NIS2 Directive · Directive (EU) 2022/2555
Article 23a
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 18 parts · 4 Council drafts · 90 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to NIS2 DirectiveThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 14 December 2022, with the Commission proposal change affecting this article applied.
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 23a
Commission proposal
Article 23a Single-entry point for incident reporting (1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. (2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. (3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that: (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; (b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; (c) the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; (d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; (e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; (f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point. (4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. (5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. (6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. (7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (14 December 2022) compared with May Presidency compromise (21 May 2026)
Article 23a
Incident reporting information point
- 1.
ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘ incident reporting information point’).
- 2a.
The incident reporting information point shall:
- (a)
enable the identification of applicable obligations to report incidents and related events referred to in paragraph 1;
- (b)
be designed to allow, on the basis of relevant information provided, to identify the applicable reporting obligations and to be redirected to the appropriate national entry point referred in Article 23b;
- (c)
make available simplified and documented information on incident notification processes in the different Member States, such as help guides or tutorials.
- (a)
- 2b.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the NIS Cooperation Group and the CSIRT Network. ENISA shall establish structured communication channels ensuring that information available on the single-information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 2a.
- 2c.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
- 2d.
After establishing the incident reporting information point and in cooperation with the NIS Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
- (a)
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
- (b)
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
- (c)
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
- (a)
Article 23a
May Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘ incident reporting information point’).
The incident reporting information point shall:
enable the identification of applicable obligations to report incidents and related events referred to in paragraph 1;
be designed to allow, on the basis of relevant information provided, to identify the applicable reporting obligations and to be redirected to the appropriate national entry point referred in Article 23b;
make available simplified and documented information on incident notification processes in the different Member States, such as help guides or tutorials.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the NIS Cooperation Group and the CSIRT Network. ENISA shall establish structured communication channels ensuring that information available on the single-information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 2a.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
After establishing the incident reporting information point and in cooperation with the NIS Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (14 December 2022) compared with June Presidency compromise · 10 June (10 June 2026)
Article 23a
Incident reporting information point
- 1.
ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
- 2.
The incident reporting information point shall:
- (a)
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States.
- (a)
- 3.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
- 5.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
- (a)
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
- (b)
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
- (c)
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
- (a)
- 4.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article 23a
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
The incident reporting information point shall:
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and
make available simplified and documented information on incident notification processes in the different Member States.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (14 December 2022) compared with June Presidency compromise · 18 June (18 June 2026)
Article 23a
Incident reporting information point
- 1.
ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
- 2.
The incident reporting information point shall:
- (a)
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States.
- (a)
- 3.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
- 5.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
- (a)
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
- (b)
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
- (c)
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
- (a)
- 4.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article 23a
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point
ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
The incident reporting information point shall:
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and
make available simplified and documented information on incident notification processes in the different Member States.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article in September Presidency compromise Council text
Comparison basis: Existing law (14 December 2022) compared with September Presidency compromise (3 September 2026)
Article 23a
Incident reporting information point
- 1.
ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
- 2.
The incident reporting information point shall:
- (a)
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States.
- (a)
- 3.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
- 4.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
- 5.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
- (a)
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
- (b)
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
- (c)
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
- (a)
Article 23a
September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’). (2) The incident reporting information point shall: (a) be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States. (3) When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a. (4) The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident. (5) After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on: (a) regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures; (b) national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations; (c) content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
Official source passage and amending instruction
1. The following Article 23a is added: ‘Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’). (2) The incident reporting information point shall: (a) be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States. (3) When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a. (4) The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident. (5) After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on: (a) regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures; (b) national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations; (c) content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.’
Article 23a 4 Council drafts
Article 23a
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘ incident reporting information point’).
The incident reporting information point shall:
enable the identification of applicable obligations to report incidents and related events referred to in paragraph 1;
be designed to allow, on the basis of relevant information provided, to identify the applicable reporting obligations and to be redirected to the appropriate national entry point referred in Article 23b;
make available simplified and documented information on incident notification processes in the different Member States, such as help guides or tutorials.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the NIS Cooperation Group and the CSIRT Network. ENISA shall establish structured communication channels ensuring that information available on the single-information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 2a.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
After establishing the incident reporting information point and in cooperation with the NIS Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
Article 23a
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
The incident reporting information point shall:
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and
make available simplified and documented information on incident notification processes in the different Member States.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article 23a
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point
ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’).
The incident reporting information point shall:
be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and
make available simplified and documented information on incident notification processes in the different Member States.
When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a.
After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on:
regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures;
national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations;
content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident.
Article 23a
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’). (2) The incident reporting information point shall: (a) be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States. (3) When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a. (4) The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident. (5) After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on: (a) regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures; (b) national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations; (c) content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.
Official source passage and amending instruction
1. The following Article 23a is added: ‘Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the identification and fulfilment of the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘incident reporting information point’). (2) The incident reporting information point shall: (a) be designed to allow, on the basis of relevant information provided, the identification of the applicable reporting obligations referred to in paragraph 1 and the direction to the appropriate national entry point referred in Article 23b, and (c) make available simplified and documented information on incident notification processes in the different Member States. (3) When developing the incident reporting information point, ENISA shall consult the relevant national competent authorities under the relevant Union legal acts, the Cooperation Group, the CSIRT Network and other relevant bodies or groups established at Union level under relevant Union legal acts. ENISA shall establish structured communication channels to ensure that information available on the incident reporting information point is swiftly and effectively updated. Member States shall communicate to ENISA all relevant and necessary information for the purpose of paragraph 1a. (4) The incident reporting information point shall not enable the submission, transmission, storage or processing of any incident notification or related data, and shall not collect any information allowing the identification of the notifying entity or of any incident. (5) After establishing the incident reporting information point and in cooperation with the Cooperation Group, ENISA shall explore the possibility to extend the incident reporting information point by providing a report on: (a) regulatory mapping of relevant EU legal acts imposing cybersecurity risk management measures; (b) national measures, including transposition measures, implementing relevant Union legal acts imposing cybersecurity risk management obligations; (c) content to support entities in complying with obligations, in particular regarding entity registration, and cybersecurity risk-management.’
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Additional proposed wording Amendment 76 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
The Commission shall, by means of implementing acts, develop a common notification template for the single-entry point covering the Union acts referred to in paragraph 1 that provide for notification through that single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. When preparing the draft implementing acts, the Commission shall consult ENISA, the Cooperation Group, the network of computer security incident response teams (CSIRTs Network) and, where relevant, other competent authorities responsible for the Union legal acts concerned;
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3a.
The Commission shall, by means of implementing acts, develop a common notification template for the single-entry point covering the Union acts referred to in paragraph 1 that provide for notification through that single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. When preparing the draft implementing acts, the Commission shall consult ENISA, the Cooperation Group, the network of computer security incident response teams (CSIRTs Network) and, where relevant, other competent authorities responsible for the Union legal acts concerned;
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3a.
The Commission shall, by means of implementing acts, develop a common notification template for the single-entry point covering the Union acts referred to in paragraph 1 that provide for notification through that single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. When preparing the draft implementing acts, the Commission shall consult ENISA, the Cooperation Group, the network of computer security incident response teams (CSIRTs Network) and, where relevant, other competent authorities responsible for the Union legal acts concerned;
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 270 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 271 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 272 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 273 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 274 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 275 · Tobiasz Bocheński, Kosma Złotowski JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems, with regard that submitted notification is forwarded to all relevant authorities in a legally effective manner;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 276 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 277 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 278 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 279 · Daniel Buda JURI
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 501 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 502 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA
shallmay develop and maintain asingle-point of entrypointto support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘Union point of entry’). ENISA shall act as the single-European coordination point between the national single points of entry established or appointed by the Member States, while guaranteeing their interoperability and the secure routing of notifications; it shall not function as a centralised point’)for the actual receipt, transmission or storage of notifications. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that coordination between thesingle-national points of entrypointbuilds on the single reporting platform established for the Member States under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 503 · Virginie Joron IMCO
The Union point of entry shall be based on existing national notification systems and shall guarantee the secure routing and interoperability of notifications between the notifying entities and the competent national authorities, without centralising the storage of these notifications within a single body. ENISA’s role shall be limited to technical operations and routing as well as checking the format and completeness of the notifications; ENISA shall not be the recipient of the notifications in substantive terms.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1a.
