Rättskällor med officiella primärkällor

Utskrivet ·

Hopp til innhold
Hopp til svaret

Agent · nis2-2022-2555-12

NIS2 artikel 12: Coordinated vulnerability disclosure and a European vulnerability database

Strukturelt tre: artikkelens egne punkter, ordrett.

CELEX 32022L2555 · 2026-08-18 · Vekt 79 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

NIS2Offisiell kilde

Hva siden er
Agent, NIS2 artikel 12
Lest mot offisiell kilde
2026-08-18Fersk
Ansvarlig utgiver
ExploreWorld Legal, redaksjonenAnsvarsposisjon

Jurisdiksjon

Samme agent, lest med ett lands øyne.

Inndata

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Regeltre

  1. Hvis: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the reques…

    Punkt 1

  2. Hvis: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    (a)

    Punkt 2

  3. Hvis: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    identifying and contacting the entities concerned;

    Punkt 3

  4. Hvis: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    (b)

    Punkt 4

  5. Hvis: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    assisting the natural or legal persons reporting a vulnerability; and

    Punkt 5

  6. Hvis: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    (c)

    Punkt 6

  7. Hvis: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.

    Punkt 7

  8. Hvis: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnera…

    Punkt 8

  9. Hvis: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    2. ENISA shall develop and maintain, after consulting the Cooperation Group, a European vulnerability database. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures, and shall adopt the necessary technical and organisational measures to ensure the security and integrity of the European vulnerability database, with a view in particular to enabling entities, regar…

    Punkt 9

  10. Hvis: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    (a)

    Punkt 10

  11. Hvis: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    information describing the vulnerability;

    Punkt 11

  12. Hvis: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    (b)

    Punkt 12

  13. Hvis: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    the affected ICT products or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited;

    Punkt 13

  14. Hvis: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    (c)

    Punkt 14

Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

Artikkelteksten som ble lest

  1. 11. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the request of either party. The tasks of the CSIRT designated as coordinator shall include:
  2. 2(a)
  3. 3identifying and contacting the entities concerned;
  4. 4(b)
  5. 5assisting the natural or legal persons reporting a vulnerability; and
  6. 6(c)
  7. 7negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.
  8. 8Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRT designated as coordinator of each Member State concerned shall, where appropriate, cooperate with other CSIRTs designated as coordinators within the CSIRTs network.
  9. 92. ENISA shall develop and maintain, after consulting the Cooperation Group, a European vulnerability database. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures, and shall adopt the necessary technical and organisational measures to ensure the security and integrity of the European vulnerability database, with a view in particular to enabling entities, regardless of whether they fall within the scope of this Directive, and their suppliers of network and information systems, to disclose and register, on a voluntary basis, publicly known vulnerabilities in ICT products or ICT services. All stakeholders shall be provided access to the information about the vulnerabilities contained in the European vulnerability database. That database shall include:
  10. 10(a)
  11. 11information describing the vulnerability;
  12. 12(b)
  13. 13the affected ICT products or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited;
  14. 14(c)

Opphav

treatyTFEU art. 288 (direktiv)
act32022L2555
chapterII. Coordinated cybersecurity frameworks
article12
paragraphs14
jurisdictionEuropean Union (EU)
supervisorIMY — Sweden
national

Grensesnitt

callhttps://legal.exploreworldai.com/api/public/v1/agents/nis2-2022-2555-12/run
methodGET
outputmatched, outcome, trace, missing, hash
Kvote60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hasher

textsha256:1c6009220085dbc2f5f06a8ed774ad93d321b67ef52f90bb8c925831f248050e
scriptsha256:89435f3e3c3e76a3e194d5dd65421a435a5489142cad312e63969071b06029fa
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:f56d309d8e714345ca84b7e38463b8efa767220b28624fb08c88583272670dc7
versionagent-engine-1+legal-2026-08-25 / f56d309d8e714345

Artefakter

Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Sitering: 32022L2555 art. 12, Coordinated vulnerability disclosure and a European vulnerability database. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-12 (hämtad 2026-08-18, bevis sha256:493de87e47a6756a, bygge legal-2026-08-25).