Compliance — NIS2 Directive
NIS2 Article 23 incident reporting — 24 hours, 72 hours, one month
NIS2 requires essential and important entities to notify their national CSIRT within 24 hours of a significant incident, with a full report within 72 hours. ManySignal detects significant incidents, classifies them automatically, and generates all three Article 23 notification documents from a single incident record.
18
Sectors covered by NIS2 essential and important entity obligations
24 hrs
Early warning to national CSIRT or competent authority
72 hrs
Full incident notification with initial assessment
1 month
Final incident report deadline — root cause and remediation required
Control mapping — NIS2 to ManySignal
| NIS2 Article | Requirement | ManySignal Capability |
|---|---|---|
| Art. 21(2)(b) | Incident Handling | Automated incident lifecycle — detection, classification as significant/non-significant, evidence collection, and timeline documentation |
| Art. 21(2)(g) | Basic Cyber Hygiene and Training | Monitoring evidence for cyber hygiene controls — patch application detection, MFA enforcement monitoring |
| Art. 23(1) | 24-hour Early Warning | Significant incident detection with automated 24-hour CSIRT/CA notification draft generation |
| Art. 23(3) | 72-hour Incident Notification | Full incident notification package — classification, initial assessment, affected services, and technical indicators |
| Art. 23(4) | Final Report — 1 month | Post-incident final report generation with full timeline, root cause, and remediation evidence |
| Art. 21(2)(d) | Supply Chain Security | Third-party and vendor access monitoring — anomalous vendor credential usage and scope violations |
| Art. 21(2)(e) | Security in Network Acquisition and Development | Change monitoring — network and system configuration changes correlated with security impact assessment |
| Art. 21(2)(f) | Policies on Access Controls and Asset Management | Access control monitoring, asset discovery, and privilege management anomaly detection |
Article 23 notification workflow
24-hour early warning
ManySignal detects a significant incident. Case classified as NIS2-reportable. Early warning draft generated — incident timestamp, type, and initial impact assessment. Sent to your national CSIRT contact via pre-configured notification.
72-hour notification
Full incident notification package compiled from case evidence — initial severity assessment, affected services, technical indicators (IOCs), and immediate containment actions taken. Formatted for your national CSIRT reporting template.
1-month final report
Post-incident final report with root cause analysis, complete attack timeline, cross-border impact assessment, remediation actions, and future mitigation measures. ENISA-aligned format.
NIS2 compliance — common questions
Which entities are subject to NIS2?
NIS2 (Directive 2022/2555) covers essential entities and important entities in 18 sectors. Essential entities include: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include: postal services, waste management, chemicals, food, manufacturing (medical devices, vehicles, electronics), digital providers (online marketplaces, search engines, social networks), and research. Size thresholds apply for most sectors.
What is the difference between the 24-hour early warning and 72-hour notification under NIS2 Article 23?
The 24-hour early warning (Article 23(1)) is a preliminary notification to the national CSIRT or competent authority — it can be brief and does not need to be complete. The 72-hour notification (Article 23(3)) must include: the initial assessment of the incident, severity, impact, and indicators of compromise. The final report (Article 23(4)) is due within one month and must include root cause, remediation, and cross-border impact assessment. ManySignal generates all three documents from the same incident record.
How does ManySignal determine if an incident is 'significant' under NIS2?
NIS2 Article 23(3) defines a significant incident as one that: has caused or is capable of causing severe operational disruption, financial loss, or substantial damage to individuals. ENISA and national competent authorities have published additional sector-specific significance criteria. ManySignal's incident classification engine applies NIS2 significance criteria — including service disruption duration thresholds, affected user count, and financial impact estimates — and flags incidents that likely meet the 'significant' threshold for analyst confirmation.
Which national CSIRT or competent authority should our organisation notify under NIS2?
Each EU member state designates one or more national CSIRTs and competent authorities for NIS2 reporting. Examples: CERT-FR / ANSSI (France), BSI / CERT-Bund (Germany), NCSC-IE (Ireland), CSIRT-IT / ACN (Italy), CCN-CERT / INCIBE (Spain). ManySignal's incident management allows customers to configure their applicable national authority and pre-populate the reporting contact and reporting format for that authority.
Does NIS2 require penetration testing, and does ManySignal help with this?
NIS2 Article 21(2)(m) requires entities to use multi-factor authentication and continuous authentication solutions. Article 21(2)(n) requires use of encryption. NIS2 does not explicitly mandate penetration testing, but ENISA guidelines recommend regular security assessments. ManySignal integrates with penetration testing results (via import of findings as detection rules) and provides continuous monitoring evidence that complements scheduled assessments.
Deploy NIS2-ready monitoring in the EU
Configure your sector-specific NIS2 significant incident thresholds, national CSIRT notification contacts, and evidence export format — all in your first deployment session.