The Union point of entry shall be based on existing national notification systems and shall guarantee the secure routing and interoperability of notifications between the notifying entities and the competent national authorities, without centralising the storage of these notifications within a single body. ENISA’s role shall be limited to technical operations and routing as well as checking the format and completeness of the notifications; ENISA shall not be the recipient of the notifications in substantive terms.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 504 · Morten Løkkegaard, Svenja Hahn, Sandro Gozi IMCO
Justification
Sensitive incident information, including information related to vulnerabilities, mitigation measures and ransomware, must be protected by strong confidentiality and access-control safeguards. This is necessary to build trust in the single-entry point and to avoid underreporting by entities operating across the Single Market.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1), including information concerning vulnerabilities, mitigation measures, ransomware demands, payment information or other commercially or legally sensitive information, and shall ensure that such information is subject to appropriate confidentiality, professional secrecy, access-control and data minimisation safeguards, while ensuring that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 505 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA and the national points of entry, each within their respective responsibilities, shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via
the single-entrythis point. ENISA and the national points of entry shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 506 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network, the national single points of entry and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 507 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
entities using the single-entry point receive an electronic confirmation of submission and, where appropriate, information on the competent authorities to which the notification has been transmitted;
Justification
Businesses need proof of compliance and clarity on where their report has gone.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- (ea)
entities using the single-entry point receive an electronic confirmation of submission and, where appropriate, information on the competent authorities to which the notification has been transmitted;
- (ea)
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 508 · Sophia Kircher IMCO
Justification
As companies and organisations are currently integrating NIS2 requirements into their processes as part of the ongoing national implementation, companies should be able to fulfil existing reporting obligations through the same mechanism, to avoid creating additional administrative burden or duplicate reporting requirements
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point and shall, to the greatest extent possible, enable entities to comply with existing reporting obligations under Union law, including Regulation (EU) 2022/2554 (DORA) and without requiring the resubmission of information already provided under other reporting frameworks.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 509 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
Justification
“Can be used” is too weak. The whole political point is that one report should legally count as one report.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point should be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 510 · Sophia Kircher IMCO
The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering core elements re-quired under Union legal acts that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- (3a)
The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering core elements re-quired under Union legal acts that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.
- (3a)
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 511 · Morten Løkkegaard, Svenja Hahn, Sandro Gozi IMCO
Member States shall not require entities to submit the same information through additional national reporting channels, portals or formats where that information has been submitted through the single-entry point in accordance with this Article, unless strictly necessary for reasons of national security and duly justified.
Justification
Avoids gold-plating and ensures the single-entry point does not become the 28th portal on top of 27 national ones.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- (3a)
Member States shall not require entities to submit the same information through additional national reporting channels, portals or formats where that information has been submitted through the single-entry point in accordance with this Article, unless strictly necessary for reasons of national security and duly justified.
- (3a)
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 513 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the national single points of entry. The notifications shall be received and handled substantively at the level of the national competent authorities.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 514 · Virginie Joron IMCO
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the national single
-points of entrypointfor each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1736 · François-Xavier Bellamy ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1737 · Katri Kulmuni ITRE · LIBE
Justification
Businesses in the EU are subject toseveral reporting mechanisms forsecurity incidents under NIS2, CRA,GDPR, and DORA, creating undesirableoverlap and double work. For example, different bumpers exist for securityincidents in the CRA, DORA and NIS2,and different reports are required for thesame event due to divergingrequirements in the various acts. Thereporting deadlines are alsoinconsistent. Uploading to the reportingplatform is merely the final step in alonger process. To achieve an actualreduction in administrative burdens forEuropean businesses it is necessary toharmonise all steps within the securityincident reporting process. Work towardsgreater alignment of reportingrequirements, including timelines (96hours) and trigger points, to reduceunnecessary administrative burden andduplication.
