The requirements and tasks of CSIRTs shall be adequately and clearly defined and supported by national policy and/or regulation. They shall include the following:


Requirements for CSIRTs:


CSIRTs shall ensure a high level of availability of their communications services by avoiding single points of failure, and shall have several means for being contacted and for contacting others at all times. Furthermore, the communication channels shall be clearly specified and well known to the constituency and cooperative partners.


CSIRTs' premises and the supporting information systems shall be located in secure sites.


Business continuity:


CSIRTs shall be equipped with an appropriate system for managing and routing requests, in order to facilitate handovers.


CSIRTs shall be adequately staffed to ensure availability at all times.


CSIRTs shall rely on an infrastructure the continuity of which is ensured. To that end, redundant systems and backup working space shall be available.


CSIRTs shall have the possibility to participate, where they wish to do so, in international cooperation networks.


CSIRTs' tasks:


CSIRTs' tasks shall include at least the following:


monitoring incidents at a national level;


providing early warning, alerts, announcements and dissemination of information to relevant stakeholders about risks and incidents;


responding to incidents;


providing dynamic risk and incident analysis and situational awareness;


participating in the CSIRTs network.


CSIRTs shall establish cooperation relationships with the private sector.


To facilitate cooperation, CSIRTs shall promote the adoption and use of common or standardised practices for:


incident and risk-handling procedures;


incident, risk and information classification schemes.



SectorSubsectorType of entity



Electricity undertakings as defined in point (35) of Article 2 of Directive 2009/72/EC of the European Parliament and of the Councila, which carry out the function of ‘supply’ as defined in point (19) of Article 2 of that Directive

Distribution system operators as defined in point (6) of Article 2 of Directive 2009/72/EC

Transmission system operators as defined in point (4) of Article 2 of Directive 2009/72/EC


Operators of oil transmission pipelines

Operators of oil production, refining and treatment facilities, storage and transmission


Supply undertakings as defined in point (8) of Article 2 of Directive 2009/73/EC of the European Parliament and of the Councilb

Distribution system operators as defined in point (6) of Article 2 of Directive 2009/73/EC

Transmission system operators as defined in point (4) of Article 2 of Directive 2009/73/EC

Storage system operators as defined in point (10) of Article 2 of Directive 2009/73/EC

LNG system operators as defined in point (12) of Article 2 of Directive 2009/73/EC

Natural gas undertakings as defined in point (1) of Article 2 of Directive 2009/73/EC

Operators of natural gas refining and treatment facilities


(a)Air transport

Air carriers as defined in point (4) of Article 3 of Regulation (EC) No 300/2008 of the European Parliament and of the Councilc

Airport managing bodies as defined in point (2) of Article 2 of Directive 2009/12/EC of the European Parliament and of the Councild, airports as defined in point (1) of Article 2 of that Directive, including the core airports listed in Section 2 of Annex II to Regulation (EU) No 1315/2013 of the European Parliament and of the Councile, and entities operating ancillary installations contained within airports

Traffic management control operators providing air traffic control (ATC) services as defined in point (1) of Article 2 of Regulation (EC) No 549/2004 of the European Parliament and of the Councilf

(b)Rail transport

Infrastructure managers as defined in point (2) of Article 3 of Directive 2012/34/EU of the European Parliament and of the Councilg

Railway undertakings as defined in point (1) of Article 3 of Directive 2012/34/EU, including operators of service facilities as defined in point (12) of Article 3 of Directive 2012/34/EU

(c)Water transport

Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004 of the European Parliament and of the Councilh, not including the individual vessels operated by those companies

Managing bodies of ports as defined in point (1) of Article 3 of Directive 2005/65/EC of the European Parliament and of the Councili, including their port facilities as defined in point (11) of Article 2 of Regulation (EC) No 725/2004, and entities operating works and equipment contained within ports

Operators of vessel traffic services as defined in point (o) of Article 3 of Directive 2002/59/EC of the European Parliament and of the Councilj

(d)Road transport

Road authorities as defined in point (12) of Article 2 of Commission Delegated Regulation (EU) 2015/962l responsible for traffic management control

Operators of Intelligent Transport Systems as defined in point (1) of Article 4 of Directive 2010/40/EU of the European Parliament and of the Councilk


Credit institutions as defined in point (1) of Article 4 of Regulation (EU) No 575/2013 of the European Parliament and of the Councilm

4.Financial market infrastructures

Operators of trading venues as defined in point (24) of Article 4 of Directive 2014/65/EU of the European Parliament and of the Counciln

Central counterparties (CCPs) as defined in point (1) of Article 2 of Regulation (EU) No 648/2012 of the European Parliament and of the Councilo

5.Health sector

Health care settings (including hospitals and private clinics)Healthcare providers as defined in point (g) of Article 3 of Directive 2011/24/EU of the European Parliament and of the Councilp

6.Drinking water supply and distribution

Suppliers and distributors of water intended for human consumption as defined in point (1)(a) of Article 2 of Council Directive 98/83/ECq but excluding distributors for whom distribution of water for human consumption is only part of their general activity of distributing other commodities and goods which are not considered essential services

7.Digital Infrastructure


DNS service providers

TLD name registries



Online marketplace.


Online search engine.


Cloud computing service.