Digital Omnibus tracker

NIS2 Directive · Directive (EU) 2022/2555

Article 23a

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 18 parts · 4 Council drafts · 90 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to NIS2 Directive

The wording proposed by the Commission at the start of this legislative file.

Full article with Commission changes

Article with proposed changes

Official consolidated text dated 14 December 2022, with the Commission proposal change affecting this article applied.

Article 23a

Single-entry point for incident reporting

  1. 1.

    ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.

  2. 2.

    ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.

  3. 3.

    ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:

    1. (a)

      the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;

    2. (b)

      technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;

    3. (c)

      the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;

    4. (d)

      where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;

    5. (e)

      entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;

    6. (f)

      a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.

  4. 4.

    Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.

  5. 5.

    Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.

  6. 6.

    The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.

  7. 7.

    Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.

Commission source wording and instructions

Article 23a

Commission proposal

Article 23a Single-entry point for incident reporting (1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation. (2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. (3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that: (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; (b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; (c) the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; (d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; (e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; (f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point. (4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point. (5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6. (6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union. (7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 23a

May Presidency compromise

Council wording reconstructed for this provision from the official operation

Article 23a Incident reporting information point (1) ENISA shall develop and maintain an incident reporting information point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘ incident reporting information point’).

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Political group at the amendment date where available; otherwise the current Parliament affiliation.

Additional proposed wording Amendment 76 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
Preview
against:
Remove proposed wording Amendment 270 · Daniel Buda JURI
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 271 · Daniel Buda JURI
Single-entry point for incident reporting
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 272 · Daniel Buda JURI
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 273 · Daniel Buda JURI
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 274 · Daniel Buda JURI
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that: (a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured; (b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems; (c) the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account; (d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point; (e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point; (f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Alternative wording Amendment 275 · Tobiasz Bocheński, Kosma Złotowski JURI
(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems, with regard that submitted notification is forwarded to all relevant authorities in a legally effective manner;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Regulation (EU) 2016/679 / Article 23 a

Remove proposed wording Amendment 276 · Daniel Buda JURI
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entry point.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 277 · Daniel Buda JURI
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 278 · Daniel Buda JURI
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 279 · Daniel Buda JURI
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.’
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Deletion marker printed in the source: deleted

Alternative wording Amendment 501 · Virginie Joron IMCO
Single-entryEuropean point of entry for incident reporting
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Alternative wording Amendment 502 · Virginie Joron IMCO
(1) ENISA shallmay develop and maintain a single-entrypoint pointof entry to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entryUnion point of entry’). ENISA shall act as the single European coordination point between the national single points of entry established or appointed by the Member States, while guaranteeing their interoperability and the secure routing of notifications; it shall not function as a centralised point for the actual receipt, transmission or storage of notifications. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that coordination between the single-entrynational pointpoints of entry builds on the single reporting platform established for the Member States under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Additional proposed wording Amendment 503 · Virginie Joron IMCO
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a

Alternative wording Amendment 504 · Morten Løkkegaard, Svenja Hahn, Sandro Gozi IMCO
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1), including information concerning vulnerabilities, mitigation measures, ransomware demands, payment information or other commercially or legally sensitive information, and shall ensure that such information is subject to appropriate confidentiality, professional secrecy, access-control and data minimisation safeguards, while ensuring that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Justification

Sensitive incident information, including information related to vulnerabilities, mitigation measures and ransomware, must be protected by strong confidentiality and access-control safeguards. This is necessary to build trust in the single-entry point and to avoid underreporting by entities operating across the Single Market.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (UE) 2022/2555 / Article 23a – paragraph 1 – point 2

Alternative wording Amendment 505 · Virginie Joron IMCO
(2) ENISA and the national points of entry, each within their respective responsibilities, shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entrythis point. ENISA and the national points of entry shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a (new) – paragraph 1 – point 2

Alternative wording Amendment 506 · Virginie Joron IMCO
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network, the national single points of entry and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a – paragraph 1 – point 3

Additional proposed wording Amendment 507 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
Justification

Businesses need proof of compliance and clarity on where their report has gone.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point e a (new)

Alternative wording Amendment 508 · Sophia Kircher IMCO
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point and shall, to the greatest extent possible, enable entities to comply with existing reporting obligations under Union law, including Regulation (EU) 2022/2554 (DORA) and without requiring the resubmission of information already provided under other reporting frameworks.
Justification

As companies and organisations are currently integrating NIS2 requirements into their processes as part of the ongoing national implementation, companies should be able to fulfil existing reporting obligations through the same mechanism, to avoid creating additional administrative burden or duplicate reporting requirements

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point f

Alternative wording Amendment 509 · Morten Løkkegaard, Svenja Hahn, Jeannette Baljeu, Sandro Gozi IMCO
(f) a single notification of information submitted by an entity via the single-entry point canshould be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
Justification

“Can be used” is too weak. The whole political point is that one report should legally count as one report.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point f

Additional proposed wording Amendment 510 · Sophia Kircher IMCO
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point 3 a (new)

Additional proposed wording Amendment 511 · Morten Løkkegaard, Svenja Hahn, Sandro Gozi IMCO
Justification

Avoids gold-plating and ensures the single-entry point does not become the 28th portal on top of 27 national ones.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point 3 a (new)

Alternative wording Amendment 513 · Virginie Joron IMCO
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through the single-entrynational pointsingle points of entry. The notifications shall be received and handled substantively at the level of the national competent authorities.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a – paragraph 1 – point 4

Alternative wording Amendment 514 · Virginie Joron IMCO
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entrynational pointsingle points of entry for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 a – paragraph 1 – point 5

Remove proposed wording Amendment 1736 · François-Xavier Bellamy ITRE · LIBE
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a

Deletion marker printed in the source: deleted

Alternative wording Amendment 1737 · Katri Kulmuni ITRE · LIBE
Single-entryNational pointsingle-entry points and interoperability for incident reporting/data breaches
Justification

Businesses in the EU are subject toseveral reporting mechanisms forsecurity incidents under NIS2, CRA,GDPR, and DORA, creating undesirableoverlap and double work. For example, different bumpers exist for securityincidents in the CRA, DORA and NIS2,and different reports are required for thesame event due to divergingrequirements in the various acts. Thereporting deadlines are alsoinconsistent. Uploading to the reportingplatform is merely the final step in alonger process. To achieve an actualreduction in administrative burdens forEuropean businesses it is necessary toharmonise all steps within the securityincident reporting process. Work towardsgreater alignment of reportingrequirements, including timelines (96hours) and trigger points, to reduceunnecessary administrative burden andduplication.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – title

Alternative wording Amendment 1738 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
Single-entryNational pointsingle-entry points and interoperability for incident reporting/data breaches
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – title

Alternative wording Amendment 1739 · Henrik Dahl ITRE · LIBE
Single-entryNational pointsingle-entry points and interoperability for incident reporting/data breaches
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – title

Alternative wording Amendment 1740 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(1) ENISA shallmay develop and maintain aan single-entryEU entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘EU entry-point'). ENISA shall act as the single European point of coordination between the national single-entry points established or designated by the Member States, ensuring their interoperability and the secure routing of notifications; it shall not constitute a centralised point’) for the substantive receipt, transmission or storage of notifications. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entrycoordination pointbetween national points of entry builds on the single reporting platform established by the Member States under that Regulation.
Justification

Member States establish a single national entry point for the submission of notifications. The simplification sought for reporting entities is achieved through a single national interface, not through the transfer to a Union body of competences exercised at national level. A single Union database of incident notifications would by its very nature constitute a target of the first order and a single point of vulnerability.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1741 · Katri Kulmuni ITRE · LIBE
(1) ENISAMember States shall developensure andthe maintainestablishment of a national single-entry point to supportfor the obligationnotification to reportof incidents and related events under the Union legal acts whereproviding thosefor Unionsuch legal acts provide so (‘single-entry point’)obligations. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Justification

Deliver a European harmonized secureinteroperable technical infrastructure toconnect national established Single-Entry Points (SEPs) for reporting thatfacilitates entities in scope of multiplelegal incident reporting obligations tosubmit one report to be compliant withall applicable rules. See example ofLuxembourg and Denmark. We supportthe settingup of one integrated reportingportal per Member State, covering allstatutory reporting obligations, coupledwith full EU interoperability throughuniform technical and functionalstandards; and automated and securetransmission where crossborder notifications are required. Companies inall sectors should be allowed to leveragetheir country of main establishment asthe primary interface (single entry point)for cybersecurity incident reportingunder relevant EU legislation, providedthat this is combined with commontemplates, definitions and deadlines,and with automated, securetransmission to competent authorities inMember States via national single entrypoints where cross border notificationsare required. ENISA’s role should besupportive and focus on standardisation,interoperability and quality assurance.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1742 · Henrik Dahl ITRE · LIBE
(1) ENISAMember States shall developensure andthe maintainestablishment of a national single-entry point to supportfor the obligationnotification to reportof incidents and related events under the Union legal acts whereproviding thosefor Unionsuch legal acts provide so (‘single-entry point’)obligations. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1743 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(1) ENISAMember States shall developensure andthe maintainestablishment of a national single-entry point to supportfor the obligationnotification to reportof incidents and related events under the Union legal acts whereproviding thosefor Unionsuch legal acts provide so (‘single-entry point’)obligations. Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1744 · Markus Buchheit ITRE · LIBE
(1) ENISA shallmay, at the request of one or more Member States, develop and maintain a single-entry point totechnical support tools for the obligationnotification toof reportcross-border or Union-wide systemic incidents and related events, underwhere this is expressly provided for in the relevant Union legal acts whereand those Union legal acts provide so (‘single-entry point’). Withoutwithout prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA may ensure that the single-entry point builds on the singlenational reporting platform established under that Regulationchannels.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1745 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA mayshall ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1

Alternative wording Amendment 1746 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
(1) ENISA shall develop and maintain a single-entry point to support the obligation to report incidents and related events under the Union legal acts where those Union legal acts provide so (‘single-entry point’). Without prejudice to Article 16 of Regulation (EU) 2024/2847 of the European Parliament and of the Council, ENISA mayshall ensure that the single-entry point builds on the single reporting platform established under that Regulation.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive 2022/2555 / Article 23a – paragraph 1

Additional proposed wording Amendment 1747 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE

(1a) In Article 23a, the following paragraph is inserted:

The EU entry point shall build on existing national reporting systems and shall ensure the secure routing and interoperability of notifications between reporting entities and the competent national authorities, without centralising the storage of those notifications within a single body. The role of ENISA is limited to the technical operation, routing and format and completeness check of the notifications; ENISA is not a recipient of the notifications for substantive purposes.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – Paragraph 1a (new)

Additional proposed wording Amendment 1748 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE

(1a) In Article 23a, the following paragraph is inserted:

ENISA shall forward the information submitted or disseminated via the single-entry point according to the relevant Union legal acts to the competent authorities in the relevant Member State or Member States.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1a (new)

Additional proposed wording Amendment 1749 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE

(1b) In Article 23a, the following paragraph is inserted:

ENISA should take into account existing such national technical solutions when developing the specifications on the technical, operational and organisational measures necessary to establish, maintain and securely operate the single-entry point to ensure continuity and interoperability.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1b (new)

Alternative wording Amendment 1750 · Henrik Dahl ITRE · LIBE
(2) ENISA shall takemake appropriatea anddefinition proportionateof technical,what operationalconstitutes anda organisationalsignificant measuresincident tothat manageshould thebe risks posedreported to the security of the single-entry point and the information submitted or disseminated via thenational single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2

Alternative wording Amendment 1751 · Katri Kulmuni ITRE · LIBE
(2) ENISA shall takemake appropriatea anddefinition proportionateof technical,what operationalconstitutes anda organisationalsignificant measuresincident tothat manageshould thebe risks posedreported to the security of the single-entry point and the information submitted or disseminated via thenational single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2

Alternative wording Amendment 1752 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(2) ENISA shall takemake appropriatea anddefinition proportionateof technical,what operationalconstitutes anda organisationalsignificant measuresincident tothat manageshould thebe risks posedreported to the security of the single-entry point and the information submitted or disseminated via thenational single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2

Alternative wording Amendment 1753 · Diego Solier, Sebastian Tynkkynen, Elena Donazzan ITRE · LIBE
(2) ENISA shall take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry point. ENISA shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts. The Commission, ENISA and the Cooperation Group shall develop harmonised reporting templates, reporting guidance and coordinated supervisory criteria for incidents that may trigger obligations under more than one Union cybersecurity instrument. Member States shall ensure that entities can submit the required information through a single-entry point.”
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2

Alternative wording Amendment 1754 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(2) ENISA and the national points of entry shall each, within their respective responsibilities, take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the single-entry point and the information submitted or disseminated via the single-entry pointit. ENISA and the national points of entry shall take into account the sensitivity of information submitted or disseminated pursuant to the Union legal acts referred to in paragraph (1) and ensure that competent authorities under those Union legal acts have access to and process the information as required under those Union legal acts.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – Paragraph 2

Additional proposed wording Amendment 1755 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Veronika Cifrová Ostrihoňová ITRE · LIBE

(2a) In Article 23a, the following paragraph is inserted:

The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:

In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2a (new)

Additional proposed wording Amendment 1756 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Sophie Wilmès, Nikola Minchev, Svenja Hahn, Andreas Glück, Katri Kulmuni, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE

(2a) In Article 23a, the following paragraph is inserted:

The Commission shall, by means of delegated act, develop one European notification template for the single-entry point. The European notification template shall:

In preparing the template, the Commission shall carry out a mapping of the Union’s reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations under point (b), in coopreration with ENISA, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned. The mapping shall provide an analysis of the extent to which reporting timelines, deadlines, thresholds and other data points relevant to the reporting obligations can be harmonized.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 2a (new)

Alternative wording Amendment 1757 · Henrik Dahl ITRE · LIBE
(3) ENISA shall providedevelop and implementmaintain an incident reporting information point to support the specificationsobligation onto thereport technical, operationalincidents and organisationalrelated measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authoritiesevents under the Union legal acts referredwhere tothose inUnion paragraphlegal (1)acts provide so. The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Alternative wording Amendment 1758 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(3) ENISA shall providedevelop and implementmaintain an incident reporting information point to support the specificationsobligation onto thereport technical, operationalincidents and organisationalrelated measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authoritiesevents under the Union legal acts referredwhere tothose inUnion paragraphlegal (1)acts provide so. The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Alternative wording Amendment 1759 · Katri Kulmuni ITRE · LIBE
(3) ENISA shall providedevelop and implementmaintain an incident reporting information point to support the specificationsobligation onto thereport technical, operationalincidents and organisationalrelated measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network and the competent authoritiesevents under the Union legal acts referredwhere tothose inUnion paragraphlegal (1)acts provide so. The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Alternative wording Amendment 1760 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Eva Maydell, Christian Ehler ITRE · LIBE
(3) ENISA shall provide and implement, in a timely manner, the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications, following a prior public consultation with the relevant stakeholders in cooperation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a (new) – paragraph 3

Alternative wording Amendment 1761 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point as established according to paragraph 8. ENISA shall developsupport the Commission in developing the specifications, in cooperationconsultation with the Commission, the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Alternative wording Amendment 1762 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(3) ENISA shall provide and implement the specifications on the technical, operational and organisational measures regarding the establishment, maintenance and secure operation of the single-entry point. ENISA shall develop the specifications in cooperation with the Commission, the CSIRTs network, the national single-entry points, and the competent authorities under the Union legal acts referred to in paragraph (1). The specifications shall ensure that:
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – Paragraph 3

Remove proposed wording Amendment 1763 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) is ensured;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Deletion marker printed in the source: deleted

Alternative wording Amendment 1764 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(a) the necessary capability for interoperability with regard to other relevant reporting obligations referred to in paragraph (1) and between the national points of entry is ensured;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3

Remove proposed wording Amendment 1765 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point b

Deletion marker printed in the source: deleted

Alternative wording Amendment 1766 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(b) technical arrangements for the relevant entities and authorities under the Union legal acts referred to in paragraph (1) to access, submit , retrieve, transmit or otherwise process information through their national point of entry from the single-entry point, are in place and, provide technical protocols and tools that allow the entities and authorities to further process the receive information within their systems;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point b

Remove proposed wording Amendment 1767 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(c) the specificities of the incident reporting requirements set out under the Union legal acts referred to in paragraph (1) are duly taken into account;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point c

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 1768 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(d) where relevant, the single-entry point is interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point d

Deletion marker printed in the source: deleted

Alternative wording Amendment 1769 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(d) where relevant, the single-entrynational points of entry and the EU entry point isare interoperable and compatible with European Business Wallets referred to in [Proposal for a Regulation: Insert title of the proposal] and that the European Business Wallets can be used at least to identify and authenticate entities using the single-entry point;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point d

Remove proposed wording Amendment 1770 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(e) entities using the single-entry point can retrieve and supplement information that they have previously submitted via the single-entry point;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point e

Deletion marker printed in the source: deleted

Alternative wording Amendment 1771 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(e) entities using thea single-entrynational point of entry can retrieve and supplement information that they have previously submitted via the single-entry point;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point e

Remove proposed wording Amendment 1772 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point f

Deletion marker printed in the source: deleted

Alternative wording Amendment 1773 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Paulo Cunha, Christian Ehler ITRE · LIBE
(f) a single notification of information submitted by an entity via the single-entry point can be used to fulfil reporting obligations as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point, and shall, to the greatest extent possible, enable entities to comply with existing reporting obligations under Union law, including Regulation (EU) 2022/2554 (DORA) and without requiring the resubmission of information already provided under other reporting frameworks.. In line with the principle of administrative simplification and the 'report-once' policy, it is necessary to avoid duplicative reporting obligations for financial entities that are already subject to stringent operational resilience requirements. Where a financial entity submits an incident report under Regulation (EU) 2022/2554 [DORA], that submission should be considered sufficient to satisfy the reporting requirements under the Regulation (EU) 2024/2847 [CRA]. This approach ensures regulatory coherence, legal clarity and reduces the compliance burden on the financial sector.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point f

Alternative wording Amendment 1774 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE
(f) a single notification of information submitted by an entity via the single-entry point canshall beconstitute usedtimely submission to fulfilall reportingcompetent obligationsauthorities provided that the report is submitted within the applicable legal deadline as set out under any of the other Union legal acts which provide for incident reporting to the single-entry point.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point f

Additional proposed wording Amendment 1775 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE

technical measures include at least:

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – point fa (new)

Additional proposed wording Amendment 1776 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point fa (new)

Additional proposed wording Amendment 1777 · Bart Groothuis, Ivars Ijabs, Morten Løkkegaard, Nikola Minchev, Svenja Hahn, Andreas Glück, João Cotrim De Figueiredo, Ana Vasconcelos ITRE · LIBE

(fb) In Article 23a, paragraph 1, the following point is added

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 1 – point fb (new)

Additional proposed wording Amendment 1778 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE

(3a) In Article 23a, the following paragraph is inserted:

The Commission should, by means of implementing acts, develop a common notification template for the single-entry point covering the Union Acts referred to in paragraph (1) that provide for notification through this single-entry point. It shall enable entities to submit a single notification to fulfil multiple reporting obligations, including, where technically feasible, through interoperable reporting channels designed to reduce duplication of reporting obligations. In preparing the draft implementing acts, the Commission shall cooperate with ENISA, the Cooperation Group, the CSIRTs Network and, where relevant, other competent authorities responsible for the Union legal acts concerned.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3a (new)

Additional proposed wording Amendment 1779 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE

(3a) In Article 23a, paragraph 3, the following points are added

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3 – points fa and fb

Additional proposed wording Amendment 1780 · Katri Kulmuni ITRE · LIBE

(3a) In Article 23a, the following paragraph is inserted:

Entities shall submit incident notifications within 96 hours to the national single-entry point of their Member State of main establishment.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3a (new)

Additional proposed wording Amendment 1781 · Katri Kulmuni ITRE · LIBE

(3b) In Article 23a, the following paragraph is inserted:

Member States shall ensure interoperability between national single-entry points, including secure and automated transmission of information where cross-border notifications are required.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3b (new)

Additional proposed wording Amendment 1782 · Katri Kulmuni ITRE · LIBE

(3c) In Article 23a, the following paragraph is inserted:

ENISA shall support interoperability and convergence by developing common technical standards and promoting a harmonised reporting template aligned with international standards.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 3c (new)

Alternative wording Amendment 1783 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISA shall not have access to the notifications submitted through thenational single-entry pointpoints. The substantive receipt and processing of notifications shall take place at the level of the competent national authorities.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – Paragraph 4

Alternative wording Amendment 1784 · Henrik Dahl ITRE · LIBE
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISAEntities shall notsubmit haveincident accessnotifications within 96 hours to the notificationsnational submitted through the single-entrysingleentry point of their Member State of main establishment.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 4

Alternative wording Amendment 1785 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(4) Unless provided for in the Union legal acts referred to in paragraph (1) of this, ENISAEntities shall notsubmit haveincident accessnotifications within 96 hours to the notificationsnational submittedsingle through the single-entryentry point of their Member State of main establishment.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 4

Additional proposed wording Amendment 1786 · Aura Salla, Niels Flemming Hansen, Ana Miguel Pedro, Christian Ehler ITRE · LIBE

(4a) In Article 23a, the following paragraph is inserted:

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – point 4a (new)

Additional proposed wording Amendment 1787 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE

(4a) In Article 23a, the following paragraph is inserted:

Where the same incident triggers notification obligations under more than one Union legal act, the Member states shall designate a coordinating competent authority responsible for coordinating requests for additional information and ensuring coherent communication with the reporting entity. The coordinating competent authority will be notified to ENISA and be included in the single-entry point system.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 4a (new)

Additional proposed wording Amendment 1788 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE

(4b) In Article 23a, the following paragraph is inserted:

ENISA in cooperation with the coordinating competent authorities shall create a database of cases and where relevant publish at least anonymised threat intelligence, lessons learned, mitigation advice.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 4b (new)

Alternative wording Amendment 1789 · Henrik Dahl ITRE · LIBE
(5) WithinThe [18]competent months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal actauthorities, including testingCSIRTs, thatshall takes into account the specificities and requirements forprocess the notifications setand, outwhere byrequired each respectiveunder Union legal actlaw, and after consulting the Commission and thetransmit relevant competentinformation authoritiesto under the respective Union legal actsENISA. ENISAEntities shall enablenot thebe notification of incidents under each Union legal act referredrequired to inreport paragraph (1) only after piloting the functioning and after the Commission published a notice pursuantdirectly to paragraph 6ENISA.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 5

Alternative wording Amendment 1790 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(5) WithinThe [18]competent months from the entry into force of this Regulation, ENISA shall pilot the functioning of the single-entry point for each added Union legal actauthorities, including testingCSIRTs, thatshall takes into account the specificities and requirements forprocess the notifications setand, outwhere byrequired each respectiveunder Union legal actlaw, and after consulting the Commission and thetransmit relevant competentinformation authoritiesto under the respective Union legal actsENISA. ENISAEntities shall enablenot thebe notification of incidents under each Union legal act referredrequired to inreport paragraph (1) only after piloting the functioning and after the Commission published a notice pursuantdirectly to paragraph 6ENISA.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 5

Alternative wording Amendment 1791 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(5) Within [18] months from the entry into force of this Regulation, ENISA shall pilot the functioning of the EU and national single-entry pointpoints for each added Union legal act, including testing that takes into account the specificities and requirements for the notifications set out by each respective Union legal act, and after consulting the Commission and the relevant competent authorities under the respective Union legal acts. ENISA shall enable the notification of incidents under each Union legal act referred to in paragraph (1) only after piloting the functioning and after the Commission published a notice pursuant to paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 5

Alternative wording Amendment 1792 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(6) TheMember CommissionStates shall ensure interoperability between national single-entry points, inincluding cooperation with ENISA, assess the proper functioning, reliability, integritysecure and confidentialityautomated transmission of theinformation single-entrywhere pointcrossborder notifications are required. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 6

Alternative wording Amendment 1793 · Henrik Dahl ITRE · LIBE
(6) TheMember CommissionStates shall ensure interoperability between national single-entry points, inincluding cooperation with ENISA, assess the proper functioning, reliability, integritysecure and confidentialityautomated transmission of theinformation single-entrywhere pointcrossborder notifications are required. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 6

Alternative wording Amendment 1794 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity and confidentiality of the EU and national single-entry pointpoints. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 6

Alternative wording Amendment 1795 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
(6) The Commission shall, in cooperation with ENISA, assess the proper functioning, reliability, integrity, availability and confidentiality of the single-entry point. When the Commission, after consultation of the CSIRTs network and the competent authorities under the Union legal acts referred to in paragraph 1, finds that the single-entry point ensures the proper functioning, reliability, integrity and confidentiality, it shall publish a notice to that effect in the Official Journal of the European Union.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 6

Alternative wording Amendment 1796 · Henrik Dahl ITRE · LIBE
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take,support ininteroperability cooperationand convergence by developing common technical standards and promoting a harmonised reporting template aligned with theinternational Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the resultsstandards. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 7

Alternative wording Amendment 1797 · Alice Teodorescu Måwe, Henrik Dahl ITRE · LIBE
(7) Where the Commission finds in its assessment that the single-entry point does not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take,support ininteroperability cooperationand convergence by developing common technical standards and promoting a harmonised reporting template aligned with theinternational Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the resultsstandards. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 7

Alternative wording Amendment 1798 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
(7) Where the Commission finds in its assessment that the EU and national single-entry pointpoints doesdo not ensure the proper functioning, reliability, integrity or confidentiality, ENISA shall take, in cooperation with the Commission and without undue delay, all necessary corrective measures to ensure the proper functioning, reliability, integrity or confidentiality without delay and inform the Commission of the results. Thereafter, the Commission shall reassess the proper functioning, reliability, integrity or confidentiality of the single-entry point and shall publish a notice in accordance with paragraph 6.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 7

Additional proposed wording Amendment 1799 · Damian Boeselager, Markéta Gregorová on behalf of the Verts/ALE Group ITRE · LIBE

(7a) In Article 23a, the following paragraph is added:

The Commission shall adopt implementing acts establishing a common Union incident reporting data model and interoperable technical specifications for all reporting obligations covered by this Regulation. The implementing act shall include a EU-wide incident taxonomy including common incident categories, common severity levels, common terminology.'

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23a – paragraph 7a (new)

Additional proposed wording Amendment 1802 · François-Xavier Bellamy ITRE · LIBE

This incident reporting information point shall identify the applicable reporting obligations, the direction to the appropriate national entry point, and make available simplified and documented information on incident notification processes in the different Member States.

The incident reporting information point shall not collect any information allowing the identification of the notifying entity or of any incident. Member States shall endeavour to design their national entry point with a view to making the national entry points interoperable with the national entry points of other Member States, to facilitate the alignment of incident notifications with cross-border reporting obligations.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 a (new) / Directive (EU) 2022/2555 / Article 23a – paragraph 1a (new)

Additional proposed wording Amendment 1805 · François-Xavier Bellamy ITRE · LIBE

The report shall in particular consider concrete steps and a timeline for introducing the unified approach to incident reporting under the Union legal acts.

Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 b (new) / Directive (EU) 2022/2555 / Article 23a – paragraph 1b (new)