against:
Article 23a
SingleNational single-entry pointpoints and interoperability for incident reporting/data breaches
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1738 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
SingleNational single-entry pointpoints and interoperability for incident reporting/data breaches
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1739 · Henrik Dahl ITRE · LIBE
against:
Article 23a
SingleNational single-entry pointpoints and interoperability for incident reporting/data breaches
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1740 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
Justification
Member States establish a single national entry point for the submission of notifications. The simplification sought for reporting entities is achieved through a single national interface, not through the transfer to a Union body of competences exercised at national level. A single Union database of incident notifications would by its very nature constitute a target of the first order and a single point of vulnerability.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA
shallmay develop and maintainaansingle-EU entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘EU entry-point'). ENISA shall act as the single European point of coordination between the national single-entry points established or designated by the Member States, ensuring their interoperability and the secure routing of notifications; it shall not constitute a centralised point’)for the substantive receipt, transmission or storage of notifications. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that thesingle-coordination between national points of entrypointbuilds on the single reporting platform established by the Member States under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1741 · Katri Kulmuni ITRE · LIBE
Justification
Deliver a European harmonized secureinteroperable technical infrastructure toconnect national established Single-Entry Points (SEPs) for reporting thatfacilitates entities in scope of multiplelegal incident reporting obligations tosubmit one report to be compliant withall applicable rules. See example ofLuxembourg and Denmark. We supportthe settingup of one integrated reportingportal per Member State, covering allstatutory reporting obligations, coupledwith full EU interoperability throughuniform technical and functionalstandards; and automated and securetransmission where crossborder notifications are required. Companies inall sectors should be allowed to leveragetheir country of main establishment asthe primary interface (single entry point)for cybersecurity incident reportingunder relevant EU legislation, providedthat this is combined with commontemplates, definitions and deadlines,and with automated, securetransmission to competent authorities inMember States via national single entrypoints where cross border notificationsare required. ENISA’s role should besupportive and focus on standardisation,interoperability and quality assurance.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISAMember States shalldevelopensureandthemaintainestablishment of a national single-entry pointto supportfor theobligationnotificationto reportof incidentsand related eventsundertheUnion legal actswhereprovidingthoseforUnionsuchlegal acts provide so (‘single-entry point’)obligations.Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1742 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISAMember States shalldevelopensureandthemaintainestablishment of a national single-entry pointto supportfor theobligationnotificationto reportof incidentsand related eventsundertheUnion legal actswhereprovidingthoseforUnionsuchlegal acts provide so (‘single-entry point’)obligations.Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1743 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISAMember States shalldevelopensureandthemaintainestablishment of a national single-entry pointto supportfor theobligationnotificationto reportof incidentsand related eventsundertheUnion legal actswhereprovidingthoseforUnionsuchlegal acts provide so (‘single-entry point’)obligations.Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1744 · Markus Buchheit ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA
shallmay, at the request of one or more Member States, develop and maintaina single-entry point totechnical support tools for theobligationnotificationtoofreportcross-border or Union-wide systemic incidents and related events,underwhere this is expressly provided for in the relevant Union legal actswhereandthose Union legal acts provide so (‘single-entry point’). Withoutwithout prejudice toArticle 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the singlenational reportingplatform established under that Regulationchannels. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1745 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA
mayshall ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1746 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA
mayshall ensure that the single-entry point builds on the single reporting platform established under that Regulation. - 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1747 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(1a) In Article 23a, the following paragraph is inserted:
The EU entry point shall build on existing national reporting systems and shall ensure the secure routing and interoperability of notifications between reporting entities and the competent national authorities, without centralising the storage of those notifications within a single body. The role of ENISA is limited to the technical operation, routing and format and completeness check of the notifications; ENISA is not a recipient of the notifications for substantive purposes.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1a.
The EU entry point shall build on existing national reporting systems and shall ensure the secure routing and interoperability of notifications between reporting entities and the competent national authorities, without centralising the storage of those notifications within a single body. The role of ENISA is limited to the technical operation, routing and format and completeness check of the notifications; ENISA is not a recipient of the notifications for substantive purposes.'
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1748 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
(1a) In Article 23a, the following paragraph is inserted:
ENISA shall forward the information submitted or disseminated via the single-entry point according to the relevant Union legal acts to the competent authorities in the relevant Member State or Member States.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1a.
ENISA shall forward the information submitted or disseminated via the single-entry point according to the relevant Union legal acts to the competent authorities in the relevant Member State or Member States.'
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1749 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
(1b) In Article 23a, the following paragraph is inserted:
ENISA should take into account existing such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point to ensure continuity and interoperability.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1b.
ENISA should take into account existing such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point to ensure continuity and interoperability.'
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1750 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall
takemakeappropriateaanddefinitionproportionateoftechnical,whatoperationalconstitutesandaorganisationalsignificantmeasuresincidenttothatmanageshouldtheberisks posedreported to thesecurity of the single-entry point and the information submitted or disseminated via thenational single-entry point.ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1751 · Katri Kulmuni ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall
takemakeappropriateaanddefinitionproportionateoftechnical,whatoperationalconstitutesandaorganisationalsignificantmeasuresincidenttothatmanageshouldtheberisks posedreported to thesecurity of the single-entry point and the information submitted or disseminated via thenational single-entry point.ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1752 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall
takemakeappropriateaanddefinitionproportionateoftechnical,whatoperationalconstitutesandaorganisationalsignificantmeasuresincidenttothatmanageshouldtheberisks posedreported to thesecurity of the single-entry point and the information submitted or disseminated via thenational single-entry point.ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1753 · Diego Solier, Sebastian Tynkkynen, Elena Donazzan ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. The Commission, ENISA and the Cooperation Group shall develop harmonised reporting templates, reporting guidance and coordinated supervisory criteria for incidents that may trigger obligations under more than one Union cybersecurity instrument. Member States shall ensure that entities can submit the required information through a single-entry point.”
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1754 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA and the national points of entry shall each, within their respective responsibilities, take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via
the single-entry pointit. ENISA and the national points of entry shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1755 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová ITRE · LIBE
(2a) In Article 23a, the following paragraph is inserted:
The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
enable entities to submit a single notification to fulfil multiple reporting obligations;
harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act);
consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 2a.
The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
- (a)
enable entities to submit a single notification to fulfil multiple reporting obligations;
- (b)
harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act);
- (c)
consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
-
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'
- (a)
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1756 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, Katri Kulmuni, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
(2a) In Article 23a, the following paragraph is inserted:
The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
enable entities to submit a single notification to fulfil multiple reporting obligations;
harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2024/1689 (AI Act);
consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 2a.
The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:
- (a)
enable entities to submit a single notification to fulfil multiple reporting obligations;
- (b)
harmonize reporting timelines, deadlines, thresholds and, where possible, other data relevant to the reporting obligations covered in, at leat, Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2016/679 (GDPR, Directive (EU) 2022/2557 (CER), Regulation (EU) No 910/2014 (eIDAS), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2024/1689 (AI Act);
- (c)
consist of a core section of data points applicable across all reporting obligations from relevant Union legal acts under point (b), that may be complemented by modular extensions that incorporate sectoral or other data fields specific to a particular Union legal act.
-
In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'
- (a)
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1757 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point.ENISA shall developtheandspecificationsmaintaininancooperationincidentwithreporting information point to support theCommission,obligationthetoCSIRTsreportnetworkincidents andtherelatedcompetent authoritiesevents under the Union legal acts where those Union legal acts provide so. (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph(1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1758 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point.ENISA shall developtheandspecificationsmaintaininancooperationincidentwithreporting information point to support theCommission,obligationthetoCSIRTsreportnetworkincidents andtherelatedcompetent authoritiesevents under the Union legal acts where those Union legal acts provide so. (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph(1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1759 · Katri Kulmuni ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point.ENISA shall developtheandspecificationsmaintaininancooperationincidentwithreporting information point to support theCommission,obligationthetoCSIRTsreportnetworkincidents andtherelatedcompetent authoritiesevents under the Union legal acts where those Union legal acts provide so. (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph(1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1760 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Eva Maydell, Christian Ehler ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement, in a timely manner, the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications, following a prior public consultation with the relevant stakeholders in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1761 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall
provide andimplement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point.ENISAasshallestablisheddevelop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referredaccording toinparagraph(1). The specifications shall ensure that:- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 8.
ENISA shall support the Commission in developing the specifications, in consultation with the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1762 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network, the national single-entry points, and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1763 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
(1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1764 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
and between the national points of entry is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1765 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1766 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information through their national point of entry from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1767 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1768 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (e)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1769 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the national points of entry and the EU entry point are interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1770 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1771 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using a national point of entry can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Remove proposed wording Amendment 1772 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1773 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Paulo Cunha, Christian Ehler ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point, and shall, to the greatest extent possible, enable entities to comply with existing reporting obligations under Union law, including Regulation (EU) 2022/2554 (DORA) and without requiring the resubmission of information already provided under other reporting frameworks.. In line with the principle of administrative simplification and the 'report-once' policy, it is necessary to avoid duplicative reporting obligations for financial entities that are already subject to stringent operational resilience requirements. Where a financial entity submits an incident report under Regulation (EU) 2022/2554 [DORA], that submission should be considered sufficient to satisfy the reporting requirements under the Regulation (EU) 2024/2847 [CRA]. This approach ensures regulatory coherence, legal clarity and reduces the compliance burden on the financial sector.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1774 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point shall constitute timely submission to all competent authorities provided that the report is submitted within the applicable legal deadline as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1775 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
In Article 23, paragraph 3, the following point is added:
technical measures include at least:
end-to-end encryption;
zero-trust architecture;
compartmentalisation;
mandatory audits and penetration testing;
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (fa)
technical measures include at least:
- i.
