Digital Omnibus proposal
Recital 49a
Compare the available Commission, Council and Parliament texts and amendments affecting this recital.
Recital total: 1 part · 4 Council drafts · 4 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
The wording proposed by the Commission at the start of this legislative file.
No standalone Commission wording is mapped to these tracked parts. A newly proposed provision may have no earlier text of its own.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Recital 49a
May Presidency compromise
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain a single information point for incident reporting. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
June Presidency compromise · 10 June
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
June Presidency compromise · 18 June
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
September Presidency compromise
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a 4 Council drafts
Recital 49a
21 May 2026 · May Presidency compromise
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain a single information point for incident reporting. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
10 June 2026 · June Presidency compromise · 10 June
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
18 June 2026 · June Presidency compromise · 18 June
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Recital 49a
3 September 2026 · September Presidency compromise
In order to facilitate compliance with the obligation to report incidents and related events, including the identification of the applicable related obligations, ENISA should develop and maintain an incident reporting information point for incident reporting. That information point should serve as a clearly arranged source of information to support entities in identifying their reporting obligations and to guide them to the appropriate national entry point. Further information on related obligations, especially in terms of cybersecurity risk management, may be added. Structured communication channels should be established to ensure that the information available on the single information point is swiftly updated based on all the relevant and necessary information communicated by Member States.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Political group at the amendment date where available; otherwise the current Parliament affiliation.
Additional proposed wording Amendment 11 ITRE–LIBE draft report · Aura Salla and Marina Kaljurand (rapporteurs)
To ensure that Directive (EU) 2022/2555 is applied consistently and proportionately across the Union and in line with the principle of administrative simplification and the 'report-once' policy, duplicative or unclear reporting obligations or diverging national interpretations and additional obligations should be avoided. The Commission should, in cooperation with the Cooperation Group referred to in Article 14 of Directive (EU) 2022/2555 and the European Union Agency for Cybersecurity (ENISA), issue guidance on the harmonised interpretation and application of key obligations under that Directive.
Additional proposed wording Amendment 495 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, António Tânger Corrêa, Christophe Bay ITRE · LIBE
The layered single-entry points structure should not result in the centralisation, within a single body, of the storage and processing of incident notifications. In accordance with the principles of subsidiarity and proportionality, and in order to avoid creating a single point of failure that could itself become a target for cybersecurity threats, the single-entry point should be designed as a layered architecture. ENISA should provide a common interface enabling entities to submit a single notification, while the competent authorities designated under the relevant Union legal acts should remain responsible, at national level, for receiving, accessing and processing the information relating to incidents within their respective fields of competence. The EU entry point should accordingly act as a means of routing and interoperability between entities and the competent national authorities, building on the technical solutions and reporting systems already in place at national level, rather than as a centralised repository. The role of ENISA should be limited to the technical operation, routing and format check of the notifications, ENISA not being a recipient of the notifications for substantive purposes. Where ENISA receives information directly that may be relevant for the performance of the tasks of the competent national authorities, it should transmit such information without undue delay to the authorities concerned.
Justification
A single database of incident notifications would by its very nature be a target of the first order. The layered architecture preserves the proximity and expertise of national authorities while delivering, for reporting entities, the benefit of a single interface.
Additional proposed wording Amendment 496 · Elena Sancho Murillo, Marina Kaljurand, Brando Benifei, José Cepeda, Matthias Ecke, Lina Gálvez, Francisco Assis, Alex Agius Saliba ITRE · LIBE
To ensure that Directive (EU) 2022/2555 is applied consistently and proportionately across the Union and in line with the principle of administrative simplification and the 'report-once' policy, duplicative or unclear reporting obligations or diverging national interpretations and additional obligations should be avoided. The Commission should, in cooperation with the Cooperation Group referred to in Article 14 of Directive (EU) 2022/2555 and the European Union Agency for Cybersecurity (ENISA), issue guidance on the harmonised interpretation and application of key obligations under that Directive. These guidelines shall be developed under the relevant sectorial legislation.
Justification
The development of detailed guidance on sector-specific cybersecurity obligations should be addressed in the context of the revision of the Cybersecurity Act, which provides the appropriate framework for considering horizontal cybersecurity governance, certification and related guidance mechanisms. This approach ensures coherence between Directive (EU) 2022/2555 and the evolving Union cybersecurity framework, while allowing sector-specific legislation to define requirements reflecting the specific risks and operational characteristics of each sector. It also avoids duplication, divergent interpretations and additional administrative burdens for entities subject to multiple cybersecurity obligations.
Additional proposed wording Amendment 497 · Michael McNamara, Irena Joveva, Sophie Wilmès, Oihane Agirregoitia Martínez, Bart Groothuis, Veronika Cifrová Ostrihoňová ITRE · LIBE
ENISA's role in the reporting process is limited to establishing and operating the single-entry point portal and routing reports to the competent CSIRT(s) without having access to the content of incident reports. Responsibility for the management and follow-up of incident reports remains with the national CSIRTs or competent authorities to which ENISA directs them.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Recital 49a
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Recital 49a
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Recital 49a
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded