NIS2 and Vulnerability Disclosure: what the directive requires and how to comply
By Kike Gandia · Co-Founder & CEO, OSCP
The NIS2 Directive includes vulnerability management and the existence of notification channels among its requirements. For many companies, this means for the first time the need to implement a Vulnerability Disclosure Programme (VDP) and a formal process for managing external security reports.
What NIS2 says about vulnerabilities and disclosure
Article 7 of NIS2 establishes the obligation of essential and important entities to adopt 'a coordinated vulnerability disclosure policy'. Article 12 creates a European network of response teams (CSIRTs) and establishes vulnerability notification mechanisms at the European level.
In practical terms, NIS2 requires:
• Having a process for receiving, managing and resolving vulnerability reports.
• Having secure communication channels for vulnerability notification.
• Cooperating with national CERTs (such as INCIBE-CERT in Spain) in managing significant vulnerabilities.
• Documenting the vulnerability management process as part of the security management system.
Which companies this NIS2 requirement affects
NIS2 applies to essential and important entities in sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, postal and courier services, waste management, manufacturing, food production and distribution and digital services.
Within these categories, essential entities are medium-sized and large companies. Micro-enterprises and small companies may be exempt, although if they are critical suppliers of essential entities, the requirement extends indirectly.
How to implement a VDP to comply with NIS2
To comply with the NIS2 disclosure requirement, a VDP must include:
1. Published and accessible responsible disclosure policy.
2. Report reception channel (email, form, platform).
3. Acknowledgment process within 72 hours.
4. Validation and resolution process for reported vulnerabilities.
5. Notification process to INCIBE-CERT for significant vulnerabilities.
6. Documentation of the process for compliance audits.
The reference standard for implementing the VDP is ISO 29147 (coordinated vulnerability disclosure), which is compatible with NIS2 requirements.
NIS2 and bug bounty: do I also need a bug bounty?
NIS2 does not require a bug bounty with monetary rewards. A VDP (without rewards) is sufficient to comply with the directive's disclosure requirement.
However, many companies that implement a VDP for NIS2 discover that the report management process it establishes is the same as what they would need for a bug bounty. The difference is only the bounty budget. If you already have the process, adding a bug bounty is a small step with a significant impact on the quality of findings received.
FAQ
When did NIS2 come into force in Spain?
NIS2 had to be transposed into national law by EU Member States by 17 October 2024. Spain is in the process of transposition. Although the specific national law may be pending, affected companies should be aligning their controls with the directive's requirements, as the formal transposition does not change the substantive obligations.
What is INCIBE-CERT and what does it have to do with the VDP?
INCIBE-CERT is the security incident response team of Spain's National Cybersecurity Institute. NIS2 establishes that essential and important entities must notify their national CSIRT (INCIBE-CERT in the case of Spain) of significant vulnerabilities. A well-implemented VDP includes the coordination process with INCIBE-CERT.
Can I outsource the management of the VDP required by NIS2?
Yes. You can outsource the management of the reception channel, report triage and researcher communication to a specialist provider. Compliance responsibility remains with the company, but the provider handles the operations. This is a common solution for companies without a dedicated security team.