Mutual Assistance

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Mutual Assistance

Member States shall establish mutual assistance processes. When an entity operates in multiple Member States or has systems located in different Member States, the authorities involved must cooperate and assist each other as needed. This includes informing and consulting each other about any supervisory or enforcement actions taken, one authority can request another to take specific supervisory or enforcement actions, authorities must assist each other by providing support proportionate to their resources to ensure effective and consistent measures.
The assistance can include information sharing, inspections, or audits. Authorities may refuse assistance only if they lack competence, if the request is disproportionate, or if it threatens national security or public safety. Before refusing, they must consult with other authorities, and, if needed, with the Commission and ENISA. Member States may also carry out joint supervisory actions by mutual agreement.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

CERT.be national and cross-border incident assistance: CERT.be provides Belgium’s standing mechanism for organisations to report cyber incidents and request technical and organisational assistance. It triages notifications, advises on containment and mitigation, may analyse system data with the organisation’s authorisation, and can exchange relevant indicators with Belgian or foreign authorities.

Sources:https://ccb.belgium.be/cert/report-incident
https://ccb.belgium.be/cert/incident-handling-cert-general-conditions

NCC-BE cybersecurity community and cooperation network: NCC-BE connects Belgian public authorities, industry, research organisations and academia with counterparts in Belgium and other EU Member States. As Belgium’s contact point for the European Cybersecurity Atlas and the NCC Network, it validates access for eligible organisations, forwards partnership and matchmaking requests and supports cross-border cooperation, knowledge exchange and participation in European cybersecurity initiatives.

Sources: https://ccb.belgium.be/ncc
https://ccb.belgium.be/ncc/cybersecurity_community
https://ccb.belgium.be/ncc/ncc-be-and-european-framework

Croatia flag
Croatia

Operational cyber mutual assistance under the Cybersecurity Act: Croatia's operational cross-border mutual-assistance mechanism, transposing NIS2 Art. 37. Where an entity operates or has systems in more than one Member State, NCSC-HR - as Croatia's designated single point of contact - informs, consults and assists the competent authorities of other Member States on supervisory/enforcement measures, may request another authority to act, and provides mutual assistance (information requests, on-site inspections, joint supervisory actions). NCSC-HR is the operational channel to the EU CSIRTs Network, EU-CyCLONe and the NIS Cooperation Group. 

Sources: https://ncsc.hr/en 
https://ncsc.hr/ 

Denmark flag
Denmark

CSIRT International Cooperation through the Danish Defence Intelligence Service: Denmark’s national CSIRT and Government CERT is placed in the Danish Defence Intelligence Service (DDIS). It provides warnings, threat information, incident handling support and cybersecurity services to government entities and operators of critical infrastructure, strengthening national incident preparedness and response capabilities.

Sources: https://tf-csirt.org/trusted-introducer/directory/teams/cfcs/
https://www.fe-ddis.dk/da/arbejdsomrade-a/Cybertruslen/

NOST — National Operational Staff: NOST is Denmark's highest operational crisis coordination forum. NOST is activated when Denmark is affected by incidents requiring cross-sector coordination, including extreme weather, pro longed power outages, serious accidents, cyber incidents or attacks on critical infrastructure.

Sources: https://samsik.dk/krisestyring/nost/
https://politi.dk/om-politiet/samarbejde/den-nationale-operative-stab-nost

New joint 24/7 situation centre: The Danish Government announced the establishment of a 24/7 situation centre linked to NOST, alongside a national cyber operations centre and cyber monitoring network. These measures aim to strengthen detection, coordination, response and crisis management for cyber and hybrid threats.

Sources: https://mssb.dk/nyheder/nyhedsarkiv/2025/december/regeringen-nyt-faelles-247-situationscenter-i-lyset-af-hybridkrig/
https://mssb.dk/media/ywqbp0rh/baggrundsnotat.pdf

Estonia flag
Estonia

Cyber reserve for national incident response: RIA maintains a three-tier reserve of cybersecurity experts for serious incidents. The first tier consists of RIA specialists, the second draws on experts from state IT organisations, and the third is provided by the Estonian Defence League Cyber Unit. The reserve enables rapid reinforcement when the affected organisation requires additional specialist capacity. 

Sources: https://www.ria.ee/en/estonias-cybersecurity-starts-you

Estonian Defence League Cyber Unit (Küberkaitseliit): The Estonian Defence League Cyber Unit contributes specialist personnel and operational support to national cyber preparedness. It works alongside RIA and other national actors in exercises, incident response coordination and resilience-building activities.

Sources: https://kaitseliit.ee/en/edl-units/

Finland flag
Finland

EU CSIRTs Network membership: Through the NCSC-FI, Finland participates in the EU CSIRTs Network, the operational cooperation network of national CSIRTs, which supports cross-border information exchange, coordinated handling of incidents and mutual assistance between Member States.

Sources: https://www.enisa.europa.eu/topics/eu-incident-response-and-cyber-crisis-management/csirts-network

Germany flag
Germany

EU CSIRTs Network membership: Through CERT-Bund, Germany is a member of the EU CSIRTs Network, the operational cooperation network of national CSIRTs and CERT-EU. The network supports information exchange, coordinated handling of cross-border incidents and mutual assistance between Member States.

Sources: https://www.enisa.europa.eu/topics/incident-response/csirts-in-europe/csirts-network 

Administrative CERT Network (Verwaltungs-CERT-Verbund): The VCV connects CERTs of the Federal Government and the Länder for operational information exchange, joint exercises and faster coordinated responses to IT attacks. Its members have explicitly agreed to provide mutual support during IT security incidents.

Sources: https://www.bsi.bund.de/EN/Themen/Oeffentliche-Verwaltung/Zusammenarbeit_mit_Bund_und_Laendern/bund-laender-zusammenarbeit_node.html 

Hungary flag
Hungary

Operational cyber mutual assistance: Hungary's operational cross-border mutual-assistance mechanism, transposing NIS2 Art. 37 into the Cybersecurity Act (Act LXIX of 2024). Where an entity operates or has systems in more than one Member State, , the National Cyber Security Centre of Hungary (NCSC HU), informs, consults and assists the competent authorities of other Member States on supervisory/enforcement measures, may request another authority to act, and provides mutual assistance (information requests, on-site inspections, joint supervisory actions). NCSC HU is the operational channel to the EU CSIRTs Network, EU-CyCLONe and the NIS Cooperation Group.

Sources: https://nki.gov.hu/intezet/nemzetkozi-kapcsolatok-egyuttmukodes/
https://en.nki.gov.hu/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00

National Cyber Security Centre (NCSC-HU)National Cyber Security Centre of Hungary (NCSC HU) serves as Hungary's responsible CSIRT for sectors covered by the NIS framework. The Centre supports cybersecurity cooperation, provides assistance during cyber incidents, and serves as a key coordination point for cybersecurity activities at national and international levels.

Source: https://en.nki.gov.hu/

Liechtenstein flag
Liechtenstein

CSIRT.LI: CSIRT.LI acts as the national CSIRT, the national cyber incident response coordinator and the international point of contact (PoC) within the NIS framework. It is connected to national and international CSIRTs/CERTs and supports incident handling through coordination, information exchange, warnings, alerts, consultation and referral to technical experts. Notifications of incidents may be exchanged with national and international authorities to support mitigation activities.

Sources: https://www.llv.li/en/national-administration/national-cyber-security-unit/csirt
https://www.llv.li/de/landesverwaltung/stabsstelle-cybersicherheit/csirt

Malta flag
Malta

CSIRT Malta incident coordination, assistance and cross-border cooperation: CSIRT Malta coordinates and responds to cybersecurity incidents, provides support and advice to affected entities, issues alerts and warnings, performs risk and incident analysis, and supports organisations in managing cyber threats, vulnerabilities and incidents. CSIRT Malta also participates in the EU CSIRTs Network and the European Cooperation Group, supporting information sharing, cross-border cooperation and mutual assistance activities with other Member States. 

Sources: https://maltacip.gov.mt/en/the-department/csirtmalta/ 
https://maltacip.gov.mt/dipartimenti/disclamer/ 

Netherlands flag
Netherlands

Cross-border mutual assistance through the EU CSIRTs Network: NCSC-NL can request and provide operational assistance through the EU CSIRTs Network when incidents have cross-border effects. Assistance may include technical information, coordination and support from peer national CSIRTs. Dutch responders get a route to European help when an incident crosses borders. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

Domestic detection assistance through the National Detection Network: Participants in the National Detection Network share technical information that can help other members identify and contain related threats. NCSC-NL coordinates the exchange and can turn individual findings into wider national awareness. The assistance is indirect but useful: one participant's detection can become another participant's early warning. 

Source: https://www.ncsc.nl/over-ons/versterkt-ncsc 

Sectoral CSIRT mutual support: Sectoral CSIRTs such as Z-CERT provide specialist support within their own communities and coordinate with NCSC-NL when an incident requires national or cross-sector assistance. The sectoral team contributes detailed operational knowledge, while NCSC-NL supports escalation and wider coordination. The model keeps specialist sector knowledge close to incidents while preserving a path to national escalation. 

