- Latest available (Revised)
- Original (As adopted by EU)
When the UK left the EU, legislation.gov.uk published EU legislation that had been published by the EU up to IP completion day (31 December 2020 11.00 p.m.). On legislation.gov.uk, these items of legislation are kept up-to-date with any amendments made by the UK since then.
Legislation.gov.uk publishes the UK version. EUR-Lex publishes the EU version. The EU Exit Web Archive holds a snapshot of EUR-Lex’s version from IP completion day (31 December 2020 11.00 p.m.).
This version of this Decision was derived from EUR-Lex on IP completion day (31 December 2020 11:00 p.m.). It has not been amended by the UK since then. Find out more about legislation originating from the EU as published on legislation.gov.uk.![]()
Revised legislation carried on this site may not be fully up to date. At the current time any known changes or effects made by subsequent legislation have been applied to the text of the legislation you are viewing by the editorial team. Please see ‘Frequently Asked Questions’ for details regarding the timescales for which new effects are identified and recorded on this site.
Article 2.Definition of EUCI, security classifications and markings
Article 10.Protection of EUCI handled in communication and information systems
Article 13.Exchange of classified information with third States and international organisations
ANNEXES
III. PERSONNEL SECURITY CLEARANCE REQUIREMENTS
4. After having received a duly authorised request, NSAs or other...
5. Should the individual concerned reside in the territory of another...
6. Where permissible under national laws and regulations, NSAs or other...
Investigative requirements for access to EUCI
Authorisation procedures in the GSC
17. Where information relevant for a security investigation becomes known to...
18. Following completion of the security investigation, the relevant NSA shall...
19. The security investigation together with the results obtained shall be...
20. National experts seconded to the GSC for a position requiring...
21. The GSC will accept the authorisation for access to EUCI...
22. If an individual’s period of service does not commence within...
23. Where information becomes known to the GSC concerning a security...
25. Any decision to withdraw or suspend an authorisation from a...
32. Where permissible under national laws and regulations, security clearance granted...
33. For reasons of urgency, where duly justified in the interests...
35. The above procedure shall be used for one-time access to...
36. In very exceptional circumstances, such as missions in hostile environments...
37. In the case of information classified TRÈS SECRET UE/EU TOP...
38. The Security Committee shall be informed of cases when recourse...
39. Where national laws and regulations of a Member State stipulate...
40. The Security Committee shall receive an annual report on recourse...
II. PHYSICAL SECURITY REQUIREMENTS AND MEASURES
3. Physical security measures shall be selected on the basis of...
4. The competent security authority, applying the concept of defence in...
5. The competent authority can be authorised to conduct entry and...
6. When EUCI is at risk from overlooking, even accidentally, appropriate...
7. For new facilities, physical security requirements and their functional specifications...
III. EQUIPMENT FOR THE PHYSICAL PROTECTION OF EUCI
8. When acquiring equipment (such as security containers, shredding machines, door...
9. The technical specifications of equipment to be used for the...
10. Security systems shall be inspected at regular intervals and equipment...
11. The effectiveness of individual security measures and of the overall...
IV. PHYSICALLY PROTECTED AREAS
12. Two types of physically protected areas, or the national equivalents...
13. The competent security authority shall establish that an area meets...
16. Where entry into a Secured Area constitutes, for all practical...
17. Secured Areas protected against eavesdropping shall be designated technically Secured...
18. Notwithstanding point (d) of paragraph 17, before being used in...
19. Secured Areas which are not occupied by duty personnel on...
20. Secured Areas and technically Secured Areas may be set up...
21. Security operating procedures shall be drawn up for each Secured...
22. Strong rooms shall be constructed within Secured Areas. The walls,...
V. PHYSICAL PROTECTIVE MEASURES FOR HANDLING AND STORING EUCI
23. EUCI which is classified RESTREINT UE/EU RESTRICTED may be handled:...
24. EUCI which is classified RESTREINT UE/EU RESTRICTED shall be stored...
25. EUCI which is classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU...
26. EUCI which is classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU...
27. EUCI which is classified TRÈS SECRET UE/EU TOP SECRET shall...
28. EUCI which is classified TRÈS SECRET UE/EU TOP SECRET shall...
29. Rules governing the carriage of EUCI outside physically protected areas...
VI. CONTROL OF KEYS AND COMBINATIONS USED FOR PROTECTING EUCI
MANAGEMENT OF CLASSIFIED INFORMATION
2. Information shall be classified where it requires protection with regard...
3. The originator of EUCI shall be responsible for determining the...
4. The classification level of EUCI shall be determined in accordance...
5. The security classification shall be clearly and correctly indicated, regardless...
6. Individual parts of a given document (i.e. pages, paragraphs, sections,...
7. The overall classification level of a document or file shall...
8. To the extent possible, documents containing parts with different classification...
9. The classification of a letter or note covering enclosures shall...
III. REGISTRATION OF EUCI FOR SECURITY PURPOSES
17. For every organisational entity within the GSC and Member States’...
18. For the purposes of this Decision, registration for security purposes...
19. All material classified CONFIDENTIEL UE/EU CONFIDENTIAL and above shall be...
20. The Central Registry within the GSC shall keep a record...
22. The Council shall approve a security policy on the registration...
28. Carriage of EUCI shall be subject to the protective measures...
29. The competent security authorities in the GSC and in Member...
32. EUCI carried between buildings or premises within the Union shall...
33. The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET...
34. Information classified RESTREINT UE/EU RESTRICTED may also be carried by...
35. Material classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET (e.g....
36. The carriage of information classified TRÈS SECRET UE/EU TOP SECRET...
From within the Union to the territory of a third...
37. EUCI carried from within the Union to the territory of...
38. The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET...
39. The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET...
40. Information classified RESTREINT UE/EU RESTRICTED may also be carried by...
41. The carriage of information classified TRÈS SECRET UE/EU TOP SECRET...
42. EU classified documents which are no longer required may be...
43. Documents subject to registration in accordance with Article 9(2) shall...
44. For documents classified SECRET UE/EU SECRET or TRÈS SECRET UE/EU...
45. The registrar and the witness, where the presence of the...
46. Classified documents, including those classified RESTREINT UE/EU RESTRICTED, shall be...
47. The destruction of computer storage media used for EUCI shall...
49. The term ‘assessment visit’ shall be used hereinafter to designate...
51. Before the end of each calendar year, the Council shall...
52. Assessment visits shall be conducted in order to check the...
53. Assessment visits shall be conducted in two phases. Prior to...
54. Assessment visits to Member States’ national administrations, third States and...
55. Assessment visits to Union bodies, agencies and entities which apply...
56. In the case of assessment visits to Union bodies, agencies...
57. At the end of the assessment visit the main conclusions...
58. For assessment visits conducted in Member States’ national administrations:
59. For assessment visits of third States and international organisations, the...
60. For assessment visits to any Union bodies, agencies and entities...
61. The GSC Security Authority shall conduct regular inspections of organisational...
PROTECTION OF EUCI HANDLED IN CIS
II. INFORMATION ASSURANCE PRINCIPLES
3. The provisions set out below shall form the baseline for...
Security throughout the CIS life-cycle
8. Ensuring security shall be a requirement throughout the entire CIS...
10. Any CIS, including its technical and non-technical security measures, shall...
11. Security assessments, inspections and reviews shall be performed periodically during...
12. Security documentation for a CIS shall evolve over its life-cycle...
Evaluation and approval of IT-security products
23. The required degree of confidence in the security measures, defined...
24. The level of assurance shall be verified by using internationally...
25. Cryptographic products for protecting EUCI shall be evaluated and approved...
26. Prior to being recommended for approval by the Council or...
27. Where warranted on specific operational grounds, the Council or the...
28. The Council, acting upon recommendation by the Security Committee, may...
30. The Council shall approve a security policy on the qualification...
32. For the purposes of this Decision, an interconnection shall mean...
33. A CIS shall treat any interconnected IT system as untrusted...
34. For all interconnections of CIS with another IT system the...
35. There shall be no interconnection between an accredited CIS and...
36. The direct or cascaded interconnection of a CIS accredited to...
39. Notwithstanding the provisions of this Decision, the specific procedures described...
40. EUCI may be transmitted using cryptographic products which have been...
41. Classified information transmitted under the circumstances set out in paragraph...
42. Should recourse be made to paragraph 39 a subsequent report...
II. SECURITY ELEMENTS IN A CLASSIFIED CONTRACT
IV. CLASSIFIED CONTRACTS AND SUB-CONTRACTS
14. Where EUCI is provided to a bidder at the pre-contractual...
15. Once a classified contract or sub-contract has been awarded, the...
16. When such contracts are terminated, the GSC, as the contracting...
17. As a general rule, the contractor or subcontractor shall be...
18. Specific provisions for the disposal of EUCI during the performance...
19. Where the contractor or subcontractor is authorised to retain EUCI...
20. The conditions under which the contractor may subcontract shall be...
21. A contractor shall obtain permission from the GSC, as the...
22. The contractor shall be responsible for ensuring that all sub-contracting...
23. With regard to EUCI created or handled by the contractor...
VII. TRANSFER OF EUCI TO CONTRACTORS LOCATED IN THIRD STATES
VIII INFORMATION CLASSIFIED RESTREINT UE/EU RESTRICTED
31. In liaison, as appropriate, with the NSA/DSA of the Member...
32. To the extent necessary under national laws and regulations, NSAs/DSAs...
33. An FSC or a PSC for contractors or subcontractors and...
34. The GSC, as the contracting authority, shall examine the responses...
35. The conditions under which the contractor may subcontract shall be...
36. Where a contract involves handling information classified RESTREINT UE/EU RESTRICTED...
