NIS2 Directive and voluntary cybersecurity reporting

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive promotes the voluntary reporting of cybersecurity information through a multifaceted approach, which includes clarifying reporting procedures, ensuring confidentiality, and emphasizing the benefits of information sharing. For an in-depth look at the regulatory text, the official document of the NIS2 Directive is available.

NIS2 Directive: Key provisions encouraging voluntary reporting

  • Article 30 of the NIS2 Directive clarifies that entities may voluntarily notify CSIRTs or national authorities.
  • Notifications may concern significant incidents, cyber threats, and near-misses detected by essential and important entities.
  • Even entities not subject to mandatory reporting requirements may communicate the same events, regardless of the Directive’s scope.
  • The Directive provides a process for handling voluntary notifications, similar to that for mandatory reporting under Article 23.
  • Member States may prioritize mandatory reports over voluntary ones.
  • Article 91 clarifies that voluntary reporting must not result in additional obligations for the entity.
  • This provision reduces concerns about potential negative consequences of disclosing information.
  • Article 29 encourages voluntary information sharing between entities.
  • The Directive promotes the creation of Cybersecurity Information Sharing Agreements.
  • These agreements allow for the exchange of data on threats, near-misses, vulnerabilities, attack techniques, and security practices.
  • The Directive encourages the formation of sharing communities in essential and important sectors.
  • Member States must facilitate these agreements with guidelines on operations, content, and conditions.
  • Essential and important entities must notify authorities of their participation in such agreements.
  • This obligation ensures transparency and promotes trust in the information-sharing system.
  • ENISA supports sharing through guidelines, best practice exchanges, and assistance in establishing agreements.

Other elements supporting voluntary reporting

  • The Directive promotes a cybersecurity culture, emphasizing the importance of training and awareness. It requires entities to provide cybersecurity training to their staff and encourages them to extend such training to all employees.
  • It establishes a framework for coordinated vulnerability disclosure across the EU, inviting individuals and organizations to report vulnerabilities in ICT products and services.
  • The creation of a European vulnerability database managed by ENISA provides a central repository for publicly known vulnerabilities, improving transparency and facilitating proactive security measures.

What this means in practice for organizations

The NIS2 Directive creates a secure environment conducive to information sharing: it clarifies reporting paths, ensures confidentiality, and highlights the collective benefits derived from proactively addressing cybersecurity challenges. For organizations that need to assess their scope of application or structure an adaptation plan, the NIS2 Directive compliance path offers structured support from the initial assessment to the implementation of required measures. For aspects related to the designation of contacts for the national CSIRT, the guide on the obligation to designate a CSIRT contact for NIS subjects is also useful.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In