NIS2 Directive (EU) 2022/2555

Article 11

Requirements, technical capabilities and tasks of CSIRTs

NIS2 Directive (EU) 2022/2555 – Article 11: Requirements, technical capabilities and tasks of CSIRTs

  1. (1) The CSIRTs shall comply with the following requirements: The CSIRTs may participate in international cooperation networks.
  2. (2) Member States shall ensure that their CSIRTs jointly have the technical capabilities necessary to carry out the tasks referred to in paragraph 3. Member States shall ensure that sufficient resources are allocated to their CSIRTs to ensure adequate staffing levels for the purpose of enabling the CSIRTs to develop their technical capabilities.
  3. (3) The CSIRTs shall have the following tasks: The CSIRTs may carry out proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities. Such scanning shall be carried out to detect vulnerable or insecurely configured network and information systems and inform the entities concerned. Such scanning shall not have any negative impact on the functioning of the entities’ services. When carrying out the tasks referred to in the first subparagraph, the CSIRTs may prioritise particular tasks on the basis of a risk-based approach.
  4. (4) The CSIRTs shall establish cooperation relationships with relevant stakeholders in the private sector, with a view to achieving the objectives of this Directive.
  5. (5) In order to facilitate cooperation referred to in paragraph 4, the CSIRTs shall promote the adoption and use of common or standardised practices, classification schemes and taxonomies in relation to: