The NIS2 Directive provides for a multi-stage approach for reporting significant incidents, emphasizing both speed and completeness. For organizations structuring their compliance plan, ISGroup’s NIS2 Directive compliance service supports the entire journey, from initial assessment to the implementation of required measures. To delve into the initial regulatory framework, it is useful to first clarify what the main objective of the NIS2 Directive is.
Here is a summary of the timelines:
1. Early Warning (Within 24 Hours)
- Article 23, paragraph 4(a): Entities must send an early warning to their CSIRT or competent national authority “without undue delay, and in any event within 24 hours” of becoming aware of a significant incident.
- Purpose: The early warning serves to quickly inform the competent authorities, even before a full assessment of the incident’s impact is possible.
- Content: The early warning does not require many details, but should, where applicable, indicate:
- Suspicious or malicious activity: Whether the incident is believed to be the result of malicious action.
- Cross-border impact: Whether the incident could affect people or organizations in other Member States.
- Request for assistance: The Commission’s communication emphasizes that sending an early warning allows the entities involved to request assistance from their CSIRT or competent authority, which may include guidance on mitigation measures or operational support. The procedures for designating the CSIRT contact person for NIS entities are defined by Italian implementing legislation.
2. Incident Notification (Within 72 Hours)
- Article 23, paragraph 4(b): Following the early warning, a more detailed incident notification must be sent “without undue delay, and in any event within 72 hours” of becoming aware of the incident.
- Content: The notification should expand on the information provided in the early warning and include:
- Updated information: Any new details that have emerged since sending the early warning.
- Initial assessment: A preliminary assessment of the significant incident, including:
- Severity: What was or could be the impact of the incident on the entity and potentially affected third parties?
- Impact: What are the specific consequences of the incident in terms of service disruption and potential damage (financial, reputational, etc.)?
- Indicators of Compromise (IoC): If available, technical details that can help identify the source or nature of the incident, such as malicious IP addresses or malware signatures.
3. Intermediate Report (Upon Request)
- Article 23, paragraph 4(c): The CSIRT or competent authority may request intermediate reports from the entity involved to provide updates on the situation.
- Purpose: This allows authorities to monitor the progress of the incident, assess any emerging risks, and coordinate response actions if necessary.
4. Final Report (Within One Month)
- Article 23, paragraph 4(d): A full final report must be submitted “within one month” of the initial incident notification.
- Content: The final report should include a detailed description of the incident, with:
- Detailed description: A complete explanation of the incident, including root causes, techniques used, affected systems, and a timeline of events.
- Severity and Impact: An in-depth analysis of the incident’s impact, based on the initial assessment provided earlier.
- Mitigation measures: A description of the actions taken to contain the incident, mitigate the effects, and prevent future similar events.
- Cross-border impact: If applicable, a detailed account of how the incident affected or could affect people or organizations in other Member States.
5. Ongoing Incidents
- Article 23, paragraph 4(e): If an incident is still ongoing when the one-month deadline for the final report expires, the entity must provide:
- Progress Report: An update on the current status of the incident and ongoing mitigation measures.
- Final Report (Within One Month of Resolution): Once the incident is resolved, the final report must be submitted within one month, following the same structure and content requirements described above.
Special Case: Trust Service Providers
- Article 23, paragraph 4 (last subparagraph): Trust service providers, due to the nature of their services, have tighter reporting timelines for significant incidents impacting their core services. They must inform their CSIRT or competent authority “without undue delay, and in any event within 24 hours” of becoming aware of the incident. This alignment follows the early warning timelines provided for other entities.
Key Points:
- Multi-stage: The reporting process under NIS2 is iterative, requiring entities to provide information in successive stages, starting with a rapid initial alert and concluding with a comprehensive final report.
- Focus on timeliness: Strict reporting deadlines underscore the importance of prompt action in response to significant incidents.
- Balance between speed and detail: While initial reports prioritize speed, subsequent reports place greater emphasis on detailed analysis and lessons learned.
- Support for cooperation and response: Reporting requirements are designed not only to inform authorities but also to facilitate cooperation, coordinate response efforts, and improve the overall cybersecurity posture. The full text of the obligations can be consulted in the official NIS2 Directive document.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
