Source: OJ L 333, 27.12.2022, p. 80–152Current language: EN
- High common level of cybersecurity for entities
Basic legislative acts
- NIS 2 directive
Article 13 Cooperation at national level
Summary What does Article 13 of the NIS 2 directive say?
This article is about internal coordination and cross-regulatory cooperation.
It establishes that the various national bodies responsible for implementing the Directive — competent authorities, single points of contact, and CSIRTs — must work together and keep each other informed.
Beyond internal coordination, it reaches outward, requiring Member States to foster cooperation between these bodies and a broad range of other national and EU-level authorities, including law enforcement, data protection authorities, and regulators under several other EU frameworks such as DORA and the Critical Entities Resilience Directive.
This cross-regulatory linkage reflects the Directive's recognition that cybersecurity incidents do not sit neatly within a single regulatory silo.
Important points:
- Member States are required to ensure their national cybersecurity bodies — competent authorities, single points of contact, and CSIRTs — cooperate with each other and share notifications of incidents, cyber threats, and near misses.
- Member States must ensure cooperation between their NIS2 competent authorities and those under a range of other EU frameworks, including Directive (EU) 2022/2557, Regulation (EU) 2022/2554, Regulation (EU) No 910/2014, and Directive (EU) 2018/1972, with regular information exchange on incidents and cyber threats.
- Member States must simplify reporting through technical means for the notifications required under Articles 23 and 30.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
Where they are separate, the competent authorities, the single point of contact and the CSIRTs of the same Member State shall cooperate with each other with regard to the fulfilment of the obligations laid down in this Directive.
Member States shall ensure that their CSIRTs or, where applicable, their competent authorities, receive notifications of significant incidents pursuant to Article 23, and incidents, cyber threats and near misses pursuant to Article 30.
Member States shall ensure that their CSIRTs or, where applicable, their competent authorities inform their single points of contact of notifications of incidents, cyber threats and near misses submitted pursuant to this Directive.
In order to ensure that the tasks and obligations of the competent authorities, the single points of contact and the CSIRTs are carried out effectively, Member States shall, to the extent possible, ensure appropriate cooperation between those bodies and law enforcement authorities, data protection authorities, the national authorities under Regulations (EC) No 300/2008 and (EU) 2018/1139, the supervisory bodies under Regulation (EU) No 910/2014, the competent authorities under Regulation (EU) 2022/2554, the national regulatory authorities under Directive (EU) 2018/1972, the competent authorities under Directive (EU) 2022/2557, as well as the competent authorities under other sector-specific Union legal acts, within that Member State.
Member States shall ensure that their competent authorities under this Directive and their competent authorities under Directive (EU) 2022/2557 cooperate and exchange information on a regular basis with regard to the identification of critical entities, on risks, cyber threats, and incidents as well as on non-cyber risks, threats and incidents affecting entities identified as critical entities under Directive (EU) 2022/2557, and the measures taken in response to such risks, threats and incidents. Member States shall also ensure that their competent authorities under this Directive and their competent authorities under Regulation (EU) No 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2018/1972 exchange relevant information on a regular basis, including with regard to relevant incidents and cyber threats.
Member States shall simplify the reporting through technical means for notifications referred to in Articles 23 and 30.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
incident
Definition
risk
Definition
network and information system
- an electronic communications network as defined in Article 2, point (1), of Directive (EU) 2018/1972;
- any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data; or
- digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance;
Definition
cyber threat
Definition
entity
Definition
near miss