NIS2 Decree and CSIRT Point of Contact for significant incident management

Decreto NIS2 e Referente CSIRT gestione incidenti significativi

The implementation of Legislative Decree 138/2024 (NIS2 Decree) and the determinations of the National Cybersecurity Agency (ACN) introduces a structured and timed process for incident management, transforming this activity from reactive to governed. The CSIRT Contact Person, whose designation is mandatory by December 31, 2025, becomes the point of contact for all communications with CSIRT Italia, ensuring that every event follows a precise sequence of notification and analysis.

Significance threshold: when notification is mandatory

Not all IT anomalies require a report. The obligation to notify arises only in the presence of significant incidents as established by Article 25 of the NIS2 Decree. An incident is significant if it meets at least one of these criteria:

  • Operational disruption: causes or is capable of causing a severe disruption of the services provided by the organization.
  • Financial losses: causes significant economic damage to the victim.
  • Impact on third parties: generates significant repercussions, material or immaterial, on other natural or legal persons.

ACN Determination no. 164179/2025 identifies four main types of “basic significant incidents”:

  • IS-1 (Loss of confidentiality): unauthorized disclosure of digital data of the organization or controlled entities.
  • IS-2 (Loss of integrity): data tampering with external impact.
  • IS-3 (Violation of service levels): failure to meet established service levels for critical activities.
  • IS-4 (Abuse of privileges – Only for Essential Entities): unauthorized access or abuse of privileges regarding proprietary digital data.

The CSIRT Contact Person verifies whether the event falls into these categories and assesses whether it exceeds the thresholds provided by Article 25.

The notification cycle: phases and timelines

When a significant incident is recognized, the CSIRT Contact Person must perform the communication to CSIRT Italia while respecting precise deadlines from the moment the event becomes known.

Pre-notification (within 24 hours)

  • Must be sent within 24 hours.
  • Must certify that the incident is significant.
  • Indicates, if possible, whether the event is malicious in nature.
  • Assesses the presence of cross-border impacts.

Full notification (within 72 hours)

  • Must be transmitted within 72 hours (reduced to 24 for trust service providers).
  • Updates the information from the pre-notification.
  • Includes the initial assessment of severity and impact.
  • Provides Indicators of Compromise (IoCs), if available.

Intermediate reports and updates

  • Upon request by CSIRT Italia, intermediate reports may be required.
  • In the case of an incident lasting longer than a month, the regulations require monthly status reports until closure.

Final report (within one month)

  • Must be produced within 30 days of sending the full notification.
  • Describes the incident and root cause in detail.
  • Analyzes the threat or attack vector.
  • Reports the mitigation measures adopted and those in progress.
  • Presents the final assessment of the cross-border impact.

Voluntary notifications: leveraging information

Article 26 of the NIS2 promotes voluntary notifications. The CSIRT Contact Person may report the following to CSIRT Italia:

  • Non-significant but technically relevant incidents.
  • Cyber threats, even if the attack has not yet occurred.
  • Near-misses: potentially serious events that were intercepted or avoided.

Voluntary notifications do not entail additional burdens or sanctions, nor do they prejudice those who collaborate compared to those who do not.

Operational role of the CSIRT contact person

The CSIRT Contact Person, whose designation is mandatory by December 31, 2025, is the sole operational contact for interactions with CSIRT Italia. Their responsibilities are decisive during all phases:

  • Detection: analyzes alerts from the SOC or IT providers to validate whether it is a significant incident.
  • Response and investigation: coordinates the Incident Response Team (IRT), which includes legal, IT, DPO, and communication staff, ensuring the collection and preservation of evidence without risk of alteration.
  • Notification: sends data via the ACN portal, verifying the consistency between technical logs and legal qualification.
  • Recovery and improvement: contributes to the Post-Incident Report, identifying gaps in procedures and updating response playbooks, for example regarding ransomware or DDoS.

Governance, responsibility, and operational continuity

Legal responsibility for notification obligations remains with the management and administrative bodies, as provided by Article 23 of Legislative Decree 138/2024. The CSIRT Contact Person performs an exclusively operational and functional delegation.

Failure to comply with the timelines for pre-notification or the final report exposes the organization to administrative sanctions and inspections by the ACN. To ensure operational continuity even in the event of the contact person’s unavailability, the appointment of one or more substitutes with the same technical and authorization powers is strongly recommended.

Conclusion

Incident management according to NIS2 requires a CSIRT Contact Person capable of integrating technical skills and procedural precision, transforming regulatory compliance into a central element of the organization’s operational resilience.

Main sources:
Official Gazette

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!