Recital 63

Recital 63

Directive on the security of network and information systems · UE 2022/2555

(63)

Although similar vulnerability registries or databases exist, they are hosted and maintained by entities which are not established in the Union. A European vulnerability database maintained by ENISA would provide improved transparency regarding the publication process before the vulnerability is publicly disclosed, and resilience in the event of a disruption or an interruption of the provision of similar services. In order, to the extent possible, to avoid a duplication of efforts and to seek complementarity, ENISA should explore the possibility of entering into structured cooperation agreements with similar registries or databases that fall under third-country jurisdiction. In particular, ENISA should explore the possibility of close cooperation with the operators of the Common Vulnerabilities and Exposures (CVE) system.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite, modifiee par la loi du 28 juillet 2025

In Luxembourg, the ILR is the competent NIS 2 authority and CIRCL (Computer Incident Response Center Luxembourg, part of SECURITYMADEIN.LU) operates the national CSIRT with recognised vulnerability expertise (CIRCL has been a CVE Numbering Authority since 2016). The law of 28 July 2023 on cybersecurity, amended on 28 July 2025, expects essential and important entities to integrate EUVD (ENISA), CVE/NVD and CIRCL/GOVCERT.LU bulletins into their vulnerability watch.

Luxgap practice: connect the CIRCL MISP feed to your Vulnerability Fusion Engine and automatically notify CIRCL via the MISP channel when an IoC linked to a critical CVE is detected on your estate.