end-to-end encryption;
- ii.
zero-trust architecture;
- iii.
compartmentalisation;
- iv.
mandatory audits and penetration testing;
- i.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1776 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
(fa) In Article 23a, paragraph 1, the following point is inserted
notifications submitted in English are allowed, at least for the first notification.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- (fa)
notifications submitted in English are allowed, at least for the first notification.'
- (fa)
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1777 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
(fb) In Article 23a, paragraph 1, the following point is added
the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- (fa)
the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'
- (fa)
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1778 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
(3a) In Article 23a, the following paragraph is inserted:
The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering the Union Acts referred to in paragraph (1) that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations, including, where technically feasible, through interoperable reporting channels designed to reduce duplication of reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3a.
The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering the Union Acts referred to in paragraph (1) that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations, including, where technically feasible, through interoperable reporting channels designed to reduce duplication of reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.'
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1779 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
(3a) In Article 23a, paragraph 3, the following points are added
notifications submitted in English are allowed, at least for the first notification
the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (fa)
notifications submitted in English are allowed, at least for the first notification
- (fb)
the single entry-point has the ability to save a partially completed notification as a draft, allows for multi-user colloberative access, and offers an automated notification systems to alert reporting entities of upcoming compliance deadlines.'
- (fb)
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1780 · Katri Kulmuni ITRE · LIBE
(3a) In Article 23a, the following paragraph is inserted:
Entities shall submit incident notifications within 96 hours to the national single-entry point of their Member State of main establishment.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3a.
Entities shall submit incident notifications within 96 hours to the national single-entry point of their Member State of main establishment.'
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1781 · Katri Kulmuni ITRE · LIBE
(3b) In Article 23a, the following paragraph is inserted:
Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where cross-border notifications are required.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3b.
Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where cross-border notifications are required.'
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1782 · Katri Kulmuni ITRE · LIBE
(3c) In Article 23a, the following paragraph is inserted:
ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 3c.
ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.'
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1783 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through national single-entry points. The substantive receipt and processing of notifications shall take place at the level of the competent national authorities.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1784 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISAEntities shallnotsubmithaveincidentaccessnotifications within 96 hours to thenotificationsnationalsubmitted through the single-entrysingleentry point of their Member State of main establishment. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1785 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISAEntities shallnotsubmithaveincidentaccessnotifications within 96 hours to thenotifications submitted through thenational single-entry point of their Member State of main establishment. - 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1786 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Christian Ehler ITRE · LIBE
(4a) In Article 23a, the following paragraph is inserted:
The establishment and operation of a single-entry point represent a critical technical milestone for the Union’s cybersecurity related incidents notification framework. To ensure that the specifications developed by ENISA are technically robust, future-proof, and operationally viable, it is essential that the drafting process remains open and transparent. Therefore, ENISA should consult not only with national authorities but also with relevant industry representatives.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- (4a)
The establishment and operation of a single-entry point represent a critical technical milestone for the Union’s cybersecurity related incidents notification framework. To ensure that the specifications developed by ENISA are technically robust, future-proof, and operationally viable, it is essential that the drafting process remains open and transparent. Therefore, ENISA should consult not only with national authorities but also with relevant industry representatives.'
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1787 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(4a) In Article 23a, the following paragraph is inserted:
Where the same incident triggers notification obligations under more than one Union legal act, the Member states shall designate a coordinating competent authority responsible for coordinating requests for additional information and ensuring coherent communication with the reporting entity. The coordinating competent authority will be notified to ENISA and be included in the single-entry point system.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 4a.
Where the same incident triggers notification obligations under more than one Union legal act, the Member states shall designate a coordinating competent authority responsible for coordinating requests for additional information and ensuring coherent communication with the reporting entity. The coordinating competent authority will be notified to ENISA and be included in the single-entry point system.'
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1788 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(4b) In Article 23a, the following paragraph is inserted:
ENISA in cooperation with the coordinating competent authorities shall create a database of cases and where relevant publish at least anonymised threat intelligence, lessons learned, mitigation advice.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 4b.
ENISA in cooperation with the coordinating competent authorities shall create a database of cases and where relevant publish at least anonymised threat intelligence, lessons learned, mitigation advice.'
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1789 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
WithinThe[18]competentmonths from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal actauthorities, includingtestingCSIRTs,thatshalltakes into account the specificities and requirements forprocess the notificationssetand,outwherebyrequiredeach respectiveunder Unionlegal actlaw,and after consulting the Commission and thetransmit relevantcompetentinformationauthoritiestounder the respective Union legal actsENISA.ENISAEntities shallenablenotthebenotification of incidents under each Union legal act referredrequired toinreportparagraph (1) only after piloting the functioning and after the Commission published a notice pursuantdirectly toparagraph 6ENISA. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1790 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
WithinThe[18]competentmonths from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal actauthorities, includingtestingCSIRTs,thatshalltakes into account the specificities and requirements forprocess the notificationssetand,outwherebyrequiredeach respectiveunder Unionlegal actlaw,and after consulting the Commission and thetransmit relevantcompetentinformationauthoritiestounder the respective Union legal actsENISA.ENISAEntities shallenablenotthebenotification of incidents under each Union legal act referredrequired toinreportparagraph (1) only after piloting the functioning and after the Commission published a notice pursuantdirectly toparagraph 6ENISA. - 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1791 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the EU and national single-entry
pointpoints for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1792 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
TheMemberCommissionStates shall,inensurecooperationinteroperabilitywithbetweenENISA, assess the proper functioning, reliability, integrity and confidentiality of thenational single-entrypoint. When the Commissionpoints,afterincludingconsultationsecure and automated transmission oftheinformationCSIRTswherenetworkcrossborderandnotificationsthearecompetent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Unionrequired. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1793 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
TheMemberCommissionStates shall,inensurecooperationinteroperabilitywithbetweenENISA, assess the proper functioning, reliability, integrity and confidentiality of thenational single-entrypoint. When the Commissionpoints,afterincludingconsultationsecure and automated transmission oftheinformationCSIRTswherenetworkcrossborderandnotificationsthearecompetent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Unionrequired. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1794 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the EU and national single-entry
pointpoints. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. - 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1795 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity, availability and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1796 · Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality,ENISA shalltake,supportininteroperabilitycooperationand convergence by developing common technical standards and promoting a harmonised reporting template aligned withtheinternationalCommission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the resultsstandards.Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1797 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality,ENISA shalltake,supportininteroperabilitycooperationand convergence by developing common technical standards and promoting a harmonised reporting template aligned withtheinternationalCommission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the resultsstandards.Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entrypoint and shall publish a notice in accordance with paragraph 6.
Alternative wording Amendment 1798 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph
(1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. - 1.
and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph
(1) is ensured; - (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; - (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; - (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; - (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; - (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 1.
is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph
- (b)
- 1.
to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph
- (c)
- 1.
are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (d)
- 4.
Unless provided for in the Union legal acts referred to in paragraph
(1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. - 1.
of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph
(1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. - 1.
only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the EU and national single-entry
pointpointsdoesdo not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1799 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(7a) In Article 23a, the following paragraph is added:
The Commission shall adopt implementing acts establishing a common Union incident reporting data model and interoperable technical specifications for all reporting obligations covered by this Regulation. The implementing act shall include a EU-wide incident taxonomy including common incident categories, common severity levels, common terminology.'
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
- 7a.
The Commission shall adopt implementing acts establishing a common Union incident reporting data model and interoperable technical specifications for all reporting obligations covered by this Regulation. The implementing act shall include a EU-wide incident taxonomy including common incident categories, common severity levels, common terminology.'
Additional proposed wording Amendment 1802 · François-Xavier Bellamy ITRE · LIBE
ENISA shall develop and maintain a single point of contact to provide an overview of regulatory obligations regarding incident reporting, and to direct users to the various national reporting platforms.
This incident reporting information point shall identify the applicable reporting obligations, the direction to the appropriate national entry point, and make available simplified and documented information on incident notification processes in the different Member States.
The incident reporting information point shall not collect any information allowing the identification of the notifying entity or of any incident. Member States shall endeavour to design their national entry point with a view to making the national entry points interoperable with the national entry points of other Member States, to facilitate the alignment of incident notifications with cross-border reporting obligations.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1a.
ENISA shall develop and maintain a single point of contact to provide an overview of regulatory obligations regarding incident reporting, and to direct users to the various national reporting platforms.
This incident reporting information point shall identify the applicable reporting obligations, the direction to the appropriate national entry point, and make available simplified and documented information on incident notification processes in the different Member States.
The incident reporting information point shall not collect any information allowing the identification of the notifying entity or of any incident. Member States shall endeavour to design their national entry point with a view to making the national entry points interoperable with the national entry points of other Member States, to facilitate the alignment of incident notifications with cross-border reporting obligations.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Additional proposed wording Amendment 1805 · François-Xavier Bellamy ITRE · LIBE
By 6 months after the entry into force of this Regulation, the Commission shall submit a report to the European Parliament and to the Council outlining common elements and differences in definitions, thresholds, deadlines, formats and procedures applying to Article 23 of Directive (EU) 2022/2555, Article 19a (1a), Article 24 (2a) and Article 45a (3a) of Regulation (EU) 910/2014, Article 33 (1) of Regulation (EU) 2016/679, Article 19 (1) and (2) of Regulation (EU) 2022/2554, and Article 15(1) of Directive (EU) 2022/2557.
The report shall in particular consider concrete steps and a timeline for introducing the unified approach to incident reporting under the Union legal acts.
against:
Article 23a
Single-entry point for incident reporting
- 1.
ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
- 1b.
By 6 months after the entry into force of this Regulation, the Commission shall submit a report to the European Parliament and to the Council outlining common elements and differences in definitions, thresholds, deadlines, formats and procedures applying to Article 23 of Directive (EU) 2022/2555, Article 19a (1a), Article 24 (2a) and Article 45a (3a) of Regulation (EU) 910/2014, Article 33 (1) of Regulation (EU) 2016/679, Article 19 (1) and (2) of Regulation (EU) 2022/2554, and Article 15(1) of Directive (EU) 2022/2557.
The report shall in particular consider concrete steps and a timeline for introducing the unified approach to incident reporting under the Union legal acts.
- 2.
ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
- 3.
ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
- (a)
the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
- (b)
technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
- (c)
the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
- (d)
where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
- (e)
entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
- (f)
a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
- (a)
- 4.
Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
- 5.
Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
- 6.
The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
- 7.
Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 23a
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 23a
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 23a
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 23a
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 23a
Wording reproduced in the amendment → Amendment 1736 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1736 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1737 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1737 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1738 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1738 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1739 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1739 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1740 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1740 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1741 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1741 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1742 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1742 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1743 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1743 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1744 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1744 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1745 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1745 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1746 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1746 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1750 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1750 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1751 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1751 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1752 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1752 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1753 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1753 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1754 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1754 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1757 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1757 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1758 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1758 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1759 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1759 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1760 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1760 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1761 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1761 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1762 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1762 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1763 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1763 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1764 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1764 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1765 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1765 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1766 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1766 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1767 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1767 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1768 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1768 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1769 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1769 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1770 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1770 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1771 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1771 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1772 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1772 · ITRE–LIBE amendments 1741–1840 to the draft report: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 1773 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1773 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1774 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1774 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1783 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1783 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1784 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1784 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1785 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1785 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1789 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1789 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1790 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1790 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1791 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1791 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1792 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1792 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1793 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1793 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1794 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1794 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1795 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1795 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1796 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1796 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1797 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1797 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 1798 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1798 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 23a
Wording reproduced in the amendment → Amendment 501 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 501 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 502 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 502 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 504 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 504 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 505 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 505 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 506 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 506 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 508 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 508 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 509 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 509 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 513 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 513 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 514 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 514 · IMCO amendments 329–532 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 270 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 270 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 271 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 271 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 272 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 272 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 273 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 273 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 274 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 274 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 275 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 275 · JURI amendments 69–296 to the draft opinion
Article 23a
Wording reproduced in the amendment → Amendment 276 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 276 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 277 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 277 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 278 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 278 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a
Wording reproduced in the amendment → Amendment 279 · JURI amendments 69–296 to the draft opinion: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 279 · JURI amendments 69–296 to the draft opinion: removal
This wording is removed.
Article 23a (new) – paragraph 1 – point 2
Wording reproduced in the amendment → Amendment 505 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 505 · IMCO amendments 329–532 to the draft opinion
Article 23a (new) – paragraph 3
Wording reproduced in the amendment → Amendment 1760 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded