While the Huawei case continues to divide Europeans, MEPs have created a new milestone in the fight against cyber attacks. On Tuesday 19 February, the Parliamentary Committee on Industry adopted its negotiating position regarding the draft regulation establishing a European Competence Centre and a Network of National Coordination Centres.
By way of reminder, in September 2018, the European Commission presented a legislative proposal intended to facilitate the pooling and sharing of cybersecurity research capacities and cybersecurity results and the deployment of innovative cybersecurity solutions (see EUROPE 12095).
The draft regulation is based on three levels of governance: (a) at EU level, the establishment of a European Cybersecurity Industrial, Technology and Research Competence Centre; (b) at Member State level, the establishment of one of the national coordination centres; (c) at the level of key players, a community of expertise relating to cybersecurity.
Principal changes
Parliament's negotiating position – adopted by 49 votes to 2, with 6 abstentions – retains these three main components of the original proposal.
Impacted by the relocation of EU agencies after Brexit, MEPs are opposed to the automatic establishment of the European Centre of Competence in Brussels and are calling for a “responsible democratic” procedure for designating the seat. While this does not affect the principle that decisions of the Governing Board (the main decision-making body of the Centre and the Network) shall be taken in proportion to the financial contributions made by Member States, it does, nevertheless, introduce an observer appointed by the European Parliament onto the Governing Board.
The other change pertains to the Cybersecurity Skills Community, which is responsible for improving and disseminating cybersecurity expertise throughout the Union. While the European Commission has suggested limiting membership of this community to entities established in the EU, MEPs are proposing to cover entities and residents of the EU, the European Economic Area, and the European Free Trade Association.
The Council has yet to define its negotiating position, thus allowing interinstitutional negotiations to start.
Reactions
Tasked with drafting the parliamentary report, MEP Julia Reda (Greens/EFA, Germany) stressed “the importance of ensuring the security of commonly used technologies where they play an infrastructure role, specifically free and open source software”. She also reiterated opposition to the use of the EU budget, in particular the part allocated to the future Digital Europe programme, potentially for defence financing, even the amendment to this effect was not adopted.
On the stakeholder side, the Business Software Alliance (which includes Microsoft, Apple and IBM among its members) responded by calling for expertise to be taken into account, rather than simply origin. “The success of the Centre should depend on the participation of those entities with the best expertise, regardless of their size or origin. All Member States, whether they are European or not, should work together to pursue safety innovations”, said Thomas Boué, Director General at BSA.
The compromise amendments can be viewed here: https://bit.ly/2BHNYVw. (Original version in French by Sophie Petitjean)