Recital 61

Recital 61

Directive on the security of network and information systems · UE 2022/2555

(61)

Member States should designate one of its CSIRTs as a coordinator, acting as a trusted intermediary between the reporting natural or legal persons and the manufacturers or providers of ICT products or ICT services, which are likely to be affected by the vulnerability, where necessary. The tasks of the CSIRT designated as coordinator should include identifying and contacting the entities concerned, assisting the natural or legal persons reporting a vulnerability, negotiating disclosure timelines and managing vulnerabilities that affect multiple entities (multi-party coordinated vulnerability disclosure). Where the reported vulnerability could have significant impact on entities in more than one Member State, the CSIRTs designated as coordinators should cooperate within the CSIRTs network, where appropriate.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the coordinator CSIRT under Recital 61 is GOVCERT.LU for the public sector and critical operators, working closely with CIRCL (Computer Incident Response Center Luxembourg) which historically acts as CVD coordinator for the private sector. The ILR, the NIS 2 competent authority, supervises the framework. The law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) confirms this dual architecture and requires essential and important entities to cooperate with the coordinator CSIRT when a vulnerability is reported.

Luxgap practice: explicitly declare GOVCERT.LU and CIRCL contact addresses in your security.txt as escalation channels, and test your cross-notification procedure with both entities twice a year to eliminate any grey zone during a multi-entity incident.