Incident Management Requirements under NIS2

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive defines specific requirements for incident management, focusing on a multi-stage approach for reporting significant incidents. For an in-depth look at the regulatory text, the official document of the NIS2 Directive is available.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Here is a summary based on the provided information:

  • Initial Response (Early Warning): Essential and important entities are required to send an early warning to their CSIRT or competent national authority without undue delay and in any case within 24 hours of becoming aware of a significant incident. This early warning must include:
    • Confirmation of the significant incident.
    • Indication, if applicable, of whether the incident is suspected to be the result of illegal or malicious acts.
    • Preliminary assessment of whether the incident has or is likely to have a cross-border impact.
    • The early warning aims to enable a timely response and allows the entity concerned to request assistance, if necessary.
  • Formal Notification: Following the early warning, entities must submit a formal notification of the incident without undue delay and in any case within 72 hours of becoming aware of the incident. This notification must include:
    • Updates to the information provided in the early warning.
    • An initial assessment of the incident, including its severity and impact.
    • Indicators of compromise, if available.
  • Intermediate Report: A CSIRT or competent authority may request an intermediate report from the entity involved. This report provides relevant updates on the situation.
  • Final Report: A final report must be submitted to the CSIRT or competent authority within one month of the submission of the incident notification. This report must contain:
    • Detailed description of the incident, its severity, and its impact.
    • Analysis of the type of threat or root cause that likely triggered the incident.
    • Description of the mitigation measures taken and those still in progress.
    • Assessment of the cross-border impact of the incident, if applicable.
  • Ongoing Incident Reporting: If the incident is still ongoing at the time of the final report submission, the entity concerned must provide a status update report. A final report will then be due within one month of the resolution of the incident.
  • Special Case: Trust Service Providers: Trust service providers must comply with a shorter deadline for reporting incidents affecting their trust services. They must notify the CSIRT or competent authority without undue delay and in any case within 24 hours of becoming aware of the significant incident.
  • Information Sharing:
    • To ensure a coordinated response, especially for incidents involving multiple Member States, the CSIRT, competent authority, or single point of contact (SPOC) must inform other affected Member States and ENISA without undue delay.
    • Information sharing must protect the commercial interests of the entity involved and the confidentiality of the information provided, in accordance with EU or national law.
    • Public disclosure of the incident may be justified if considered necessary to protect the public or is in the public interest. This should be done in consultation with the entity concerned.
  • Support and Guidance: Once an early warning is received, the CSIRT or competent authority must acknowledge receipt and, if requested by the entity concerned, provide guidance or operational advice on possible mitigation measures. They may also offer further technical support upon request.
  • Reporting to Other Authorities:
    • CSIRTs or competent authorities must share information on significant incidents with relevant authorities under the CER Directive.
    • If a possible data breach is identified during incident management, competent authorities must inform data protection authorities as provided for by the GDPR.

The NIS2 Directive aims to simplify incident reporting and ensure a consistent approach across Member States, while allowing for some flexibility to address the specific circumstances of each incident. For organizations structuring their NIS2 compliance journey, translating these obligations into concrete operational procedures requires a precise analysis of their perimeter and internal processes. You can also learn more about what the main objective of the NIS2 Directive is to better frame the overall regulatory context.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In