What are the minimum requirements for incident reporting under the NIS2 Directive?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive outlines a multi-stage approach for incident reporting by entities designated as “essential” or “important,” requiring them to provide timely and comprehensive information to the competent authorities.

Here are the minimum requirements:

1. Early Warning (Within 24 Hours)

Trigger: An essential or important entity must submit an early warning to its national Computer Security Incident Response Team (CSIRT) or national competent authority “without undue delay, and in any event within 24 hours” of becoming aware of a “significant incident.”

Content:

  • This early warning should, “where applicable,” indicate whether the incident:
    • Is suspected of being the result of unlawful or malicious acts, or
    • Could have a cross-border impact.
  • According to Recital 102, the early warning should contain only the information necessary to inform the CSIRT or competent authority that a significant incident has occurred or is ongoing.
  • Purpose:
  • Allow authorities a rapid assessment of the situation.
  • Provide the affected entity with the opportunity to request assistance, guidance, or operational advice on the implementation of mitigation measures.

2. Incident Notification (Within 72 Hours)

Trigger: Following the early warning, the entity must submit a more detailed incident notification.

Timing: This notification must be submitted “without undue delay, and in any event within 72 hours” of the entity becoming aware of the significant incident.

Content:

  • This notification should, “where applicable,” update the information provided in the early warning.
  • It should also include an initial assessment of the incident, including:
    • Its severity,
    • Its impact, and
    • Where available, indicators of compromise.

3. Final Report (Within One Month)

Trigger: The final stage of incident reporting is the submission of a comprehensive final report.

Timing: This report must be submitted “within one month” of the submission of the incident notification.

Content: The final report must include:

  • A detailed description of the incident, including its severity and impact,
  • The type of threat or root cause that likely triggered the incident,
  • Mitigation measures taken and ongoing, and
  • Where applicable, the cross-border impact of the incident.

Ongoing Incidents: If the incident is still ongoing when the final report is due, the entity must:

  • Provide a progress report at that time, and
  • Submit a final report within one month of the resolution of the incident.

4. Additional Requirements and Considerations

Significant Incident: Reporting requirements are triggered by “significant incidents.” An incident is considered significant if it meets one of the following criteria:

  • It has caused or is capable of causing a substantial disruption in the provision of the entity’s services or a financial loss for the entity, or
  • It has had or is capable of having a substantial impact on other natural or legal persons, resulting in considerable material or non-material damage.

Vulnerability Disclosure: The NIS2 Directive introduces a coordinated vulnerability disclosure process through a designated CSIRT, facilitating communication between those who discover vulnerabilities and the affected ICT product/service providers. This process aims to address vulnerabilities promptly and minimize their potential impact.

Information Sharing: Essential and important entities are encouraged to establish agreements for sharing cybersecurity information, including threats, incidents, and best practices, to promote a more proactive and collaborative approach to cybersecurity.

The NIS2 Directive’s incident reporting requirements emphasize a proactive and multi-layered approach to information sharing and incident response. By providing timely and comprehensive reports to authorities, organizations contribute to a more robust cybersecurity posture across the EU.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!

In