Art. 12
Coordinated vulnerability disclosure
The process by which a reporter discloses a vulnerability to a vendor in a way that allows a fix before public disclosure.
NIS2 requires member states to designate a CSIRT as coordinator and obliges ENISA to maintain a European vulnerability database. For entities, the relevant duty sits in article 21(2)(e): vulnerability handling and disclosure must be part of your acquisition, development and maintenance security.
Related terms
- Essential entity · Art. 3(1)
- Important entity · Art. 3(2)
- Significant incident · Art. 23(3)
- Early warning · Art. 23(4)(a)
- Size-cap rule · Art. 2(1)
- CSIRT · Art. 10