Agent · nis2-2022-2555-12
NIS2 artikel 12: Coordinated vulnerability disclosure and a European vulnerability database
Strukturelt tre: artikkelens egne punkter, ordrett.
CELEX 32022L2555 · 2026-08-18 · Vekt 79 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- Hva siden er
- Agent, NIS2 artikel 12
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does NIS2 Article 12 require, and what outcome does the rule tree give?
NIS2 Article 12 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 12Lest mot utgiveren 2026-08-18Offisiell tekst
- Paragraph 1 applies. 1. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the reques…
- Paragraph 2 applies. (a)
- Paragraph 3 applies. identifying and contacting the entities concerned;
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Regeltre
Hvis: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the reques…
Punkt 1
Hvis: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
(a)
Punkt 2
Hvis: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
identifying and contacting the entities concerned;
Punkt 3
Hvis: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(b)
Punkt 4
Hvis: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
assisting the natural or legal persons reporting a vulnerability; and
Punkt 5
Hvis: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(c)
Punkt 6
Hvis: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.
Punkt 7
Hvis: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnera…
Punkt 8
Hvis: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
2. ENISA shall develop and maintain, after consulting the Cooperation Group, a European vulnerability database. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures, and shall adopt the necessary technical and organisational measures to ensure the security and integrity of the European vulnerability database, with a view in particular to enabling entities, regar…
Punkt 9
Hvis: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
(a)
Punkt 10
Hvis: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
information describing the vulnerability;
Punkt 11
Hvis: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
(b)
Punkt 12
Hvis: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
the affected ICT products or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited;
Punkt 13
Hvis: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
(c)
Punkt 14
Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
Artikkelteksten som ble lest
- 11. Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the request of either party. The tasks of the CSIRT designated as coordinator shall include:
- 2(a)
- 3identifying and contacting the entities concerned;
- 4(b)
- 5assisting the natural or legal persons reporting a vulnerability; and
- 6(c)
- 7negotiating disclosure timelines and managing vulnerabilities that affect multiple entities.
- 8Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRT designated as coordinator of each Member State concerned shall, where appropriate, cooperate with other CSIRTs designated as coordinators within the CSIRTs network.
- 92. ENISA shall develop and maintain, after consulting the Cooperation Group, a European vulnerability database. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures, and shall adopt the necessary technical and organisational measures to ensure the security and integrity of the European vulnerability database, with a view in particular to enabling entities, regardless of whether they fall within the scope of this Directive, and their suppliers of network and information systems, to disclose and register, on a voluntary basis, publicly known vulnerabilities in ICT products or ICT services. All stakeholders shall be provided access to the information about the vulnerabilities contained in the European vulnerability database. That database shall include:
- 10(a)
- 11information describing the vulnerability;
- 12(b)
- 13the affected ICT products or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited;
- 14(c)
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32022L2555 art. 12, Coordinated vulnerability disclosure and a European vulnerability database. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-12 (hämtad 2026-08-18, bevis sha256:493de87e47a6756a, bygge legal-2026-08-25).