NIS2 · CELEX 02022L2555-20221227
Article 11
Verbatim text of the current consolidated version (consolidated 2022-12-27) · status: in force. Check it on EUR-Lex ↗
NIS2, Article 11(1) — Requirements, technical capabilities and tasks of CSIRTs
The CSIRTs shall comply with the following requirements: (a) the CSIRTs shall ensure a high level of availability of their communication channels by avoiding single points of failure, and shall have several means for being contacted and for contacting others at all times; they shall clearly specify the communication channels and make them known to constituency and cooperative partners; (b) the CSIRTs’ premises and the supporting information systems shall be located at secure sites; (c) the CSIRTs shall be equipped with an appropriate system for managing and routing requests, in particular to facilitate effective and efficient handovers; (d) the CSIRTs shall ensure the confidentiality and trustworthiness of their operations; (e) the CSIRTs shall be adequately staffed to ensure availability of their services at all times and they shall ensure that their staff is trained appropriately; (f) the CSIRTs shall be equipped with redundant systems and backup working space to ensure continuity of their services. The CSIRTs may participate in international cooperation networks.
NIS2, Article 11(2) — Requirements, technical capabilities and tasks of CSIRTs
Member States shall ensure that their CSIRTs jointly have the technical capabilities necessary to carry out the tasks referred to in paragraph 3. Member States shall ensure that sufficient resources are allocated to their CSIRTs to ensure adequate staffing levels for the purpose of enabling the CSIRTs to develop their technical capabilities.
NIS2, Article 11(3) — Requirements, technical capabilities and tasks of CSIRTs
The CSIRTs shall have the following tasks: The CSIRTs may carry out proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities. Such scanning shall be carried out to detect vulnerable or insecurely configured network and information systems and inform the entities concerned. Such scanning shall not have any negative impact on the functioning of the entities’ services. When carrying out the tasks referred to in the first subparagraph, the CSIRTs may prioritise particular tasks on the basis of a risk-based approach.
NIS2, Article 11(3)(a) — Requirements, technical capabilities and tasks of CSIRTs
monitoring and analysing cyber threats, vulnerabilities and incidents at national level and, upon request, providing assistance to essential and important entities concerned regarding real-time or near real-time monitoring of their network and information systems;
NIS2, Article 11(3)(b) — Requirements, technical capabilities and tasks of CSIRTs
providing early warnings, alerts, announcements and dissemination of information to essential and important entities concerned as well as to the competent authorities and other relevant stakeholders on cyber threats, vulnerabilities and incidents, if possible in near real-time;
NIS2, Article 11(3)(c) — Requirements, technical capabilities and tasks of CSIRTs
responding to incidents and providing assistance to the essential and important entities concerned, where applicable;
NIS2, Article 11(3)(d) — Requirements, technical capabilities and tasks of CSIRTs
collecting and analysing forensic data and providing dynamic risk and incident analysis and situational awareness regarding cybersecurity;
NIS2, Article 11(3)(e) — Requirements, technical capabilities and tasks of CSIRTs
providing, upon the request of an essential or important entity, a proactive scanning of the network and information systems of the entity concerned to detect vulnerabilities with a potential significant impact;
NIS2, Article 11(3)(f) — Requirements, technical capabilities and tasks of CSIRTs
participating in the CSIRTs network and providing mutual assistance in accordance with their capacities and competencies to other members of the CSIRTs network upon their request;
NIS2, Article 11(3)(g) — Requirements, technical capabilities and tasks of CSIRTs
where applicable, acting as a coordinator for the purposes of the coordinated vulnerability disclosure under Article 12(1);
NIS2, Article 11(3)(h) — Requirements, technical capabilities and tasks of CSIRTs
contributing to the deployment of secure information-sharing tools pursuant to Article 10(3).
NIS2, Article 11(4) — Requirements, technical capabilities and tasks of CSIRTs
The CSIRTs shall establish cooperation relationships with relevant stakeholders in the private sector, with a view to achieving the objectives of this Directive.
NIS2, Article 11(5) — Requirements, technical capabilities and tasks of CSIRTs
In order to facilitate cooperation referred to in paragraph 4, the CSIRTs shall promote the adoption and use of common or standardised practices, classification schemes and taxonomies in relation to: (a) incident-handling procedures; (b) crisis management; and (c) coordinated vulnerability disclosure under Article 12(1).
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the NIS2
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage