Article 12 — Coordinated vulnerability disclosure and a European vulnerability database

NIS2 — direktiv (EU) 2022/2555

I rettsaktenEU 2022/2555
KapittelII · Coordinated cybersecurity frameworks
CELEX32022L2555
Lest2026-08-14

Offisiell tekst

Lest hos EUs publikasjonskontor for dette CELEX-nummeret. Ordlyden står slik den er publisert, ingenting er skrevet om eller sammenfattet.

Teksten vises på engelsk. Norsk er ikke et offisielt EU-språk, så den offisielle ordlyden finnes ikke på norsk.

1. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the request of either party. The tasks of the CSIRT designated as coordinator shall include:

(a) identifying and contacting the entities concerned;

(b) assisting the natural or legal persons reporting a vulnerability; and

(c) negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.

Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRT designated as coordinator of each Member State concerned shall, where appropriate, cooperate with other CSIRTs designated as coordinators within the CSIRTs network.

Artikkelen fortsetter i den offisielle teksten.

Åpne artikkelen på EUR-Lex

Andre artikler i kapitlet

Teksten er sitert fra den offisielle kilden og er ikke juridisk rådgivning. En nasjonal domstol leser språkversjonen som binder i sin jurisdiksjon.

Tilbake til rettsakten · EU-rettsakter, lest helt ned til nasjonal lov

ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.

Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.