Článok 68
Kybernetická bezpečnosťNová úprava, v doterajších smerniciach nemá predchodcu.
1. Ak produkty s digitálnymi prvkami patria do rozsahu pôsobnosti nariadenia (EÚ) 2024/2847, členské štáty zabezpečia, aby sa v procese obstarávania zohľadnil súlad so základnými požiadavkami kybernetickej bezpečnosti stanovenými v prílohe I k uvedenému nariadeniu vrátane schopnosti výrobcov účinne riešiť zraniteľnosti.
2. Toto nariadenie nebráni členským štátom, aby na produkty s digitálnymi prvkami uplatňovali dodatočné požiadavky kybernetickej bezpečnosti pri obstarávaní alebo používaní týchto produktov na osobitné účely, a to aj vtedy, ak sa tieto produkty obstarávajú alebo používajú na účely národnej bezpečnosti alebo obrany, za predpokladu, že takéto požiadavky sú v súlade s povinnosťami členských štátov stanovenými v práve Únie a že sú potrebné a primerané na dosiahnutie týchto účelov.
3. Bez toho, aby bol dotknutý odsek 1, a bez toho, aby bola dotknutá smernica (EÚ) 2022/255552, obstarávatelia môžu v príslušných prípadoch v podrobnostiach o obstarávaní špecifikovať požiadavky týkajúce sa kybernetickej bezpečnosti obstarávaných prác, tovaru alebo služieb. Na tento účel môžu zahŕňať špecifikácie, podmienky účasti, kritériá na vyhodnotenie ponúk alebo podmienky plnenia zákaziek. Takéto požiadavky sú spojené s predmetom zákazky a sú v súlade so zásadami transparentnosti, nediskriminácie a proporcionality.
52. Smernica Európskeho parlamentu a Rady (EÚ) 2022/2555 zo 14. decembra 2022 o opatreniach na zabezpečenie vysokej spoločnej úrovne kybernetickej bezpečnosti v Únii, ktorou sa mení nariadenie (EÚ) č. 910/2014 a smernica (EÚ) 2018/1972 a zrušuje smernica (EÚ) 2016/1148 (smernica NIS 2) (Ú. v. EÚ L 333, 27.12.2022, s. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj).
Article 68
CybersecurityNew provision, with no predecessor in the current directives.
1. Where products with digital elements fall within the scope of Regulation (EU) 2024/2847, Member States shall ensure that compliance with the essential cybersecurity requirements set out in Annex I to that Regulation, including the manufacturers’ ability to handle vulnerabilities effectively are taken into consideration in the procurement process.
2. This Regulation shall not prevent Member States from subjecting products with digital elements to additional cybersecurity requirements for the procurement or use of those products for specific purposes, including where those products are procured or used for national security or defence purposes, provided that such requirements are consistent with Member States’ obligations laid down in Union law and that they are necessary and proportionate for the achievement of those purposes.
3. Without prejudice to paragraph 1, and without prejudice to Directive (EU) 2022/255552 where applicable, public buyers may specify in the procurement detail requirements relating to cybersecurity for the works, supplies or services procured. To that end, they may include specifications, selection criteria, award criteria or conditions for the performance of contracts. Such requirements shall be linked to the subject-matter of the contract and comply with the principles of transparency, non-discrimination and proportionality.
52. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj).