My bookmarksSign up free

Commission Decision (EU, Euratom) 2021/259 of 10 February… CHAPTER 3 — HANDLING OF CLASSIFIED GRANTS

Article 5–Article 7 · 3 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Basic principles

Article 5

1.   When awarding a classified grant, the granting authority, together with the Commission security authority, shall ensure that the beneficiaries’ obligations regarding the protection of EUCI used or generated in the performance of the grant agreement are an integral part of the grant agreement. Grant-specific security requirements shall take the form of a security aspects letter (‘SAL’). A sample template for a SAL is set out in Annex III. 2.   Before signing a classified grant, the granting authority shall approve a security classification guide (‘SCG’) for the tasks to be performed and information generated in the implementation of the grant, or at programme or project level, where applicable. The SCG shall be part of the SAL. 3.   Programme- or project-specific security requirements shall take the form of a programme (or project) security instruction (‘PSI’). The PSI may be drafted using the provisions of the SAL template as set out in Annex III. The PSI shall be developed by the Commission department managing the programme or project, in close cooperation with the Commission security authority, and submitted for advice to the Commission Security Expert Group. Where a grant agreement is part of a programme or project with its own PSI, the SAL of the grant agreement shall have a simplified form and shall include reference to the security provisions set out in the PSI of the programme or project. 4.   Except for cases mentioned in Article 3(9), the classified grant agreement shall not be signed until the applicant’s NSA or DSA has confirmed the applicant’s FSC, or, where the classified grant agreement is awarded to a consortium, until the NSA or DSA of at least one applicant, within the consortium, or more if necessary, has confirmed that applicant’s FSC. 5.   In principle, and save provided otherwise in other relevant rules, the granting authority shall be considered the originator of EUCI generated in the performance of the grant agreement. 6.   The granting authority, through the Commission security authority, shall notify the NSAs and/or DSAs of all beneficiaries and subcontractors about the signature of classified grant agreements or subcontracts and any extensions or early terminations of such grant agreements or subcontracts. A list of country requirements is provided in Annex IV. 7.   Grant agreements involving information classified RESTREINT UE/EU RESTRICTED shall include a security clause making the provisions set out in Annex III, Appendix E binding upon beneficiaries. Those grant agreements shall include an SAL setting out, as a minimum, the requirements for handling RESTREINT UE/EU RESTRICTED information including information assurance aspects and specific requirements to be fulfilled by the beneficiaries regarding the accreditation of their CIS handling RESTREINT UE/EU RESTRICTED information. 8.   Where this is required by Member States’ national laws and regulations, NSAs or DSAs ensure that beneficiaries or subcontractors under their jurisdiction comply with the applicable security provisions for the protection of RESTREINT UE/EU RESTRICTED information and conduct verification visits to beneficiaries’ or subcontractors’ facilities located in their territory. Where the NSA or DSA is not under such an obligation, the granting authority shall ensure that the beneficiaries implement the required security provisions set out in Annex III, Appendix E.

Access to EUCI by staff of beneficiaries and subcontractors

Article 6

1.   The granting authority shall ensure that classified grant agreements include provisions stating that staff of beneficiaries or subcontractors who, for the performance of the classified grant agreement or subcontract, require access to EUCI, may be granted that access only if: (a) it has been established that they have a need-to-know; (b) for information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, they have been security cleared at the relevant level by the respective NSA or DSA or any other competent security authority; (c) they have been briefed on the applicable security rules for protecting EUCI, and have acknowledged their responsibilities with regard to protecting such information. 2.   Where applicable, access to EUCI shall also be in compliance with the basic act establishing the programme and take account of any additional markings defined in the SCG. 3.   If a beneficiary or subcontractor wishes to employ a national of a non-EU country in a position that requires access to EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, it is the responsibility of the beneficiary or subcontractor to initiate the security clearance procedure of such a person in accordance with national laws and regulations applicable at the location where access to the EUCI is to be granted.

Access to EUCI by experts participating in checks, reviews or audits

Article 7

1.   Where external persons (‘experts’) are involved in checks, reviews or audits conducted by the granting authority or in performance reviews of the beneficiaries that require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET, they shall be provided with a contract only if they have been security cleared at the relevant level by the respective NSA or DSA or any other competent security authority. The granting authority, through the Commission security authority, shall check and, where necessary, ask the NSA or DSA to initiate the vetting process for experts at least six months prior to the start of their respective contracts. 2.   Before signing their contracts, the experts shall be briefed on the applicable security rules for protecting EUCI, and shall have acknowledged their responsibilities with regard to protecting such information.

Back to Commission Decision (EU, Euratom) 2021/259 of 10 February… — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next