Source: OJ L, 2026/881, 20.4.2026

Current language: SV

Artikel 2 Definitioner


Summary What does Article 2 of the Terms and conditions for delaying notifications say?

This is a definitions article, establishing the precise meaning of two key terms used throughout the Regulation.

Rather than introducing substantive obligations, it sets the terminological foundation that underpins the operative provisions — particularly those in Articles 3, 4, and 5 — which govern when and how the dissemination of vulnerability notifications may be delayed.

Both definitions are anchored in existing legal frameworks, specifically Directive (EU) 2022/2555 and Regulation (EU) 2024/2847, ensuring consistency across the broader EU cybersecurity legislative landscape.

Important points:

  • The "CSIRT initially receiving the notification" refers to the designated coordinator CSIRT that first receives a vulnerability notification under Regulation (EU) 2024/2847 — this is the body that holds the power to delay dissemination under the Regulation.
  • The "relevant CSIRT" is defined as the designated coordinator CSIRT covering the territory where the manufacturer has indicated the product with digital elements has been made available — establishing which CSIRTs are entitled to receive disseminated notifications.
  • Both definitions rely on the designation mechanism set out in Article 12(1) of Directive (EU) 2022/2555, tying this Regulation firmly to the broader NIS2 framework.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

I denna förordning gäller följande definitioner:

  1. CSIRT-enhet som först tog emot anmälan: den CSIRT-enhet som utsetts till samordnare och som först tog emot anmälan i enlighet med artiklarna 14.1, 14.3, 15.1 och 15.2 i förordning (EU) 2024/2847.

  2. berörd CSIRT-enhet: den CSIRT-enhet som utsetts till samordnare på det territorium där tillverkaren har angett att produkten med digitala element har tillhandahållits.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod