The NIS2 Directive recognizes the increasingly interconnected nature of digital systems and the potential cross-border impact of cybersecurity incidents. It establishes several mechanisms to facilitate cooperation and coordinated actions among Member States in addressing such incidents. For organizations falling within the scope, understanding these obligations is the first step toward a structured NIS2 compliance path.
Notification of cross-border impacts
- The Directive emphasizes the importance of promptly notifying relevant parties in the event of significant cybersecurity incidents, particularly those with potential cross-border impacts.
- Article 23 of the Directive requires essential and important entities to include information on any cross-border impacts in the incident notifications sent to their CSIRT or competent authority.
- This information helps CSIRTs and competent authorities assess the scale of the incident and determine whether it is necessary to activate cross-border cooperation.
NIS2 Directive: Information sharing and cooperation
- The NIS2 Directive promotes information sharing and cooperation among Member States at various levels.
- Cooperation Group: The Directive establishes a Cooperation Group, composed of representatives from the competent authorities of each Member State, to support and facilitate strategic cooperation and information exchange.
- This Group plays a key role in developing a common understanding of cyber threats and vulnerabilities, sharing best practices, coordinating policy responses, and strengthening trust among Member States.
- CSIRTs Network: The Directive creates a network of national CSIRTs to promote rapid and effective operational cooperation.
- This network facilitates the exchange of technical information on incidents, vulnerabilities, and mitigation measures, and supports Member States in managing cross-border incidents.
- The network also establishes procedures for requesting and providing mutual assistance among Member States in incident management.
- Single Points of Contact (SPOCs): Each Member State is required to designate a Single Point of Contact (SPOC). The SPOC serves as the central liaison point for cross-border cooperation on cybersecurity matters.
- SPOCs facilitate communication and coordination between competent authorities, CSIRTs, and other relevant bodies, both within the EU and with third countries and international organizations.
- EU-CyCLONe: The Directive establishes the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) to support the coordinated management of large-scale cybersecurity incidents and crises at the operational level.
- EU-CyCLONe brings together representatives from Member States’ cyber crisis management authorities. The goal is to facilitate information exchange, coordinate response activities, and support decision-making during major incidents.
Mutual assistance
- The NIS2 Directive provides for mutual assistance among Member States in investigation and response activities for cybersecurity incidents.
- Article 37 allows a competent authority of one Member State to request assistance from another Member State in cases where:
- An entity provides services in multiple Member States.
- An entity’s information systems and networks are located in multiple Member States.
- The requesting authority may ask for assistance in gathering information, conducting investigations, taking enforcement actions, and other incident-related activities.
- The requested authority must provide assistance unless it deems that it lacks jurisdiction, that the request is disproportionate, or that it is contrary to its fundamental national interests.
Joint supervisory actions
- The NIS2 Directive provides for the possibility of conducting joint supervisory actions among the competent authorities of different Member States in certain circumstances.
- When an entity is established in multiple Member States, the competent authorities of those States must cooperate, provide mutual assistance, and may carry out joint supervisory actions.
- This provision aims to ensure consistent application of the Directive’s requirements for entities operating cross-border.
NIS2 Directive: Other cooperation mechanisms
- In addition to the specific mechanisms described above, the NIS2 Directive encourages broader cooperation among Member States on cybersecurity.
- The Directive promotes the exchange of best practices, the development of joint training and exercise programs, and the creation of bilateral or multilateral agreements to strengthen cybersecurity cooperation.
The NIS2 Directive establishes a comprehensive framework for addressing cross-border cybersecurity incidents and promoting cooperation among Member States. By strengthening notification requirements, establishing dedicated cooperation mechanisms, and facilitating mutual assistance, the Directive aims to improve the EU’s collective ability to prevent, detect, and respond to cyber threats that transcend national borders. To delve deeper into the regulatory framework, the official NIS2 Directive document is available; for those who want to understand the origins of this structure, it is useful to start with what the main objective of the NIS2 Directive is. Italian organizations that still need to verify their status can consult the guidance on ACN and the list of NIS2 entities.
Frequently asked questions about NIS2 cross-border incident management
- What must an incident notification with cross-border impact include?
- According to Article 23 of the NIS2 Directive, the notification must contain specific information regarding any cross-border impacts of the incident. This data is used by the CSIRT or competent authority to assess whether to activate cooperation mechanisms with other Member States.
- Who is the Single Point of Contact (SPOC) and what is their role?
- Each Member State must designate an SPOC, which serves as the central liaison point for cross-border cybersecurity cooperation. The SPOC coordinates communication between competent authorities, CSIRTs, and other relevant entities, both within the EU and with third countries.
- What does EU-CyCLONe do and when is it activated?
- EU-CyCLONe (European Cyber Crisis Liaison Organisation Network) supports the coordinated management of large-scale cybersecurity incidents and crises at the operational level. It is activated in major scenarios, bringing together Member States’ cyber crisis management authorities to facilitate information exchange and coordinate responses.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
