Article 15

CSIRTs network

1.   In order to contribute to the development of confidence and trust and to promote swift and effective operational cooperation among Member States, a network of national CSIRTs is established.

2.   The CSIRTs network shall be composed of representatives of the CSIRTs designated or established pursuant to Article 10 and the computer emergency response team for the Union’s institutions, bodies and agencies (CERT-EU). The Commission shall participate in the CSIRTs network as an observer. ENISA shall provide the secretariat and shall actively provide assistance for the cooperation among the CSIRTs.

3.   The CSIRTs network shall have the following tasks:

(a)

to exchange information about the CSIRTs’ capabilities;

(b)

to facilitate the sharing, transfer and exchange of technology and relevant measures, policies, tools, processes, best practices and frameworks among the CSIRTs;

(c)

to exchange relevant information about incidents, near misses, cyber threats, risks and vulnerabilities;

(d)

to exchange information with regard to cybersecurity publications and recommendations;

(e)

to ensure interoperability with regard to information-sharing specifications and protocols;

(f)

at the request of a member of the CSIRTs network potentially affected by an incident, to exchange and discuss information in relation to that incident and associated cyber threats, risks and vulnerabilities;

(g)

at the request of a member of the CSIRTs network, to discuss and, where possible, implement a coordinated response to an incident that has been identified within the jurisdiction of that Member State;

(h)

to provide Member States with assistance in addressing cross-border incidents pursuant to this Directive;

(i)

to cooperate, exchange best practices and provide assistance to the CSIRTs designated as coordinators pursuant to Article 12(1) with regard to the management of the coordinated disclosure of vulnerabilities which could have a significant impact on entities in more than one Member State;

(j)

to discuss and identify further forms of operational cooperation, including in relation to:

(i)

categories of cyber threats and incidents;

(ii)

early warnings;

(iii)

mutual assistance;

(iv)

principles and arrangements for coordination in response to cross-border risks and incidents;

(v)

contribution to the national large-scale cybersecurity incident and crisis response plan referred to in Article 9(4) at the request of a Member State;

(k)

to inform the Cooperation Group of its activities and of the further forms of operational cooperation discussed pursuant to point (j), and, where necessary, request guidance in that regard;

(l)

to take stock of cybersecurity exercises, including those organised by ENISA;

(m)

at the request of an individual CSIRT, to discuss the capabilities and preparedness of that CSIRT;

(n)

to cooperate and exchange information with regional and Union-level Security Operations Centres (SOCs) in order to improve common situational awareness on incidents and cyber threats across the Union;

(o)

where relevant, to discuss the peer-review reports referred to in Article 19(9);

(p)

to provide guidelines in order to facilitate the convergence of operational practices with regard to the application of the provisions of this Article concerning operational cooperation.

4.   By 17 January 2025, and every two years thereafter, the CSIRTs network shall, for the purpose of the review referred to in Article 40, assess the progress made with regard to the operational cooperation and adopt a report. The report shall, in particular, draw up conclusions and recommendations on the basis of the outcome of the peer reviews referred to in Article 19, which are carried out in relation to the national CSIRTs. That report shall be submitted to the Cooperation Group.

5.   The CSIRTs network shall adopt its rules of procedure.

6.   The CSIRTs network and EU-CyCLONe shall agree on procedural arrangements and cooperate on the basis thereof.

Frequently Asked Questions

The CSIRTs network, established by the NIS2 directive, is a group of national Computer Security Incident Response Teams (CSIRTs) that work together across EU Member States to share vital cybersecurity information, exchange experiences, and quickly respond to cyber threats and incidents to enhance collective cybersecurity readiness and response capabilities throughout Europe.
The CSIRTs network consists of representatives from national CSIRTs designated by each Member State, alongside the CERT-EU, and includes participation from the European Commission as observers. Additionally, the European Union Agency for Cybersecurity (ENISA) provides secretarial support and helps facilitate cooperation among these groups to ensure efficient operational coordination and information exchange.
The CSIRTs network shares information on cybersecurity incidents, cyber threats, risks, and vulnerabilities, supports affected Member States encountering cyber incidents by coordinating responses, and ensures affected countries quickly receive trusted assistance and expert advice. The network also discusses vulnerabilities, informs about early warnings, and enhances operational cooperation and preparedness across borders.
The CSIRTs network must produce an evaluation report of its cooperative activities every two years, starting no later than January 17, 2025. This report examines the progress made toward effective operational collaboration, offers conclusions and recommendations based on peer reviews, and is submitted to the Cooperation Group to ensure continual improvement in the EU’s cybersecurity capacity and coordination.

NIS2 Training

Free Trial

We will get back to you via email as soon as possible.