Source: https://z-cert.nl/ 

Poland flag
Poland

National CSIRT incident coordination and mutual support: CSIRT NASK, CSIRT GOV and CSIRT MON coordinate incidents for their respective constituencies and may undertake joint action when an incident crosses institutional boundaries. They exchange information, develop common procedures and can allocate tasks among teams to provide coordinated assistance.

Sources: https://www.gov.pl/web/cyfryzacja/zespol-reagowania-na-incydenty-bezpieczenstwa-komputerowego-csirt
https://csirt.gov.pl/cee/

NCC-PL cybersecurity community and cooperation network: NCC-PL links government, industry, research and academia through Poland’s national cybersecurity competence community. As the national contact point for the ECCC and NCC Network, it supports partnership development, knowledge exchange and participation in national and cross-border initiatives.

Sources: https://www.gov.pl/web/cyber-nccpl/projekt-national-coordination-centre--poland-ncc-pl

Portugal flag
Portugal

Portuguese CSIRTs Network (Rede Nacional de CSIRT – RNCSIRT): RNCSIRT is Portugal’s operational forum for sharing incident information and coordinating response among CSIRTs from different sectors. The network establishes trusted relationships for cooperation and mutual assistance in incident handling, develops national incident indicators, supports proactive and reactive countermeasures, and creates instruments for prevention and rapid response during large-scale incidents. 

Sources: https://www.cncs.gov.pt/en/csirt/ 
https://www.redecsirt.pt/ 

CERT.PT: CERT.PT is Portugal's national cybersecurity incident response team, integrated within National Cybersecurity Centre (CNCS). It coordinates cybersecurity incident response involving public administration, essential and important entities, and the wider national cyberspace. CERT.PT also represents Portugal in the European CSIRTs Network. 

Sources: https://www.cncs.gov.pt/en/certpt/ 
https://www.cncs.gov.pt/pt/certpt/ 

Slovakia flag
Slovakia

SK-CERT Incident Coordination, Assistance and Cooperation: SK-CERT, operated by the National Security Authority, coordinates cybersecurity incident handling, receives incident reports, issues warnings and alerts, supports affected organisations, and provides assistance during cybersecurity incidents.

Sources: https://www.sk-cert.sk/en/about-us/index.html
https://www.sk-cert.sk/sk/o-nas/index.html
https://www.sk-cert.sk/en/news/index.html

Government CSIRT.SK: CSIRT.SK (Computer Incident Response Team) is part of Cyber Security department at the Ministry of Investment, Regional Development and Informatisation of the Slovak Republic. It provides services related to incident handling processes and restoration of the informational and communication systems in the public sector, and also offers preventive and educational services. The role and tasks of the teams are also embedded in the National Cybersecurity Act.

Historically, it was established by Resolution of the Government of the Slovak Republic No. 479/2009 of 1 July 2009

Sources:https://mirri.gov.sk/en/sections/informatization/csirt/about-csirt/
https://www.csirt.sk/o-nas.html

Slovenia flag
Slovenia

National Cyber Crisis Management Authority: URSIV serves as the competent authority for managing large-scale cyber incidents and cyber crises and coordinates national response efforts while linking Slovenia with international crisis-management mechanisms. 

Sources: https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/ 

EU Cyber Crisis Management Blueprint: Slovenia supports and implements the EU Cyber Crisis Management Blueprint (Cyber Blueprint), which defines cooperation procedures, activation thresholds, crisis protocols, information-sharing arrangements and coordinated response processes between Member States and EU institutions. 

Sources: https://www.gov.si/novice/2025-06-11-eu-sprejela-priporocilo-sveta-o-nacrtu-eu-za-krizno-upravljanje-na-podrocju-kibernetske-varnosti/ 

Single Point of Contact for Cross-Border Cooperation: URSIV acts as Slovenia's cybersecurity single point of contact and facilitates cooperation with EU Member States, European CSIRT structures, international organisations and cross-border partners. 

Sources: https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/ 

Spain flag
Spain

INCIBE-CERT and CCN-CERT national incident-assistance functions: INCIBE-CERT provides incident-response and recovery assistance to businesses and citizens, while CCN-CERT performs the corresponding coordination role for public administrations and organisations within its remit. Their standing reporting and support channels allow affected organisations to request technical help, exchange incident information and coordinate handling across responsible parties. 

Sources: https://www.incibe.es/en/incibe-cert/publications/guides-and-studies/guides/spanish-national-guidelines-reporting-and-managing-cyber-incidents 
https://www.ccn-cert.cni.es/en/incident-management.html 

NCC-ES cybersecurity community and cooperation network: NCC-ES gives Spanish businesses, public bodies, researchers and academia a structured route into the European cybersecurity competence ecosystem. It builds a national cooperation community, enables cross-border partnerships and helps organisations access European projects and knowledge networks. 

Sources: https://www.incibe.es/en/ncc-es