Articles
Article 12Coordinated vulnerability disclosure and a European vulnerability database
- (a)identifying and contacting the entities concerned;
- (b)assisting the natural or legal persons reporting a vulnerability; and
- (c)negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.
Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRT designated as coordinator of each Member State concerned shall, where appropriate, cooperate with other CSIRTs designated as coordinators within the CSIRTs network.
- (a)information describing the vulnerability;
- (b)the affected ICT products or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited;
- (c)the availability of related patches and, in the absence of available patches, guidance provided by the competent authorities or the CSIRTs addressed to users of vulnerable ICT products and ICT services as to how the risks resulting from disclosed vulnerabilities can be mitigated.
https://nis2.digiphile.law/article/article-12.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU NIS2 Directive (Directive (EU) 2022/2555). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.