Annexes to COM(2022)119 - Information security in the institutions, bodies, offices and agencies of the Union

Please note

This page contains a limited version of this dossier in the EU Monitor.

Annex to the Legislative Financial Statement (Annex V to the internal rules), which is uploaded to DECIDE for interservice consultation purposes.

EUR million (to three decimal places)

Year
2023
Year
2024
Year
2025
Year
2026
Year
2027
TOTAL
DG: HR
• Human resources
0.3140.3140.3140.3140.3141.570
• Other administrative expenditure
TOTAL DG <…….>Appropriations0.3140.3140.3140.3140.3141.570

TOTAL appropriations
under HEADING 7
of the multiannual financial framework 
(Total commitments = Total payments)0.3140.3140.3140.3140.3141.570

EUR (to three decimal places)

Year
2023
Year
2024
Year
2025
Year
2026
Year
2027
TOTAL
TOTAL appropriations
under HEADINGS 1 to 7
of the multiannual financial framework 
Commitments0.3140.3140.3140.3140.3141.570
Payments0.3140.3140.3140.3140.3141.570


3.2.2.Estimated output funded with operational appropriations 

Commitment appropriations in EUR million (to three decimal places)

Indicate objectives and outputs



Year
N
Year
N+1
Year
N+2
Year
N+3
Enter as many years as necessary to show the duration of the impact (see point 1.6)TOTAL
OUTPUTS
Type 40

Average costNoCostNoCostNoCostNoCostNoCostNoCostNoCostTotal NoTotal cost
SPECIFIC OBJECTIVE No 1 41
- Output
- Output
- Output
Subtotal for specific objective No 1
SPECIFIC OBJECTIVE No 2 ...
- Output
Subtotal for specific objective No 2
TOTALS

3.2.3.Summary of estimated impact on administrative appropriations 

–◻    The proposal/initiative does not require the use of appropriations of an administrative nature

–The proposal/initiative requires the use of appropriations of an administrative nature, as explained below:

EUR million (to three decimal places)

Year
2023
Year
2024
Year
2025
Year
2026
Year
2027
TOTAL

HEADING 7
of the multiannual financial framework
Human resources0.3140.3140.3140.3140.3141.570
Other administrative expenditure
Subtotal HEADING 7
of the multiannual financial framework
0.3140.3140.3140.3140.3141.570

Outside HEADING 7 42  
of the multiannual financial framework

Human resources
Other expenditure
of an administrative nature
Subtotal
outside HEADING 7
of the multiannual financial framework

TOTAL0.3140.3140.3140.3140.3141.570

The appropriations required for human resources and other expenditure of an administrative nature will be met by appropriations from the DG that are already assigned to management of the action and/or have been redeployed within the DG, together if necessary with any additional allocation which may be granted to the managing DG under the annual allocation procedure and in the light of budgetary constraints.

3.2.3.1.Estimated requirements of human resources

–◻    The proposal/initiative does not require the use of human resources.

–The proposal/initiative requires the use of human resources, as explained below:

Estimate to be expressed in full time equivalent units

Year
2023
Year
2024
Year

2025
Year 2026Year 2027
20 01 02 01 (Headquarters and Commission’s Representation Offices)22222
20 01 02 03 (Delegations)
01 01 01 01  (Indirect research)
01 01 01 11 (Direct research)
Other budget lines (specify)
20 02 01 (AC, END, INT from the ‘global envelope’)
20 02 03 (AC, AL, END, INT and JPD in the delegations)
XX 01 xx yy zz   43

- at Headquarters

- in Delegations
01 01 01 02 (AC, END, INT - Indirect research)
01 01 01 12 (AC, END, INT - Direct research)
Other budget lines (specify)
TOTAL22222

XX is the policy area or budget title concerned.

The human resources required will be met by staff from the DG who are already assigned to management of the action and/or have been redeployed within the DG, together if necessary with any additional allocation which may be granted to the managing DG under the annual allocation procedure and in the light of budgetary constraints.

Description of tasks to be carried out:

Officials and temporary staffSecretariat of the information security coordination group: 1 AD official + 1 AST official
External staff

3.2.4.Compatibility with the current multiannual financial framework 

The proposal/initiative:

–can be fully financed through redeployment within the relevant heading of the Multiannual Financial Framework (MFF).

The proposal requires allocating two staffs to the permanent secretariat of the Interinstitutional Coordination Group, located in HR.DS.

–◻    requires use of the unallocated margin under the relevant heading of the MFF and/or use of the special instruments as defined in the MFF Regulation.

Explain what is required, specifying the headings and budget lines concerned, the corresponding amounts, and the instruments proposed to be used.

–◻    requires a revision of the MFF.

Explain what is required, specifying the headings and budget lines concerned and the corresponding amounts.

3.2.5.Third-party contributions 

The proposal/initiative:

–    does not provide for co-financing by third parties

–◻    provides for the co-financing by third parties estimated below:

Appropriations in EUR million (to three decimal places)

Year
N 44
Year
N+1
Year
N+2
Year
N+3
Total
Specify the co-financing body 
TOTAL appropriations co-financed


Remark: the proposal will intensify current cooperations on information security through SLAs.

3.3.Estimated impact on revenue 

–The proposal/initiative has no financial impact on revenue.

–◻    The proposal/initiative has the following financial impact:

on own resources

on other revenue

please indicate, if the revenue is assigned to expenditure lines

EUR million (to three decimal places)

Budget revenue line:Appropriations available for the current financial yearImpact of the proposal/initiative 45
Year
N
Year
N+1
Year
N+2
Year
N+3

For assigned revenue, specify the budget expenditure line(s) affected.


Other remarks (e.g. method/formula used for calculating the impact on revenue or any other information).


(1) Communication on the EU Security Union Strategy, COM(2020) 605, 24 July 2020 (Strategic priority ‘A future-proof security environment).
(2) EUCO 9/19.
(3) 14972/19.
(4) WK 10563/2018 INIT section 9.
(5) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194/1).
(6) C(2020)605.
(7) The EU’s Cybersecurity Strategy for the Digital Decade | Shaping Europe’s digital future (europa.eu) including a Joint Communication with the High Representative of the Union for Foreign Affairs and Security Policy (JOIN(2020)18) and also a revised Network and Information Security (NIS) Directive (COM(2020)823).
(8) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).
(9) Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).
(10) Charter of Fundamental Rights of the European Union (OJ C 326, 26.10.2012, p. 391–407).
(11) Article 41 of the Charter of Fundamental Rights of the European Union. 
(12) Article 8 of the Charter of the Fundamental Rights of the European Union.
(13) Article 42 in the Charter of Fundamental Rights of the European Union.
(14) Article 17 of the Charter of Fundamental rights of the European Union.
(15) Directive 2001/29/EC of the European Parliament and of the Council of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society (OJ L 167, 22.6.2001, p. 10–19).
(16) Article 11 in the Charter of the Fundamental Rights of the European Union.
(17) Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).
(18) OJ 45, 14.6.1962, p. 1385.
(19) Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).
(20) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).
(21) Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1).
(22) Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1).
(23) Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149).
(24) Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted
(25) EAEC Council: Regulation No 3 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).
(26) Interinstitutional Agreement between the European Parliament, the Council of the European Union and the European Commission on Better Law-Making (OJ L 123, 12.5.2016, p. 1–14).
(27) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018).
(28) Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15–69)
(29) OJ C 202, 8.7.2011, p. 13.
(30) Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council.
(31) Idem
(32) As referred to in Article 58(2)(a) or (b) of the Financial Regulation.
(33) Details of management modes and references to the Financial Regulation may be found on the BudgWeb site: https://myintracomm.ec.europa.eu/budgweb/EN/man/budgmanag/Pages/budgmanag.aspx  
(34) Diff. = Differentiated appropriations / Non-diff. = Non-differentiated appropriations.
(35) EFTA: European Free Trade Association.
(36) Candidate countries and, where applicable, potential candidates from the Western Balkans.
(37) Year N is the year in which implementation of the proposal/initiative starts. Please replace "N" by the expected first year of implementation (for instance: 2021). The same for the following years.
(38) According to the official budget nomenclature.
(39) Technical and/or administrative assistance and expenditure in support of the implementation of EU programmes and/or actions (former ‘BA’ lines), indirect research, direct research.
(40) Outputs are products and services to be supplied (e.g.: number of student exchanges financed, number of km of roads built, etc.).
(41) As described in point 1.4.2. ‘Specific objective(s)…’
(42) Technical and/or administrative assistance and expenditure in support of the implementation of EU programmes and/or actions (former ‘BA’ lines), indirect research, direct research.
(43) Sub-ceiling for external staff covered by operational appropriations (former ‘BA’ lines).
(44) Year N is the year in which implementation of the proposal/initiative starts. Please replace "N" by the expected first year of implementation (for instance: 2021). The same for the following years.
(45) As regards traditional own resources (customs duties, sugar levies), the amounts indicated must be net amounts, i.e. gross amounts after deduction of 20 % for collection costs.