Recital 62

Recital 62

Directive on the security of network and information systems · UE 2022/2555

(62)

Access to correct and timely information about vulnerabilities affecting ICT products and ICT services contributes to an enhanced cybersecurity risk management. Sources of publicly available information about vulnerabilities are an important tool for the entities and for the users of their services, but also for the competent authorities and the CSIRTs. For that reason, ENISA should establish a European vulnerability database where entities, regardless of whether they fall within the scope of this Directive, and their suppliers of network and information systems, as well as the competent authorities and the CSIRTs, can disclose and register, on a voluntary basis, publicly known vulnerabilities for the purpose of allowing users to take appropriate mitigating measures. The aim of that database is to address the unique challenges posed by risks to Union entities. Furthermore, ENISA should establish an appropriate procedure regarding the publication process in order to give entities the time to take mitigating measures as regards their vulnerabilities and employ state-of-the-art cybersecurity risk-management measures as well as machine-readable datasets and corresponding interfaces. To encourage a culture of disclosure of vulnerabilities, disclosure should have no detrimental effects on the reporting natural or legal person.

Luxembourg specificity
loi du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the national competent authority for NIS 2 and works in direct coordination with GOVCERT.LU and the CIRCL (Computer Incident Response Center Luxembourg), one of Europe's most active CSIRTs in coordinated vulnerability disclosure and a major contributor to the ENISA EUVD. The Law of 28 July 2023 on cybersecurity, amended by the Law of 28 July 2025, anchors this voluntary disclosure mechanism and designates CIRCL as the preferred contact point for coordinated reporting by essential and important entities established in the Grand Duchy.

Luxgap practice: connect your CVD process to CIRCL through their MISP platform, and keep the timestamped proof of disclosure to present to the ILR during an inspection as concrete evidence of your cyber maturity.