The NIS2 Directive defines several minimum requirements for Computer Security Incident Response Teams (CSIRT). These requirements cover various aspects, including communication, infrastructure, technical capabilities, and operational tasks.
Communication and Availability:
- Multiple Communication Channels: CSIRTs must ensure high availability of communication channels and avoid single points of failure. They should provide various methods for entities to contact them and vice versa, ensuring constant accessibility.
- Clear Communication Channels: The chosen communication channels must be clearly identified and made known to the CSIRT’s user base and partners. This transparency ensures that entities can easily reach the CSIRT when necessary.
Security and Infrastructure:
- Secure Location: CSIRTs must operate from secure locations, protecting their physical premises and IT systems from unauthorized access, environmental threats, and other risks.
- Secure and Resilient Infrastructure: A dedicated, secure, and resilient communication and information infrastructure is crucial for CSIRTs to exchange information with essential and important entities and stakeholders. This infrastructure should facilitate secure and reliable communication, resisting disruptions.
- Secure Information Sharing Tools: Member States are required to ensure that their CSIRTs contribute to the development of secure information-sharing tools. This collaborative effort aims to establish trusted mechanisms for the exchange of sensitive cybersecurity information.
Technical Capabilities and Resources:
- Adequate Resources: Member States have an obligation to allocate sufficient resources to their CSIRTs, enabling them to effectively perform their tasks. These resources include personnel, funding, and technical infrastructure.
- Collective Technical Expertise: Member States must ensure that their designated CSIRTs collectively possess the technical capabilities necessary to perform their duties as outlined in Article 11(3) of the NIS2 Directive. This requires providing CSIRTs with sufficient resources for training and development to enhance their technical competence.
Operational Tasks and Responsibilities:
- Monitoring and Analysis: CSIRTs are tasked with monitoring and analyzing cybersecurity threats, vulnerabilities, and incidents at the national level. They should provide assistance to essential and important entities, upon request, to support real-time or near-real-time monitoring of their network and information systems.
- Early Warning and Alerts: CSIRTs play a critical role in issuing early warnings, alerts, and bulletins. They must disseminate information regarding cybersecurity threats, vulnerabilities, and incidents to relevant stakeholders, including essential and important entities, competent authorities, and other interested parties, in a timely manner, ideally in near-real-time.
- Incident Response and Support: When incidents occur, CSIRTs are expected to provide a coordinated response. They should offer assistance to affected essential and important entities, helping them mitigate the impact of incidents and restore normal operations.
- Forensic Analysis and Situational Awareness: CSIRTs are responsible for collecting and analyzing forensic data following incidents. This analysis contributes to a dynamic understanding of risks and incidents and helps maintain overall situational awareness regarding cybersecurity.
- Proactive Vulnerability Scanning: Upon request, CSIRTs should be able to conduct proactive scans of the network and information systems of essential or important entities. These scans aim to identify vulnerabilities that could have a significant impact if exploited.
- Collaboration and Mutual Assistance within the CSIRT Network: CSIRTs are required to actively participate in the CSIRT Network, promoting collaboration and providing mutual assistance to other members based on their capabilities and expertise. This collaborative approach enhances the overall resilience of the network and enables a more coordinated and effective response to cybersecurity incidents. For NIS entities, the Directive also provides for the obligation to designate a CSIRT contact person, a figure distinct from the general point of contact.
- Coordinated Vulnerability Disclosure: CSIRTs can act as coordinators for vulnerability disclosure, serving as trusted intermediaries between those who report vulnerabilities and the manufacturers or ICT service providers of potentially vulnerable products.
Additional Requirements:
- Request Management: CSIRTs should have a system to efficiently manage and escalate received requests, particularly during cybersecurity incidents. This ensures a streamlined approach to handling requests for information and assistance.
- Confidentiality and Reliability: Maintaining confidentiality and ensuring operational reliability are fundamental for CSIRTs. This involves protecting sensitive information, adhering to data protection regulations, and maintaining consistent and reliable services.
- Staffing and Competence: CSIRTs should be adequately staffed to provide continuous service and ensure 24/7 availability. Furthermore, staff members should receive appropriate training to develop the skills necessary to effectively handle their tasks. It is worth noting that the distinction between the point of contact and the CSIRT contact person introduced by ACN Determination no. 333017/2025 clarifies the internal roles that organizations must manage.
- Redundancy and Backup: Implementing redundancy measures and having backup workspaces are crucial for CSIRTs to maintain operational continuity during disruptions. This includes backup systems, alternative communication channels, and offsite data storage.
- International Cooperation: CSIRTs are encouraged to establish cooperative relationships with their counterparts in other countries, particularly with National CSIRTs in third countries. This collaboration aims to facilitate information exchange, share best practices, and strengthen global cybersecurity efforts.
Risk-Based Prioritization:
The sources emphasize that CSIRTs can prioritize their tasks based on a risk-based approach. This flexibility allows them to allocate resources and focus on the most critical activities based on the evolving threat landscape and the potential impact of incidents. This risk-based prioritization ensures a more efficient use of resources and a more effective response to the most urgent cybersecurity challenges.
The sources also note that the requirements for CSIRTs are in addition to any existing national or EU legislation on data protection and the safeguarding of classified information. For organizations that need to verify their scope of application and initiate a structured path to compliance, the NIS2 Directive compliance support offered by ISGroup covers both the initial assessment and the implementation of the required measures. Further details on deadlines and how to register for the ACN list are available in the article dedicated to ACN and the NIS2 list.
Frequently Asked Questions about CSIRT requirements in NIS2
- Do all NIS2 subjects need to have their own internal CSIRT?
- No. The NIS2 Directive provides that national CSIRTs are established by Member States. Essential and important entities are not required to create an autonomous internal CSIRT, but they must be able to interact with the reference national CSIRT and comply with incident notification obligations. Some large organizations choose to equip themselves with internal incident response capabilities anyway.
- What is the difference between the CSIRT contact person and the NIS2 point of contact?
- These are two distinct figures. The point of contact is the organization’s representative to the competent authorities for general communications related to NIS2. The CSIRT contact person is the person designated for operational interactions with the national CSIRT in the event of an incident. ACN Determination no. 333017/2025 has clarified this distinction and the related designation obligations.
- How does an organization subject to the Directive concretely start a NIS2 compliance path?
- The starting point is to verify whether the organization falls within the NIS2 scope and proceed with registration in the ACN list by the established deadlines. Subsequently, it is necessary to conduct a risk assessment, identify the security measures to be implemented, and define incident notification procedures. A structured path also includes staff training and periodic review of the measures adopted.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
