NIS2 Directive: To whom must incidents be reported?

Direttiva NIS2 Frequently Asked Questions

Regulations, in particular the European Union (EU) legislation establishing the NIS2 Directive, describe to whom entities must report significant incidents that occur within their digital infrastructure.

  • Entities classified as essential or important are required to report significant incidents to their designated Computer Security Incident Response Team (CSIRT) or, where appropriate, to the competent national authority. This reporting mechanism aims to ensure a rapid and coordinated response to cybersecurity incidents across the EU. To learn more about the obligations related to the contact person, it is also useful to read the obligation to designate a CSIRT contact person for NIS subjects.
  • The legislation emphasizes the importance of the initial assessment carried out by the entity concerned to determine whether an incident is significant enough to warrant reporting. This assessment should take into account the criticality of the systems involved in providing the entity’s services, the severity and nature of any cyber threats, as well as the entity’s previous experience with similar incidents.
  • In addition to reporting significant incidents to their CSIRT or competent national authority, entities are required to also inform the recipients of their services if the incident is likely to adversely affect the provision of those services.

NIS2 Directive: Important considerations for reporting

  • The legislation emphasizes a multi-stage approach to incident reporting, which involves sending an early warning, a formal incident notification, and a final report. This approach aims to balance the need for timely reporting, to reduce potential widespread impacts, with the need for detailed reports that facilitate learning from individual incidents.
  • The early warning must be submitted within 24 hours of becoming aware of a significant incident. Subsequently, a formal incident notification is required within 72 hours. Finally, a final report must be submitted within one month of the initial notification, unless the incident is still ongoing; in that case, a progress report must be sent, followed by a final report within one month of the incident’s resolution. However, trust service providers must report significant incidents within 24 hours of becoming aware of them, without exception.
  • The regulations also emphasize that the mere act of reporting an incident does not expose the reporting entity to increased legal liability. This provision encourages transparency and the timely reporting of cybersecurity incidents without fear of repercussions.

Overall, the regulation highlights the crucial role of reporting in establishing robust cybersecurity practices across the EU. By clearly defining reporting lines and emphasizing the importance of timely and comprehensive information sharing, the NIS2 Directive aims to strengthen the collective cyber resilience of essential and important entities. For organizations that have yet to structure or verify their NIS2 Directive compliance path, it is also useful to consult the ACN guidelines on deadlines and registration for the NIS2 list.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In