Source: OJ L, 2026/881, 20.4.2026

Current language: FR

Article 4 Conditions d’application des motifs ayant trait à la cybersécurité en ce qui concerne un CSIRT particulier


Summary What does Article 4 of the Terms and conditions for delaying notifications say?

This article deals with a more targeted scenario compared to Article 3, which addresses delays in dissemination broadly.

Here, the focus is on situations where the CSIRT initially receiving the notification may withhold sharing notification information with a specific relevant CSIRT, rather than all relevant CSIRTs.

The basis for this targeted delay is concern over that specific CSIRT's ability to maintain the confidentiality of the notified information, either because it has suffered a cybersecurity incident or because its general capabilities are considered inadequate.

The article also sets out the conditions under which dissemination may resume, tying the end of the delay to the relevant CSIRT demonstrating that the confidentiality concern has been resolved.

Important points:

  • The CSIRT initially receiving the notification may delay dissemination to a specific relevant CSIRT if that CSIRT has been hit by a cybersecurity incident or is considered to lack adequate capability to protect the confidentiality of the information.
  • The delay triggered by a cybersecurity incident lasts until the affected CSIRT notifies the CSIRTs Network that its confidentiality capabilities have been restored.
  • Where the delay is based on inadequate capabilities, the relevant CSIRT must provide evidence that it has addressed the identified shortcomings before dissemination resumes.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

  1. Le CSIRT recevant initialement la notification peut décider de retarder pour une période limitée à ce qui est strictement nécessaire la diffusion des notifications ou de parties de celles-ci à un CSIRT concerné particulier dans les cas où:

    1. le CSIRT concerné a été touché par un incident de cybersécurité remettant en cause sa capacité à garantir la confidentialité des informations notifiées;

    2. il a des raisons suffisantes de penser que les capacités du CSIRT concerné sont insuffisantes pour garantir la confidentialité des informations notifiées.

  2. Dans les cas visés au premier alinéa, point a), le CSIRT recevant initialement la notification peut retarder la diffusion jusqu’à ce que le CSIRT concerné ait informé le réseau des CSIRT mentionné à l’article 15 de la directive (UE) 2022/2555 que sa capacité à garantir la confidentialité des notifications a été rétablie.

  3. Dans les cas visés au premier alinéa, point b), le CSIRT recevant initialement la notification peut retarder la diffusion au CSIRT concerné jusqu’à ce que ce dernier ait fourni la preuve qu’il a remédié aux lacunes constatées.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod