Agent · nis2-2022-2555-29
NIS2 artikel 29: Cybersecurity information-sharing arrangements
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022L2555 · 2026-08-18 · Weight 79 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, NIS2 artikel 29
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does NIS2 Article 29 require, and what outcome does the rule tree give?
NIS2 Article 29 is tested here by a deterministic rule tree of 9 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 29Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. Member States shall ensure that entities falling within the scope of this Directive and, where relevant, other entities not falling within the scope of this Directive are able to exchange on a voluntary basis relevant cybersecurity information among themselves, including information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, th…
- Paragraph 2 applies. (a)
- Paragraph 3 applies. aims to prevent, detect, respond to or recover from incidents or to mitigate their impact;
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Member States shall ensure that entities falling within the scope of this Directive and, where relevant, other entities not falling within the scope of this Directive are able to exchange on a voluntary basis relevant cybersecurity information among themselves, including information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, th…
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
(a)
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
aims to prevent, detect, respond to or recover from incidents or to mitigate their impact;
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(b)
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
enhances the level of cybersecurity, in particular through raising awareness in relation to cyber threats, limiting or impeding the ability of such threats to spread, supporting a range of defensive capabilities, vulnerability remediation and disclosure, threat detection, containment and prevention techniques, mitigation strategies, or response and recovery stages or promoting collaborative cyber threat research betw…
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
2. Member States shall ensure that the exchange of information takes place within communities of essential and important entities, and where relevant, their suppliers or service providers. Such exchange shall be implemented through cybersecurity information-sharing arrangements in respect of the potentially sensitive nature of the information shared.
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
3. Member States shall facilitate the establishment of cybersecurity information-sharing arrangements referred to in paragraph 2 of this Article. Such arrangements may specify operational elements, including the use of dedicated ICT platforms and automation tools, content and conditions of the information-sharing arrangements. In laying down the details of the involvement of public authorities in such arrangements, M…
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
4. Member States shall ensure that essential and important entities notify the competent authorities of their participation in the cybersecurity information-sharing arrangements referred to in paragraph 2, upon entering into such arrangements, or, as applicable, of their withdrawal from such arrangements, once the withdrawal takes effect.
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
5. ENISA shall provide assistance for the establishment of cybersecurity information-sharing arrangements referred to in paragraph 2 by exchanging best practices and providing guidance.
Paragraph 9
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. Member States shall ensure that entities falling within the scope of this Directive and, where relevant, other entities not falling within the scope of this Directive are able to exchange on a voluntary basis relevant cybersecurity information among themselves, including information relating to cyber threats, near misses, vulnerabilities, techniques and procedures, indicators of compromise, adversarial tactics, threat-actor-specific information, cybersecurity alerts and recommendations regarding configuration of cybersecurity tools to detect cyberattacks, where such information sharing:
- 2(a)
- 3aims to prevent, detect, respond to or recover from incidents or to mitigate their impact;
- 4(b)
- 5enhances the level of cybersecurity, in particular through raising awareness in relation to cyber threats, limiting or impeding the ability of such threats to spread, supporting a range of defensive capabilities, vulnerability remediation and disclosure, threat detection, containment and prevention techniques, mitigation strategies, or response and recovery stages or promoting collaborative cyber threat research between public and private entities.
- 62. Member States shall ensure that the exchange of information takes place within communities of essential and important entities, and where relevant, their suppliers or service providers. Such exchange shall be implemented through cybersecurity information-sharing arrangements in respect of the potentially sensitive nature of the information shared.
- 73. Member States shall facilitate the establishment of cybersecurity information-sharing arrangements referred to in paragraph 2 of this Article. Such arrangements may specify operational elements, including the use of dedicated ICT platforms and automation tools, content and conditions of the information-sharing arrangements. In laying down the details of the involvement of public authorities in such arrangements, Member States may impose conditions on the information made available by the competent authorities or the CSIRTs. Member States shall offer assistance for the application of such arrangements in accordance with their policies referred to in Article 7(2), point (h).
- 84. Member States shall ensure that essential and important entities notify the competent authorities of their participation in the cybersecurity information-sharing arrangements referred to in paragraph 2, upon entering into such arrangements, or, as applicable, of their withdrawal from such arrangements, once the withdrawal takes effect.
- 95. ENISA shall provide assistance for the establishment of cybersecurity information-sharing arrangements referred to in paragraph 2 by exchanging best practices and providing guidance.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022L2555 art. 29, Cybersecurity information-sharing arrangements. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-29 (hämtad 2026-08-18, bevis sha256:7ae91b07863d1998, bygge legal-2026-08-25).