What information must be included in an early warning of a significant incident?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive establishes specific information that must be included in an early warning of a significant incident. Article 23, Paragraph 4(a) states that entities must submit an early warning to their CSIRT (Computer Security Incident Response Team) or the competent national authority “without undue delay and, in any event, within 24 hours” after becoming aware of a significant incident.

This early warning must include, where applicable:

  • Suspected unlawful or malicious activity: If the entity suspects that the incident was caused by illegal or malicious actions, this must be clearly indicated in the early warning.
  • Potential cross-border impact: The entity must specify whether the incident could affect individuals or organizations in other EU Member States.

Considerations on the purpose of the early warning

Sources highlight that the primary objective of an early warning is to provide a rapid alert to the competent authorities. Therefore, while speed is essential, in-depth details about the incident are not required at this stage. The focus must be on reporting the incident quickly and indicating potential areas of concern (such as criminal activity or cross-border effects). For an in-depth look at the relevant regulatory framework, it is useful to consult the official NIS2 Directive document.

Additional information to facilitate assistance

Although not explicitly required by Article 23, Paragraph 4(a), the Commission’s Communication clarifies that submitting an early warning allows affected entities to request assistance from their CSIRT or competent authority. To facilitate this assistance, it is advisable to include the following information in the early warning, even if not strictly mandatory:

  • Brief description of the incident: Providing a concise overview of what happened can help the CSIRT or authority quickly understand the nature of the situation.
  • Initial impact assessment: If possible, it is useful to provide a preliminary assessment of the severity and potential impact of the incident, but a detailed analysis is not expected at this stage.
  • Specific assistance requested: By clearly indicating the type of assistance the entity needs (e.g., guidance on mitigation measures or operational support), the CSIRT or authority will be able to respond more effectively.

By including this additional information, even in a summary format, entities can optimize the early warning process and enable more effective support from designated cybersecurity authorities. Managing these obligations correctly requires organizational preparation that goes well beyond a single incident: a structured NIS2 Directive compliance path helps define clear procedures, roles, and notification channels before a critical event occurs. The correct designation of the CSIRT contact person is also an integral part of this preparation.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In