Skip to main content
PolicySpeak
← All legislative files
Regulation (EU) 2023/28412022/0085(COD)COM(2022)122ITRE

High common level of cybersecurity at the institutions, bodies, offices and agencies of the Union

Laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union

Stage
In force, reached 18 Dec 2023
In force
In force since 7 Jan 2024 · CELEX 32023R2841
Procedure
Ordinary legislative procedure
Rapporteur
Henna Virkkunen (EPP)
Lead DG
DG DIGIT
Last activity
18 Dec 2023
31 entries · record as of 14 Sept 2026

Where it stands

Latest: Published in the Official Journal, 18 Dec 2023.

Show the earlier record: 19 dates, 7 Jan 2021 to 21 Mar 2023
  1. 7 Jan 2021
    • Inception impact assessment closed: Regulation on Common Cybersecurity Rules for EU institutions, bodies and agencies, 1 responses · Commission
  2. 22 Mar 2022
    • Adoption by Commission
  3. 23 Mar 2022
    • Discussions within the Council or its preparatory bodies
  4. 4 Apr 2022
    • Plenary sitting
    • Referred to committee
  5. 18 May 2022
    • Feedback on adopted proposal closed: Regulation on Common Cybersecurity Rules for EU institutions, bodies and agencies, 12 responses · Commission
  6. 31 May 2022
    • Committee opinion tabled
  7. 12 Jul 2022
    • Committee opinion adopted
  8. 15 Sept 2022
    • Plenary sitting
  9. 4 Oct 2022
    • Committee opinion tabled
  10. 7 Oct 2022
    • Committee report tabled
  11. 31 Oct 2022
    • Discussions within the Council or its preparatory bodies
  12. 15 Dec 2022
    • Committee opinion tabled
  13. 25 Jan 2023
    • Committee opinion adopted
  14. 1 Mar 2023
    • Committee opinion adopted
  15. 9 Mar 2023
    • Committee report adopted
  16. 10 Mar 2023
    • Tabled for plenary
  17. 13 Mar 2023
    • Plenary sitting
  18. 15 Mar 2023
    • Plenary endorsed the trilogue mandate
  19. 21 Mar 2023
    • Discussions within the Council or its preparatory bodies
  1. 19 Sept 2023
    • Committee approved the provisional agreement
    • Discussions within the Council or its preparatory bodies
  2. 21 Nov 2023
    • Plenary adopted first-reading position
    • Plenary vote
  3. 23 Nov 2023
    • Discussions within the Council or its preparatory bodies
  4. 29 Nov 2023
    • Discussions within the Council or its preparatory bodies
  5. 1 Dec 2023
    • Discussions within the Council or its preparatory bodies
  6. 11 Dec 2023
    • Plenary sitting
  7. 13 Dec 2023
    • Approval of the EP's first reading position by the Council (adoption of the legislative act)
    • Signed
  8. 18 Dec 2023
    • Published in the Official Journal
10 people

Who is on it

The Parliament's rapporteurs, shadow rapporteurs and opinion rapporteurs currently on this file.

RoleNameGroupCountryCommittee
RapporteurHenna VirkkunenEPPFIITRE
Shadow rapporteurEvžen TošenovskýECRCZITRE
Shadow rapporteurIzaskun Bilbao BarandicaRenewESITRE
Shadow rapporteurMarc BotengaThe LeftBEITRE
Shadow rapporteurMarkus BuchheitPfEDEITRE
Shadow rapporteurMiapetra Kumpula-natriS&DFIITRE
Shadow rapporteurMikuláš PeksaGreens/EFACZITRE
Rapporteur for opinionMarkéta GregorováGreens/EFACZAFCO
Rapporteur for opinionNils UšakovsS&DLVBUDG
Rapporteur for opinionTomas TobéEPPSELIBE
1 consultation

Consultations on it

The Commission's Have Your Say consultations linked to this file. Each title opens on the Commission's portal.

ConsultationFeedback deadlineFeedback received
18 May 202213

Summary

Generated

This regulation imposes a mandatory cybersecurity framework on all EU institutions, bodies, and agencies, requiring risk management, incident reporting, and governance measures. It directly affects internal cybersecurity operations and IT suppliers of these entities. Signed in December 2023, the regulation is now in force.

What the workspace adds on this file

Everything above is the public record. Subscribers see this page with their own layer on top.

Why it matters to you

What this file means for your organization, assessed against your own priorities.

What moved

When this file moves, it reaches your own briefing, with a link to its source.

Your contacts on it

Your team's contacts logged against this file: who you met, what was said and the next step.

A first draft

A statement, a member update or a meeting brief on this file, in your organization's voice, with its sources.

Sources: EP Legislative Observatory · EUR-Lex. Record as of 14 Sept 2026. Something wrong on this page? Report an error.

Request access

See this file with your own layer on top: why it matters to you, your contacts on it and a first draft. We’ll schedule a 20-minute walkthrough.

EU-hosted · GDPR-compliant · Trust Center →

By submitting, you agree to our privacy policy.