What are the requirements for CSIRTs to ensure high availability of their communication channels?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive establishes specific requirements for Computer Security Incident Response Teams (CSIRTs) to ensure the high availability of their communication channels. These requirements focus on redundancy, diversification, and clear communication with stakeholders.

According to Article 11, Paragraph 1(a) of the NIS2 Directive, CSIRTs must:

  • Ensure a high level of availability of their communication channels: This underscores the crucial role of reliable communication in incident response.
  • Avoid single points of failure: CSIRTs should implement redundant systems and procedures to prevent a single point of failure from disrupting communication. This could include the use of multiple communication channels, backup systems, and diversified infrastructure.
  • Maintain various means to be contacted and to contact others at any time: CSIRTs should offer different ways to allow entities to report incidents, request assistance, and receive updates. This could include telephone lines, email addresses, web portals, and dedicated secure communication platforms.
  • Clearly indicate and publicize communication channels: CSIRTs must provide clear and accessible information about their communication channels to their user base and partners. This transparency ensures that entities know how to contact the CSIRT in the event of an incident. Publication could be facilitated through websites, public awareness campaigns, and stakeholder engagement forums.

These requirements highlight the importance of a robust and resilient communication infrastructure for effective incident response. By implementing redundant systems, diversified communication channels, and transparent communication practices, CSIRTs can ensure they are reachable and can effectively coordinate responses even during a major cybersecurity incident. For organizations that need to verify their position regarding these obligations, a structured NIS2 compliance path helps map applicable requirements and define concrete actions to take. Further details on designation obligations towards CSIRTs are available in the article on the designation of the CSIRT representative for NIS entities and in the one on the distinction between the point of contact and the CSIRT representative in ACN Determination no. 333017/2025.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In