Subject matter and scope
1. This Regulation establishes the European Cybersecurity Industrial, Technology and Research Competence Centre (the ‘Competence Centre’) and the Network of National Coordination Centres (the ‘Network’). It lays down rules for the nomination of national coordination centres as well as rules for the establishment of the Cybersecurity Competence Community (the ‘Community’).
2. The Competence Centre shall have an essential role in the implementation of the cybersecurity part of the Digital Europe Programme, in particular with regard to actions related to Article 6 of Regulation (EU) 2021/694, and shall contribute to the implementation of Horizon Europe, in particular with regard to Section 3.1.3 of Pillar II of Annex I to Council Decision (EU) 2021/764 ( 12 ) .
3. Member States shall collectively contribute to the work of the Competence Centre and the Network.
4. This Regulation is without prejudice to the competences of the Member States regarding public security, defence, national security and the activities of the state in areas of criminal law.
Definitions
For the purpose of this Regulation, the following definitions apply:
(1)
‘cybersecurity’ means the activities necessary to protect network and information systems, the users of such systems, and other persons affected by cyber threats;
(2)
‘network and information system’ means a network and information system as defined in point (1) of Article 4 of Directive (EU) 2016/1148;
(3)
‘cybersecurity products, services and processes’ means commercial and non-commercial ICT products, services or processes with the specific purpose of protecting network and information systems or ensuring the confidentiality, integrity and accessibility of data that are processed or stored in network and information systems, as well as the cybersecurity of the users of such systems and other persons affected by cyber threats;
(4)
‘cyber threat’ means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons;
(5)
‘joint action’ means an action that is included in the annual work programme and that receives financial support from Horizon Europe, the Digital Europe Programme or other Union programmes as well as financial or in-kind support by one or more Member States, and which is implemented via projects involving beneficiaries that are established in and receive financial or in-kind support from those Member States;
(6)
‘in-kind contribution’ means eligible costs incurred by national coordination centres and other public entities when they participate in projects funded through this Regulation, where those costs are not financed by a Union contribution or by financial contributions from Member States;
(7)
‘European Digital Innovation Hub’ means a European Digital Innovation Hub as defined in point (e) of Article 2 of Regulation (EU) 2021/694;
(8)
‘Agenda’ means a comprehensive and sustainable cybersecurity industrial, technology and research strategy which sets out strategic recommendations for the development and growth of the European cybersecurity industrial, technological and research sector and strategic priorities for the Competence Centre’s activities and is not binding with respect to decisions to be taken on the annual work programmes;
(9)
‘technical assistance’ means assistance by the Competence Centre to the national coordination centres or the Community in the performance of theirs tasks by providing knowledge or facilitating access to expertise in the area of cybersecurity research, technology and industry, facilitating networking, raising awareness and promoting cooperation, or means assistance by the Competence Centre together with the national coordination centres to stakeholders with respect to the preparation of projects in relation to the mission of the Competence Centre and the Network and the objectives of the Competence Centre.
Mission of the Competence Centre and the Network
1. The mission of the Competence Centre and the Network is to help the Union to:
(a)
strengthen its leadership and strategic autonomy in the area of cybersecurity by retaining and developing the Union’s research, academic, societal, technological and industrial cybersecurity capacities and capabilities necessary to enhance trust and security, including the confidentiality, integrity and accessibility of data, in the Digital Single Market;
(b)
support Union technological capacities, capabilities and skills in relation to the resilience and reliability of the infrastructure of network and information systems, including critical infrastructure and commonly used hardware and software in the Union; and
(c)
increase the global competitiveness of the Union’s cybersecurity industry, ensure high cybersecurity standards throughout the Union and turn cybersecurity into a competitive advantage for other Union industries.
2. The Competence Centre and the Network shall undertake their tasks in collaboration with ENISA and the Community, as appropriate.
3. The Competence Centre shall, in accordance with the legislative acts establishing the relevant programmes, in particular Horizon Europe and the Digital Europe Programme, use relevant Union financial resources in such a way as to contribute to the mission set out in paragraph 1.
Objectives of the Competence Centre
1. The Competence Centre shall have the overall objective of promoting research, innovation and deployment in the area of cybersecurity in order to fulfil the mission as set out in Article 3.
2. The Competence Centre shall have the following specific objectives:
(a)
enhancing cybersecurity capacities, capabilities, knowledge and infrastructure for the benefit of industry, in particular SMEs, research communities, the public sector and civil society, as appropriate;
(b)
promoting cybersecurity resilience, the uptake of cybersecurity best practices, the principle of security by design, and the certification of the security of digital products and services, in a manner that complements the efforts of other public entities;
(c)
contributing to a strong European cybersecurity ecosystem which brings together all relevant stakeholders.
3. The Competence Centre shall implement the specific objectives referred to in paragraph 2 by:
(a)
establishing strategic recommendations for research, innovation and deployment in cybersecurity in accordance with Union law and setting out strategic priorities for the Competence Centre’s activities;
(b)
implementing actions under relevant Union funding programmes in accordance with the relevant work programmes and the Union legislative acts establishing those funding programmes;
(c)
fostering cooperation and coordination among the national coordination centres and with and within the Community; and
(d)
where relevant and appropriate, acquiring and operating ICT infrastructure and services where necessary to fulfil the tasks set out in Article 5 and in accordance with the respective work programmes set out in point (b) of Article 5(3).
Tasks of the Competence Centre
1. In order to fulfil its mission and objectives, the Competence Centre shall have the following tasks:
(a)
strategic tasks; and
(b)
implementation tasks.
2. The strategic tasks referred to in point (a) of paragraph 1 shall consist of:
(a)
developing and monitoring the implementation of the Agenda;
(b)
through the Agenda and the multiannual work programme, while avoiding any duplication of activities with ENISA and taking into account the need to create synergies between cybersecurity and other parts of Horizon Europe and the Digital Europe Programme:
(i)
establishing priorities for the work of the Competence Centre in relation to:
(1)
the enhancement of cybersecurity research and innovation, covering the entire innovation cycle, and the deployment of that research and innovation;
(2)
the development of cybersecurity industrial, technological and research capacities, capabilities, and infrastructure;
(3)
the reinforcement of cybersecurity and technology skills and competence in industry, technology and research and at all relevant educational levels, supporting gender balance;
(4)
the deployment of cybersecurity products, services and processes;
(5)
support for the uptake by the market of cybersecurity products, services and processes contributing to the mission set out in Article 3;
(6)
support for the adoption and integration of state-of-the-art cybersecurity products, services and processes by public authorities at their request, by demand-side industries and by other users;
(ii)
supporting the cybersecurity industry, in particular SMEs, with a view to strengthening Union excellence, capacity and competitiveness with regard to cybersecurity, including with a view to connecting to potential markets and deployment opportunities, and to attracting investment; and
(iii)
providing support and technical assistance to cybersecurity start-ups, SMEs, microenterprises, associations, individual experts and civic technology projects;
(c)
ensuring synergies between and cooperation with relevant Union institutions, bodies, offices and agencies, in particular ENISA, while avoiding any duplication of activities with those Union institutions, bodies, offices and agencies;
(d)
coordinating national coordination centres through the Network and ensuring a regular exchange of expertise;
(e)
providing expert cybersecurity industrial, technology and research advice to Member States at their request, including with regard to the procurement and deployment of technologies;
(f)
facilitating collaboration and the sharing of expertise among all relevant stakeholders, in particular members of the Community;
(g)
attending Union, national and international conferences, fairs and forums related to the mission, objectives and tasks of the Competence Centre with the aim of sharing views and exchanging relevant best practices with other participants;
(h)
facilitating the use of results from research and innovation projects in actions related to the development of cybersecurity products, services and processes, while seeking to avoid the fragmentation and duplication of efforts and replicating good cybersecurity practices and cybersecurity products, services and processes, in particular those developed by SMEs and those using open source software.
3. The implementation tasks referred to in point (b) of paragraph 1 shall consist of:
(a)
coordinating and administrating the work of the Network and the Community in order to fulfil the mission set out in Article 3, in particular by supporting cybersecurity start-ups, SMEs, microenterprises, associations and civic technology projects in the Union and facilitating their access to expertise, funding, investment and markets;
(b)
establishing and implementing the annual work programme, in accordance with the Agenda and the multiannual work programme, for the cybersecurity parts of:
(i)
the Digital Europe Programme, in particular actions related to Article 6 of Regulation (EU) 2021/694;
(ii)
joint actions receiving support under the provisions that relate to cybersecurity in Horizon Europe, in particular with regard to Section 3.1.3 of Pillar II of Annex I to Decision (EU) 2021/764, in accordance with the multiannual work programme and the strategic planning process of Horizon Europe; and
(iii)
other programmes where provided for in the relevant legislative acts of the Union;
(c)
supporting, where appropriate, the achievement of Specific Objective 4 – ‘Advanced Digital Skills’ as set out in Article 7 of Regulation (EU) 2021/694, in cooperation with European Digital Innovation Hubs;
(d)
providing expert advice on cybersecurity industry, technology and research to the Commission when the Commission prepares draft work programmes pursuant to Article 13 of Decision (EU) 2021/764;
(e)
carrying out or enabling the deployment of ICT infrastructure and facilitating the acquisition of such infrastructure, for the benefit of society, industry and the public sector, at the request of Member States, research communities and operators of essential services, by means of, inter alia, contributions from Member States and Union funding for joint actions, in accordance with the Agenda, the annual work programme and the multiannual work programme;
(f)
raising awareness of the mission of the Competence Centre and the Network and of the objectives and tasks of the Competence Centre;
(g)
without prejudice to the civilian nature of projects to be financed from Horizon Europe, and in accordance with Regulations (EU) 2021/695 and (EU) 2021/694, enhancing synergies and coordination between the cybersecurity civilian and defence spheres, by facilitating the exchange of:
(i)
knowledge and information with regard to dual-use technologies and applications;
(ii)
results, requirements and best practices; and
(iii)
information with regard to the priorities of relevant Union programmes.
4. The Competence Centre shall carry out the tasks set out in paragraph 1 in close cooperation with the Network.
5. In accordance with Article 6 of Regulation (EU) 2021/695 and subject to a contribution agreement as defined in point (18) of Article 2 of the Financial Regulation, the Competence Centre may be entrusted with the implementation of the cybersecurity parts under Horizon Europe that are not co-funded by the Member States, in particular with regard to Section 3.1.3 of Pillar II of Annex I to Decision (EU) 2021/764.
Nomination of national coordination centres
1. By 29 December 2021, each Member State shall nominate one entity which fulfils the criteria laid down in paragraph 5 to act as its national coordination centre for the purposes of this Regulation. Each Member State shall notify that entity to the Governing Board without delay. Such entity may be an entity already established in that Member State.
The deadline set out in the first subparagraph of this paragraph shall be extended for the period during which the Commission is to issue the opinion referred to in paragraph 2.
2. At any time, a Member State may ask the Commission for an opinion concerning whether the entity that the Member State has nominated or intends to nominate to act as its national coordination centre has the necessary capacity to manage funds to fulfil the mission and objectives laid down in this Regulation. The Commission shall issue its opinion to that Member State within three months of the Member State’s request.
3. On the basis of the notification by a Member State of an entity as referred to in paragraph 1, the Governing Board shall list that entity as a national coordination centre no later than three months after the notification. The Competence Centre shall publish the list of nominated national coordination centres.
4. A Member State may at any time nominate a new entity to act as its national coordination centre for the purposes of this Regulation. Paragraphs 1, 2 and 3 shall apply to the nomination of any new entity.
5. The national coordination centre shall be a public sector entity or an entity, a majority of which is owned by the Member State, which performs public administrative functions under national law, including by means of delegation, and having the capacity to support the Competence Centre and the Network in fulfilling their mission as set out in Article 3 of this Regulation. It shall either possess or have access to research and technological expertise in cybersecurity. It shall have the capacity to engage effectively and coordinate with industry, the public sector, the academic and research community and citizens, as well as with authorities designated pursuant to Directive (EU) 2016/1148.
6. At any time, a national coordination centre may request to be recognised as having the necessary capacity to manage funds to fulfil the mission and objectives laid down in this Regulation, in accordance with Regulations (EU) 2021/695 and (EU) 2021/694. Within three months of such a request, the Commission shall assess whether that national coordination centre has such capacity and shall issue a decision.
Where the Commission has provided a positive opinion to a Member State in accordance with the procedure laid down in paragraph 2, that opinion shall be deemed to be a decision recognising the relevant entity as having the necessary capacity for the purposes of this paragraph.
No later than 29 August 2021, after consulting the Governing Board, the Commission shall issue guidelines on the assessment referred to in the first subparagraph, including a specification of the conditions for recognition and how opinions and assessments are conducted.
Before issuing the opinion referred to in paragraph 2 and the decision referred to in the first subparagraph of this paragraph, the Commission shall take into account any information and documentation provided by the requesting national coordination centre.
Any decision not to recognise a national coordination centre as having the necessary capacity to manage funds to fulfil the mission and objectives laid down in this Regulation shall be duly reasoned, setting out the requirements the requesting national coordination centre has not yet fulfilled that justify the decision to withhold recognition. Any national coordination centre whose request for recognition has been rejected may resubmit its request with additional information at any time.
Member States shall inform the Commission in the event of changes to the national coordination centre, such as the composition of the national coordination centre, the legal form of the national coordination centre or other relevant aspects, that affect its capacity to manage funds to fulfil the mission and objectives laid down in this Regulation. On receiving such information the Commission may review a decision to grant or withhold recognition of the national coordination centre as having the necessary capacity to manage funds accordingly.
7. The Network shall be composed of all the national coordination centres that have been notified to the Governing Board by the Member States.
Tasks of the national coordination centres
1. The national coordination centres shall have the following tasks:
(a)
acting as points of contact at national level for the Community to support the Competence Centre in fulfilling its mission and objectives, in particular in coordinating the Community through the coordination of Community members in their Member States;
(b)
providing expertise and actively contributing to the strategic tasks set out in Article 5(2), taking into account relevant national and regional challenges for cybersecurity in different sectors;
(c)
promoting, encouraging and facilitating the participation of civil society, industry, in particular start-ups and SMEs, the academic and research communities and other stakeholders at national level in cross-border projects and in cybersecurity actions funded by relevant Union programmes;
(d)
providing technical assistance to stakeholders by supporting them in the application phase for projects managed by the Competence Centre in relation to its mission and objectives, and in full compliance with the rules of sound financial management, especially with regard to conflicts of interest;
(e)
seeking to establish synergies with relevant activities at national, regional and local level, such as national policies on research, development and innovation in the area of cybersecurity, in particular those policies stated in the national cybersecurity strategies;
(f)
implementing specific actions for which grants have been awarded by the Competence Centre, including through the provision of financial support to third parties in accordance with Article 204 of the Financial Regulation under conditions specified in the grant agreements concerned;
(g)
without prejudice to the competences of Member States for education and taking into account the relevant tasks of ENISA, engaging with national authorities regarding possible contributions to promoting and disseminating cybersecurity educational programmes;
(h)
promoting and disseminating the relevant outcomes of the work of the Network, the Community and the Competence Centre at national, regional or local level;
(i)
assessing requests by entities established in the same Member State as the national coordination centre to become part of the Community;
(j)
advocating and promoting the involvement of relevant entities in the activities arising from the Competence Centre, the Network and the Community, and monitoring, as appropriate, the level of engagement with and the amount of public financial support awarded for cybersecurity research, developments and deployments.
2. For the purposes of point (f) of paragraph 1 of this Article, the financial support to third parties may be provided in any of the forms of Union contribution specified in Article 125 of the Financial Regulation, including in the form of lump sums.
3. On the basis of a decision as referred to in Article 6(6) of this Regulation, national coordination centres may receive a grant from the Union in accordance with point (d) of the first paragraph of Article 195 of the Financial Regulation in relation to carrying out the tasks laid down in this Article.
4. National coordination centres shall, where relevant, cooperate through the Network.
The Cybersecurity Competence Community
1. The Community shall contribute to the mission of the Competence Centre and the Network set out in Article 3 and shall enhance, share and disseminate cybersecurity expertise across the Union.
2. The Community shall consist of industry, including SMEs, academic and research organisations, other relevant civil society associations as well as, as appropriate, relevant European Standardisation Organisations, public entities and other entities dealing with cybersecurity operational and technical matters and, where relevant, stakeholders in sectors that have an interest in cybersecurity and that face cybersecurity challenges. The Community shall bring together the main stakeholders with regard to cybersecurity technological, industrial, academic and research capacities in the Union. It shall involve national coordination centres, European Digital Innovation Hubs, where relevant, as well as Union institutions, bodies, offices and agencies with relevant expertise, such as ENISA.
3. Only entities which are established within the Member States shall be registered as members of the Community. They shall demonstrate that they are able to contribute to the mission and shall have cybersecurity expertise with regard to at least one of the following domains:
(a)
academia, research or innovation;
(b)
industrial or product development;
(c)
training and education;
(d)
information security or incident response operations;
(e)
ethics;
(f)
formal and technical standardisation and specifications.
4. The Competence Centre shall register entities, at their request, as members of the Community after an assessment made by the national coordination centre of the Member State in which those entities are established to confirm that those entities meet the criteria set out in paragraph 3 of this Article. That assessment shall also take into account any relevant national assessment on security grounds made by the national competent authorities. Such registrations shall not be limited in time but may be revoked by the Competence Centre at any time if the relevant national coordination centre considers that the entity concerned no longer fulfils the criteria set out in paragraph 3 of this Article or falls under Article 136 of the Financial Regulation, or on justified security grounds. Where membership in the Community is revoked on security grounds, the decision to revoke shall be proportional and reasoned. The national coordination centres shall aim to achieve a balanced representation of stakeholders in the Community and actively stimulate participation, in particular of SMEs.
5. National coordination centres shall be encouraged to cooperate through the Network in order to harmonise the way in which they apply the criteria set out in paragraph 3 and the procedures for assessing and registering entities referred to in paragraph 4.
6. The Competence Centre shall register relevant Union institutions, bodies, offices and agencies as members of the Community after carrying out an assessment to confirm that that Union institution, body, office or agency meets the criteria set out in paragraph 3 of this Article. Such registrations shall not be limited in time but may be revoked by the Competence Centre at any time if it considers that the Union institution, body, office or agency no longer fulfils the criteria set out in paragraph 3 of this Article or falls under Article 136 of the Financial Regulation.
7. Representatives of the Union institutions, bodies, offices and agencies may participate in the work of the Community.
8. An entity registered as a member of the Community shall designate its representatives to ensure an efficient dialogue. Those representatives shall have expertise with regard to cybersecurity research, technology or industry. The requirements may be further specified by the Governing Board, without unduly limiting the entities in the designation of their representatives.
9. The Community, through its working groups and in particular through the Strategic Advisory Group, shall provide the Executive Director and the Governing Board with strategic advice on the Agenda, the annual work programme and the multiannual work programme, in accordance with the rules of procedure of the Governing Board.
Tasks of the members of the Community
The members of the Community shall:
(a)
support the Competence Centre in fulfilling its mission and objectives and, for that purpose, shall work closely with the Competence Centre and the national coordination centres;
(b)
where relevant, participate in formal or informal activities and in the working groups referred to in point (n) of Article 13(3) to carry out specific activities as provided by the annual work programme; and
(c)
where relevant, support the Competence Centre and the national coordination centres in promoting specific projects.
Cooperation of the Competence Centre with other Union institutions, bodies, offices and agencies and international organisations
1. To ensure consistency and complementarity while avoiding any duplication of effort, the Competence Centre shall cooperate with relevant Union institutions, bodies, offices and agencies, including ENISA, the European External Action Service, the Directorate-General Joint Research Centre of the Commission, the European Research Executive Agency, the European Research Council Executive Agency and the European Health and Digital Executive Agency established by Commission Implementing Decision (EU) 2021/173 ( 13 ) , relevant European Digital Innovation Hubs, the European Cybercrime Centre at the European Union Agency for Law Enforcement Cooperation established by Regulation (EU) 2016/794 of the European Parliament and of the Council ( 14 ) , the European Defence Agency in relation to the tasks set out in Article 5 of this Regulation and other relevant Union entities. The Competence Centre may also cooperate with international organisations, where relevant.
2. Cooperation as referred to in paragraph 1 of this Article may take place within the framework of working arrangements. Those arrangements shall be submitted for the approval of the Governing Board. Any sharing of classified information shall take place within the framework of administrative arrangements concluded in accordance with Article 36(3).
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.