Directive NIS2 European Union
Cart 0
Art. 12

Coordinated vulnerability disclosure


The process by which a reporter discloses a vulnerability to a vendor in a way that allows a fix before public disclosure.

NIS2 requires member states to designate a CSIRT as coordinator and obliges ENISA to maintain a European vulnerability database. For entities, the relevant duty sits in article 21(2)(e): vulnerability handling and disclosure must be part of your acquisition, development and maintenance security.

Related terms

Full glossary →

Cart 0