NIS2 Recital 60
Member States, in cooperation with ENISA, should take measures to facilitate coordinated vulnerability disclosure by establishing a relevant national policy. As part of their national policy, Member States should aim to address, to the extent possible, the challenges faced by vulnerability researchers, including their potential exposure to criminal liability, in accordance with national law. Given that natural and legal persons researching vulnerabilities could in some Member States be exposed to criminal and civil liability, Member States are encouraged to adopt guidelines as regards the non-prosecution of information security researchers and an exemption from civil liability for their activities.
NIS2 is a Directive: the binding obligations live in each Member State's transposing national law, and this is the EU Directive text those laws implement.
Source text: EUR-Lex, Official Journal HTML (CELEX 32022L2555). The parser was validated against the anchor articles verified in REP-08.