EXCHANGE OF CLASSIFIED INFORMATION WITH THIRD STATES AND INTERNATIONAL ORGANISATIONS
II. FRAMEWORKS GOVERNING THE EXCHANGE OF CLASSIFIED INFORMATION
III. SECURITY OF INFORMATION AGREEMENTS
5. Security of information agreements shall establish the basic principles and...
6. Security of information agreements shall provide for technical implementing arrangements...
7. No EUCI shall be exchanged under a security of information...
8. When the Council concludes a security of information agreement, a...
9. In order to assess the effectiveness of the security regulations,...
10. The team conducting an assessment visit on behalf of the...
12. Every endeavour shall be made to conduct a full security...
13. The report on the assessment visit, or in the absence...
14. The competent security authorities of the Union institutions and bodies...
15. Follow-up assessment visits shall be conducted as necessary, in particular...
16. Once the security of information agreement is in force and...
IV. ADMINISTRATIVE ARRANGEMENTS
17. Where a long-term need exists to exchange information classified as...
18. Where, for urgent operational reasons, a framework for exchanging classified...
19. Administrative arrangements shall as a general rule take the form...
20. An assessment visit referred to in paragraph 9 shall be...
21. No EUCI shall be exchanged under an administrative arrangement by...
V. EXCHANGE OF CLASSIFIED INFORMATION IN THE CONTEXT OF CSDP OPERATIONS...
22. Framework participation agreements govern the participation of third States or...
23. Ad hoc participation agreements concluded for a specific CSDP operation...
24. In the absence of a security of information agreement and...
25. The provisions on classified information to be included in framework...
26. If a security of information agreement is subsequently concluded between...
27. No exchange of EUCI by electronic means shall be permitted...
28. EUCI generated for the purposes of a CSDP operation may...
29. In the absence of a security of information agreement, the...
30. In the absence of a security of information agreement, the...
31. No implementing arrangements or assessment visits are required prior to...
VI. EXCEPTIONAL AD HOC RELEASE OF EUCI
32. Where no framework is in place in accordance with Sections...
33. If the Security Committee issues a recommendation in favour of...
34. If the Security Committee’s recommendation is not in favour of...
35. Where deemed appropriate, and subject to the prior written consent...
36. Following a decision to release EUCI, the GSC shall forward...
VII. AUTHORITY TO RELEASE EUCI TO THIRD STATES OR INTERNATIONAL ORGANISATIONS...
ATTACHMENTS
The Whole Decision you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.
Would you like to continue?
The Schedules you have selected contains over 200 provisions and might take some time to download. You may also experience some issues with your browser, such as an alert box that a script is taking a long time to run.
Would you like to continue?
Latest Available (revised):The latest available updated version of the legislation incorporating changes made by subsequent legislation and applied by our editorial team. Changes we have not yet applied to the text, can be found in the ‘Changes to Legislation’ area.
Original (As adopted by EU): The original version of the legislation as it stood when it was first adopted in the EU. No changes have been applied to the text.
Access essential accompanying documents and information for this legislation item from this tab. Dependent on the legislation item being viewed this may include:
This timeline shows the different versions taken from EUR-Lex before exit day and during the implementation period as well as any subsequent versions created after the implementation period as a result of changes made by UK legislation.
The dates for the EU versions are taken from the document dates on EUR-Lex and may not always coincide with when the changes came into force for the document.
For any versions created after the implementation period as a result of changes made by UK legislation the date will coincide with the earliest date on which the change (e.g an insertion, a repeal or a substitution) that was applied came into force. For further information see our guide to revised legislation on Understanding Legislation.
Use this menu to access essential accompanying documents and information for this legislation item. Dependent on the legislation item being viewed this may include:
Click 'View More' or select 'More Resources' tab for additional information including:
The data on this page is available in the alternative data formats listed: