acquis · Law · NIS2

NIS2 · CELEX 02022L2555-20221227

Article 10

Verbatim text of the current consolidated version (consolidated 2022-12-27) · status: in force. Check it on EUR-Lex ↗

NIS2, Article 10(1) — Computer security incident response teams (CSIRTs)
Each Member State shall designate or establish one or more CSIRTs. The CSIRTs may be designated or established within a competent authority. The CSIRTs shall comply with the requirements set out in Article 11(1), shall cover at least the sectors, subsectors and types of entity referred to in Annexes I and II, and shall be responsible for incident handling in accordance with a well-defined process.
NIS2, Article 10(2) — Computer security incident response teams (CSIRTs)
Member States shall ensure that each CSIRT has adequate resources to carry out effectively its tasks as set out in Article 11(3).
NIS2, Article 10(3) — Computer security incident response teams (CSIRTs)
Member States shall ensure that each CSIRT has at its disposal an appropriate, secure, and resilient communication and information infrastructure through which to exchange information with essential and important entities and other relevant stakeholders. To that end, Member States shall ensure that each CSIRT contributes to the deployment of secure information-sharing tools.
NIS2, Article 10(4) — Computer security incident response teams (CSIRTs)
The CSIRTs shall cooperate and, where appropriate, exchange relevant information in accordance with Article 29 with sectoral or cross-sectoral communities of essential and important entities.
NIS2, Article 10(5) — Computer security incident response teams (CSIRTs)
The CSIRTs shall participate in peer reviews organised in accordance with Article 19.
NIS2, Article 10(6) — Computer security incident response teams (CSIRTs)
Member States shall ensure the effective, efficient and secure cooperation of their CSIRTs in the CSIRTs network.
NIS2, Article 10(7) — Computer security incident response teams (CSIRTs)
The CSIRTs may establish cooperation relationships with third countries’ national computer security incident response teams. As part of such cooperation relationships, Member States shall facilitate effective, efficient and secure information exchange with those third countries’ national computer security incident response teams, using relevant information-sharing protocols, including the traffic light protocol. The CSIRTs may exchange relevant information with third countries’ national computer security incident response teams, including personal data in accordance with Union data protection law.
NIS2, Article 10(8) — Computer security incident response teams (CSIRTs)
The CSIRTs may cooperate with third countries’ national computer security incident response teams or equivalent third-country bodies, in particular for the purpose of providing them with cybersecurity assistance.
NIS2, Article 10(9) — Computer security incident response teams (CSIRTs)
Each Member State shall notify the Commission without undue delay of the identity of the CSIRT referred to in paragraph 1 of this Article and the CSIRT designated as coordinator pursuant to Article 12(1), of their respective tasks in relation to essential and important entities, and of any subsequent changes thereto.
NIS2, Article 10(10) — Computer security incident response teams (CSIRTs)
Member States may request the assistance of ENISA in developing their CSIRTs.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →

Other articles of the NIS2

← Article 9 · Article 11

Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage