nis2

Art. 21(2)(e)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (41)

Techniques referencing this article

  • Ground-software integrity, secure development of telemetry processors and dashboards, and disclosed-vulnerability handling on those services fall under Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance obligation.

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    addresses
    moderate
    direct

    Detector model training/packaging/promotion is part of the network-and-information-systems development/maintenance pipeline Art. 21(2)(e) governs, including disclosed-weakness handling on label-flipping and clean-label backdoor attacks.

  • DE-0007Evasion via RootkitST0006
    addresses
    high
    direct

    Kernel-syscall integrity, separation-kernel hardening, and FSW-API tamper detection are squarely Art. 21(2)(e)'s network-and-information-systems development/maintenance + vulnerability-handling obligation.

  • DE-0008Evasion via BootkitST0006
    addresses
    high
    direct

    Bootloader integrity, image-selection logic, device-tree handling, and recovery-mode images are network-and-information-systems development/maintenance artefacts; Art. 21(2)(e), including disclosed-vulnerability handling on the boot chain, is the obligation that governs them.

  • SDA software/ML-pipeline integrity (fusion/association code, detection models, ingest validators) is part of Art. 21(2)(e)'s network-and-information-systems development/maintenance + vulnerability-handling obligation, including disclosed weaknesses in those services.

  • DE-0012Component CollusionST0006
    addresses
    moderate
    direct

    Detection of cooperative-multi-component behaviour requires assurance disciplines (cross-component static analysis, behavioural fuzzing, integration-level vulnerability handling) Art. 21(2)(e)'s secure development/maintenance + disclosure obligation is meant to cover.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    high
    direct

    Patches to flight binaries, hot-patches in memory, and command-handler hooks are the integrity failures Art. 21(2)(e)'s secure development/maintenance and vulnerability-handling/disclosure obligation is meant to prevent and detect.

  • EX-0004Compromise Boot MemoryST0004
    addresses
    high
    direct

    Bootloaders, OTP fuses, boot configuration words, and non-volatile boot images are network-and-information-systems development/maintenance artefacts; Art. 21(2)(e), including disclosed-vulnerability handling on those mechanisms, is the obligation that governs their integrity.

  • Firmware images, programmable-logic bitstreams, and configuration blobs in non-volatile memory are squarely within Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance and vulnerability-handling obligation — particularly the disclosure of below-OS weaknesses traditional endpoint tooling misses.

  • EX-0005.01Design FlawsST0004
    addresses
    high
    direct

    Errata, undocumented test modes, and counter/timer rollovers are exactly the kind of disclosed-or-disclosable weaknesses Art. 21(2)(e)'s vulnerability handling and disclosure obligation requires the entity to track and remediate within its N+IS dev/maintenance posture.

  • EX-0009Exploit Code FlawsST0004
    addresses
    moderate
    inferred

    EX-0009 abuses coding defects and known component vulnerabilities to execute on-board; NIS2 21(2)(e) security in acquisition, development and maintenance including vulnerability handling governs this defect class.

  • EX-0009.01Flight SoftwareST0004
    addresses
    moderate
    inferred

    EX-0009.01 exploits flight-software implementation flaws to execute code or alter persistent parameters; NIS2 21(2)(e) security in development and maintenance including vulnerability handling governs this defect class.

  • EX-0009.02Operating SystemST0004
    addresses
    moderate
    inferred

    EX-0009.02 exploits operating-system weaknesses and exposed management consoles for kernel-level execution; NIS2 21(2)(e) security in development and maintenance including vulnerability handling governs this risk.

  • Vulnerability handling and disclosure under Art. 21(2)(e) is the precise obligation that requires the entity to track CPE/CVE matches against components on-board, monitor vendor advisories, and close the disclosure-to-patch lag the technique exploits.

  • EX-0010Malicious CodeST0004
    addresses
    high
    direct

    Native binaries, scripts, shellcode, and 'data payloads' delivered via update paths, file-transfer services, table loaders, or maintenance consoles all ride the network-and-information-systems acquisition/development/maintenance pipeline Art. 21(2)(e) governs, including disclosed-vulnerability handling on the parsers and loaders involved.

  • EX-0010.03RootkitST0004
    addresses
    high
    direct

    Separation-kernel/hypervisor integrity, syscall-hooking detection, and firmware-driver assurance are squarely Art. 21(2)(e)'s network-and-information-systems development/maintenance + vulnerability-handling obligation — including disclosed weaknesses in any of those layers.

  • EX-0010.04BootkitST0004
    addresses
    high
    direct

    Bootloader integrity, image-selection logic, and recovery-mode handling are network-and-information-systems development/maintenance artefacts; Art. 21(2)(e), including disclosed-vulnerability handling on the boot chain, is the obligation that governs them.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    moderate
    direct

    Model training, packaging, and uplink as routine updates are part of the network-and-information-systems acquisition/development/maintenance pipeline Art. 21(2)(e) governs, including disclosed-weakness handling for clean-label backdoors and label-flipping attacks.

  • EX-0015Side-Channel AttackST0004
    addresses
    moderate
    direct

    Hardening of SDR/FPGA pipelines, bootloaders, and bus controllers against fault injection is part of secure development and maintenance under Art. 21(2)(e), including disclosed-vulnerability handling on the side-channel/fault surface.

  • EXF-0002Side-Channel ExfiltrationST0008
    addresses
    moderate
    direct

    Hardening of crypto modules, SDR/FPGA pipelines, bus controllers, and bootloaders against side-channel leakage and fault injection is part of secure development and maintenance under Art. 21(2)(e), including disclosed-weakness handling on the side-channel surface.

  • EXF-0006.01Software Defined RadioST0008
    addresses
    moderate
    direct

    SDR DSP-chain modifications shipped as legitimate update profiles are a maintenance-pipeline attack; secure acquisition/development/maintenance and vulnerability handling under Art. 21(2)(e) cover the channel through which the change reaches the radio.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    high
    direct

    Embedding extended logging, telemetry taps, or 'export' features in test harnesses, simulators, or flight builds is exactly the integrity attack on the development pipeline Art. 21(2)(e)'s acquisition/development/maintenance and vulnerability-handling discipline is intended to detect and prevent.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    direct

    The technique targets sources, dependencies, build systems and CI/CD runners — the precise pipeline Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance obligation governs, including handling of disclosed weaknesses in those mechanisms.

  • Trust-on-first-use lock-ins on tainted packages, abuse of CI secrets, and compromised compilers are paradigmatic dev-pipeline failures Art. 21(2)(e)'s network-and-information-systems development-and-maintenance + vulnerability-handling obligation is meant to detect and remediate.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    direct

    Subverting update metadata, swapping signed binaries at distribution edges, and version-rollback attacks on flight tables are precisely the integrity failures Art. 21(2)(e)'s secure development/maintenance and vulnerability-handling/disclosure obligations are meant to catch.

  • Toolchains, out-of-tree modules, bitstream loading, and update channels for SDR waveforms are precisely the network-and-information-systems acquisition/development/maintenance pipeline Art. 21(2)(e) governs, including disclosed-vulnerability handling on the SDR stack.

  • IA-0007.01Compromise On-Orbit UpdateST0003
    addresses
    moderate
    inferred

    IA-0007.01 substitutes or modifies update artefacts in the build, packaging and staging pipeline before transmission to the vehicle; NIS2 21(2)(e) security in acquisition, development and maintenance governs the integrity of this pipeline.

  • ATLO is the late-stage network-and-information-systems acquisition/development/maintenance phase before flight; Art. 21(2)(e) — including disclosed-vulnerability handling — governs late firmware loads, key/counter initialisation, and configuration freezes that the technique exploits.

  • LM-0002Exploit Lack of Bus SegregationST0007
    addresses
    moderate
    direct

    Bus-controller hardening, gateway-bridge design discipline, and disclosed-weakness handling on broadcast-semantic protocols are part of Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance + vulnerability-handling obligation.

  • LM-0005Virtualization EscapeST0007
    addresses
    high
    direct

    Separation kernels, hypervisors, virtual NICs, IPC port services, and shared driver backends with IOMMU bounds are squarely within Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance and vulnerability-handling obligation — including disclosed parser flaws and racing-management-channel weaknesses.

  • PER-0001Memory CompromiseST0005
    addresses
    high
    direct

    Boot ROM handoff, first/second-stage loaders, golden fallback partitions, configuration words, and copy-on-boot logic are network-and-information-systems development/maintenance artefacts; Art. 21(2)(e), including disclosed-vulnerability handling on the persistence surface, is the obligation that governs them.

  • PER-0002BackdoorST0005
    addresses
    high
    direct

    Pre-existing service modes, debug features, and adversary-introduced backdoors are integrity failures Art. 21(2)(e)'s secure development/maintenance and vulnerability-handling/disclosure obligation is meant to catch — both in pre-flight assurance and through post-flight disclosure response.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    moderate
    direct

    Hardware-integrity assurance and firmware-level vulnerability handling are part of Art. 21(2)(e)'s network-and-information-systems acquisition/development/maintenance and vulnerability-handling/disclosure obligation.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    direct

    Hidden command handlers, alternate-authentication checks, special user/role constructs, and procedure/script hooks are integrity failures Art. 21(2)(e)'s secure development/maintenance and vulnerability-handling/disclosure obligation is meant to catch through code review, fuzzing, and disclosure response.

  • REC-0001.01Software DesignST0001
    addresses
    high
    direct

    Protection of source trees, binaries-with-symbols, command-handler implementations, bootloaders, and patch/update mechanisms is exactly what secure acquisition, development and maintenance under Art. 21(2)(e) requires, including vulnerability handling for the disclosed dependencies an SBOM exposes.

  • REC-0001.02FirmwareST0001
    addresses
    high
    direct

    Firmware update images, OTA bundles, secure-boot configuration, and anti-rollback policy live inside the network-and-information-systems development and maintenance pipeline that Art. 21(2)(e) explicitly governs, including handling of disclosed weaknesses in those mechanisms.

  • Cradle-to-operations protection of the FSW pipeline (architecture, source, build/sign/release, integration environments, autonomy rules) is exactly the network-and-information-systems acquisition/development/maintenance obligation in Art. 21(2)(e), including vulnerability handling on disclosed weaknesses.

  • REC-0006.01Development EnvironmentST0001
    addresses
    high
    direct

    Hardening of cross-compilers/SDKs, container images, build systems, branch protections, and CI orchestrators is exactly the secure development and maintenance posture Art. 21(2)(e) requires the entity to maintain.

  • REC-0006.02Security Testing ToolsST0001
    addresses
    high
    direct

    Static analysers, fuzzers, sanitisers, fault-injection rigs, and coverage gates are the assurance discipline secure development and maintenance under Art. 21(2)(e) — including disclosed-vulnerability handling — explicitly mandates.

  • REC-0008.02Software ReconST0001
    addresses
    high
    direct

    Software-factory hardening (repositories, build containers, package registries, signing services/HSMs, promotion gates) is the network-and-information-systems acquisition/development/maintenance posture Art. 21(2)(e) explicitly governs, including handling of disclosed weaknesses in those mechanisms.

  • REC-0008.03Known VulnerabilitiesST0001
    addresses
    high
    direct

    Vulnerability handling and disclosure under Art. 21(2)(e) is the precise obligation that requires the entity to track CPE/CVE matches against its components, monitor advisories, and close the disclosure-to-patch lag the technique exploits.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.