financial burden placed upon them
ANNEX: LIST OF ENTITIES OR PERSONS FROM WHOM THE RAPPORTEUR HAS RECEIVED INPUT
The following list is drawn up on a purely voluntary basis under the exclusive responsibility of the rapporteur. The rapporteur has received input from the following entities or persons in the preparation of the Draft Report on the Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulation (EU) 2019/881 as regards managed security services 2023/0108 (COD).
Entity and/or person
European Economic and Social Committee
European Commission
ENISA
Leonardo Cyber and Security Solutions
Red Alert Labs IoT Security
ESET Slovak
Board of Cyber
IBM
Tecnalia
FERMA - Federation of European Risk Management Associations