eIDAS Regulation · Regulation (EU) No 910/2014
Article 45a
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 1 part · 4 Council drafts · 4 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to eIDAS RegulationThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 18 October 2024, with the Commission proposal change affecting this article applied.
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.
- 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 45a(3a)
Commission proposal
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (18 October 2024) compared with May Presidency compromise (21 May 2026)
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
- 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Article 45a(3a)
May Presidency compromise
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (18 October 2024) compared with June Presidency compromise · 10 June (10 June 2026)
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
- 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Article 45a(3a)
June Presidency compromise · 10 June
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (18 October 2024) compared with June Presidency compromise · 18 June (18 June 2026)
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
- 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Article 45a(3a)
June Presidency compromise · 18 June
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article in September Presidency compromise Council text
Comparison basis: Existing law (18 October 2024) compared with September Presidency compromise (3 September 2026)
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be supported through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
- 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Article 45a(3a)
September Presidency compromise
Council wording reconstructed for this provision from the official operation
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be supported through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Official source passage and amending instruction
3. in Article 45a the following paragraph 3a is inserted: ‘3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be supported through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article 45a(3a) 4 Council drafts
Article 45a(3a)
21 May 2026 · May Presidency compromise
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article 45a(3a)
10 June 2026 · June Presidency compromise · 10 June
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article 45a(3a)
18 June 2026 · June Presidency compromise · 18 June
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Article 45a(3a)
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be supported through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Official source passage and amending instruction
3. in Article 45a the following paragraph 3a is inserted: ‘3a. Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be supported through the national entry point pursuant to Article 23b of Directive (EU) 2022/2555.
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Alternative wording Amendment 287 · Daniel Buda JURI
against:
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph
32, point (fb), of this Article to theCommissionsupervisory body and, where applicable, totheother relevant competentsupervisory bodybodies, shall be made through thesingle-entryreportingpointchannelpursuantdesignatedtoby the relevant competent authority or, where the competent Member State has so decided, through the interoperable European framework provided for in Article 23a of Directive (EU) 2022/2555. - 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Alternative wording Amendment 520 · Virginie Joron IMCO
against:
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
‘3a Notifications pursuant to
inparagraph 3 to the Commission and to the competent supervisory body,shall be made through the national single-points of entrypointpursuant to Article 23a of Directive (EU) 2022/2555.’ - 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
Remove proposed wording Amendment 1811 · Markus Buchheit ITRE · LIBE
The source names this article, but its precise target scope has not been resolved. Related tracker provisions are not asserted as direct targets.
Article 7
Alternative wording Amendment 1814 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 45a
Cybersecurity precautionary measures
- 1.
Providers of web-browsers shall not take any measures contrary to their obligations set out in Article 45, in particular the requirements to recognise qualified certificates for website authentication and to display the identity data provided in a user-friendly manner.
- 2.
By way of derogation from paragraph 1 and only in the event of substantiated concerns related to security breaches or the loss of integrity of an identified certificate or set of certificates, providers of web-browsers may take precautionary measures in relation to that certificate or set of certificates.
- 3.
Where a provider of a web-browser takes precautionary measures pursuant to paragraph 2, the provider of the web-browser shall notify its concerns in writing, without undue delay, together with a description of the measures taken to mitigate those concerns, to the Commission, the competent supervisory body, the entity to whom the certificate was issued and to the qualified trust service provider that issued that certificate or set of certificates. Upon receipt of such a notification, the competent supervisory body shall issue an acknowledgement of receipt to the provider of the web-browser in question.
- 3a.
Notifications pursuant to in paragraph 3 to the Commission and to the competent supervisory body, shall be made
throughby the national single-entry points to the EU the single-entry point pursuant to Article 23a of Directive (EU) 2022/2555. - 4.
The competent supervisory body shall investigate the issues raised in the notification in accordance with Article 46b(4), point (k). Where the outcome of that investigation does not result in the withdrawal of the qualified status of the certificate, the supervisory body shall inform the provider of the web-browser accordingly and shall request that provider to put an end to the precautionary measures referred to in paragraph 2 of this Article.
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 45a(3a)
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 45a(3a)
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 45a(3a)
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 45a(3a)
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 45a(3a)
Wording reproduced in the amendment → Amendment 1814 · ITRE–LIBE amendments 1741–1840 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1814 · ITRE–LIBE amendments 1741–1840 to the draft report
Article 45a(3a)
Wording reproduced in the amendment → Amendment 520 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 520 · IMCO amendments 329–532 to the draft opinion
Article 45a(3a)
Wording reproduced in the amendment → Amendment 287 · JURI amendments 69–296 to the draft opinion
Changes in context
RemovedAdded