Skip to main content
Glossary term

CSIRT designated as coordinator

What does "CSIRT designated as coordinator" mean under the Cyber Resilience Act?

A CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555:

Each Member State shall designate one of its CSIRTs as a coordinator for the purposes of coordinated vulnerability disclosure. The CSIRT designated as coordinator shall act as a trusted intermediary, facilitating, where necessary, the interaction between the natural or legal person reporting a vulnerability and the manufacturer or provider of the potentially vulnerable ICT products or ICT services, upon the request of either party. The tasks of the CSIRT designated as coordinator shall include:
  • (a) identifying and contacting the entities concerned
  • (b) assisting the natural or legal persons reporting a vulnerability
  • (c) negotiating disclosure timelines and managing vulnerabilities that affect multiple entities
Member States shall ensure that natural or legal persons are able to report, anonymously where they so request, a vulnerability to the CSIRT designated as coordinator. The CSIRT designated as coordinator shall ensure that diligent follow-up action is carried out with regard to the reported vulnerability and shall ensure the anonymity of the natural or legal person reporting the vulnerability. Where a reported vulnerability could have a significant impact on entities in more than one Member State, the CSIRT designated as coordinator of each Member State concerned shall, where appropriate, cooperate with other CSIRTs designated as coordinators within the CSIRTs network.

Defined in / by

Last updated: 22 August 2026.