Source: OJ L 333, 27.12.2022, p. 80–152
EN
- High common level of cybersecurity
Basic legislative acts
- NIS 2 directive
Article 13 Cooperation at national level
Where they are separate, the competent authoritiesas defined in Article 46, the single point of contact and the CSIRTscomputer security incident response teams of the same Member State shall cooperate with each other with regard to the fulfilment of the obligations laid down in this Directive.
Member States shall ensure that their CSIRTscomputer security incident response teams or, where applicable, their competent authoritiesas defined in Article 46, receive notifications of significant incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; pursuant to Article 23, and incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;, cyber threats means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; and near misses pursuant to Article 30.
Member States shall ensure that their CSIRTscomputer security incident response teams or, where applicable, their competent authoritiesas defined in Article 46 inform their single points of contact of notifications of incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;, cyber threats means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; and near misses submitted pursuant to this Directive.
In order to ensure that the tasks and obligations of the competent authoritiesas defined in Article 46, the single points of contact and the CSIRTscomputer security incident response teams are carried out effectively, Member States shall, to the extent possible, ensure appropriate cooperation between those bodies and law enforcement authorities, data protection authorities, the national authorities under Regulations (EC) No 300/2008 and (EU) 2018/1139, the supervisory bodies under Regulation (EU) No 910/2014, the competent authoritiesas defined in Article 46 under Regulation (EU) 2022/2554, the national regulatory authorities under Directive (EU) 2018/1972, the competent authoritiesas defined in Article 46 under Directive (EU) 2022/2557, as well as the competent authoritiesas defined in Article 46 under other sector-specific Union legal acts, within that Member State.
Member States shall ensure that their competent authoritiesas defined in Article 46 under this Directive and their competent authoritiesas defined in Article 46 under Directive (EU) 2022/2557 cooperate and exchange information on a regular basis with regard to the identification of critical entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;, on risks means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, cyber threats means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;, and incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; as well as on non-cyber risks means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, threats and incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; affecting entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; identified as critical entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; under Directive (EU) 2022/2557, and the measures taken in response to such risks means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;, threats and incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;. Member States shall also ensure that their competent authoritiesas defined in Article 46 under this Directive and their competent authoritiesas defined in Article 46 under Regulation (EU) No 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2018/1972 exchange relevant information on a regular basis, including with regard to relevant incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; and cyber threats means a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;.
Member States shall simplify the reporting through technical means for notifications referred to in Articles 23 and 30.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.