Lex/EU laws/Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union
Regulation · CELEX 32023R2841 · Procedure completed

Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union

Regulation 32023R2841 — what it is, who it's in scope for, and the official record behind it. Built only from official sources.

CELEX32023R2841
TypeRegulation
Dated2023-12-13
Lead committeeITRE
StageProcedure completed
In short

Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union is Regulation 32023R2841. to establish measures to ensure a high common level of cybersecurity in the Union institutions, bodies and agencies. Source: EUR-Lex and the European Parliament procedure file.

Does Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union affect your company?
Run a free exposure scan — see this file and the rest of the EU corpus, ranked for you.

What it is

to establish measures to ensure a high common level of cybersecurity in the Union institutions, bodies and agencies. PROPOSED ACT: Regulation of the European Parliament and of the Council. ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council. BACKGROUND: evolving technology and increased complexity and interconnectedness of digital systems amplify cybersecurity risks making the Union administration more vulnerable to cyber threats and incidents . The Committee on Industry, Research and Energy adopted the report by Henna VIRKUNEN (EPP, FI) on the proposal for a regulation of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union. The committee responsible recommended that the European Parliament's position adopted at first reading under the ordinary legislative procedure should amend the proposal as follows: This Regulation lays down measures that aim to achieve a high common level of cybersecurity in Union entities. To that end, this Regulation lays down: - obligations that require Union entities to establish a cybersecurity risk management, handling of incidents, governance and control framework; - cybersecurity risk management and reporting obligations for Union entities; - rules underpinning information sharing obligations and the facilitation of voluntary information sharing arrangements with regard to Union entities; - rules on the organisation, tasks and operation of the Cybersecurity Centre for the Union entities (CERT-EU) and on the functioning, organisation and operation of the Interinstitutional Cybersecurity Board (IICB). Risk management, handling of incidents, governance and control framework On the basis of a full cybersecurity audit, each Union entity should establish its own cybersecurity risk management, handling of incidents, governance and control framework. The establishment of the framework should be overseen by the Union entity’s highest level of management . The risk management framework should (i) define the strategic objectives to ensure a high level of cybersecurity in the Union entities; (ii) lay down cybersecurity policies for the security of network and information systems encompassing the entirety of the ICT environment, and define the roles and responsibilities of staff of the Union entities tasked with ensuring the effective implementation of this Regulation; (iii) include the key performance indicators (KPIs). The framework should be reviewed regularly and at least every three years. Risk management measures should ensure a level of security for networks and information systems across the ICT environment that is appropriate to the risks identified in the risk management framework, taking into account the state of the art and, where appropriate, applicable European and international standards or available European cybersecurity certificates. When assessing the proportionality of those measures, due account should be taken of the degree of the Union entity’s exposure to risks, its size,…

Official title: Regulation (EU, Euratom) 2023/2841 of the European Parliament and of the Council of 13 December 2023 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union

Frequently asked

What is Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union?

to establish measures to ensure a high common level of cybersecurity in the Union institutions, bodies and agencies. PROPOSED ACT: Regulation of the European Parliament and of the Council. ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council. BACKGROUND: evolving technology and increased complexity and interconnectedness of digital systems amplify cybersecurity risks making the Union administration more vulnerable to cyber threats and incidents . The Committee on Industry, Research and En

When was 32023R2841 adopted?

Regulation 32023R2841 is dated 2023-12-13. The full official text is on EUR-Lex.

What is the EU legislative procedure reference?

The procedure reference is 2022/0085(COD). You can follow it on the European Parliament's procedure file.

Primary sources

Summary extracted from the European Parliament's own per-stage procedure record. Data © European Union (Decision 2011/833/EU). Methodology.

See your company’s exposure to Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Unionand the rest of the corpus.

Enter your company and Lex builds a cited Exposure Map in about 30 seconds. Free, no login.

Monitor this regulation

Get an email when Regulation (EU, Euratom) 2023/2841 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union advances — free, no account. We only email on real changes.