Recital 63
Directive on the security of network and information systems · UE 2022/2555
| (63) | Although similar vulnerability registries or databases exist, they are hosted and maintained by entities which are not established in the Union. A European vulnerability database maintained by ENISA would provide improved transparency regarding the publication process before the vulnerability is publicly disclosed, and resilience in the event of a disruption or an interruption of the provision of similar services. In order, to the extent possible, to avoid a duplication of efforts and to seek complementarity, ENISA should explore the possibility of entering into structured cooperation agreements with similar registries or databases that fall under third-country jurisdiction. In particular, ENISA should explore the possibility of close cooperation with the operators of the Common Vulnerabilities and Exposures (CVE) system. |
In Luxembourg, the ILR is the competent NIS 2 authority and CIRCL (Computer Incident Response Center Luxembourg, part of SECURITYMADEIN.LU) operates the national CSIRT with recognised vulnerability expertise (CIRCL has been a CVE Numbering Authority since 2016). The law of 28 July 2023 on cybersecurity, amended on 28 July 2025, expects essential and important entities to integrate EUVD (ENISA), CVE/NVD and CIRCL/GOVCERT.LU bulletins into their vulnerability watch.
Luxgap practice: connect the CIRCL MISP feed to your Vulnerability Fusion Engine and automatically notify CIRCL via the MISP channel when an IoC linked to a critical CVE is detected on your estate.