M ManySignal

Compliance — NIS2 Directive

NIS2 Article 23 incident reporting — 24 hours, 72 hours, one month

NIS2 requires essential and important entities to notify their national CSIRT within 24 hours of a significant incident, with a full report within 72 hours. ManySignal detects significant incidents, classifies them automatically, and generates all three Article 23 notification documents from a single incident record.

18

Sectors covered by NIS2 essential and important entity obligations

24 hrs

Early warning to national CSIRT or competent authority

72 hrs

Full incident notification with initial assessment

1 month

Final incident report deadline — root cause and remediation required

Control mapping — NIS2 to ManySignal

NIS2 ArticleRequirementManySignal Capability
Art. 21(2)(b) Incident Handling Automated incident lifecycle — detection, classification as significant/non-significant, evidence collection, and timeline documentation
Art. 21(2)(g) Basic Cyber Hygiene and Training Monitoring evidence for cyber hygiene controls — patch application detection, MFA enforcement monitoring
Art. 23(1) 24-hour Early Warning Significant incident detection with automated 24-hour CSIRT/CA notification draft generation
Art. 23(3) 72-hour Incident Notification Full incident notification package — classification, initial assessment, affected services, and technical indicators
Art. 23(4) Final Report — 1 month Post-incident final report generation with full timeline, root cause, and remediation evidence
Art. 21(2)(d) Supply Chain Security Third-party and vendor access monitoring — anomalous vendor credential usage and scope violations
Art. 21(2)(e) Security in Network Acquisition and Development Change monitoring — network and system configuration changes correlated with security impact assessment
Art. 21(2)(f) Policies on Access Controls and Asset Management Access control monitoring, asset discovery, and privilege management anomaly detection

Article 23 notification workflow

24-hour early warning

ManySignal detects a significant incident. Case classified as NIS2-reportable. Early warning draft generated — incident timestamp, type, and initial impact assessment. Sent to your national CSIRT contact via pre-configured notification.

72-hour notification

Full incident notification package compiled from case evidence — initial severity assessment, affected services, technical indicators (IOCs), and immediate containment actions taken. Formatted for your national CSIRT reporting template.

1-month final report

Post-incident final report with root cause analysis, complete attack timeline, cross-border impact assessment, remediation actions, and future mitigation measures. ENISA-aligned format.

NIS2 compliance — common questions

Which entities are subject to NIS2?

NIS2 (Directive 2022/2555) covers essential entities and important entities in 18 sectors. Essential entities include: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include: postal services, waste management, chemicals, food, manufacturing (medical devices, vehicles, electronics), digital providers (online marketplaces, search engines, social networks), and research. Size thresholds apply for most sectors.

What is the difference between the 24-hour early warning and 72-hour notification under NIS2 Article 23?

The 24-hour early warning (Article 23(1)) is a preliminary notification to the national CSIRT or competent authority — it can be brief and does not need to be complete. The 72-hour notification (Article 23(3)) must include: the initial assessment of the incident, severity, impact, and indicators of compromise. The final report (Article 23(4)) is due within one month and must include root cause, remediation, and cross-border impact assessment. ManySignal generates all three documents from the same incident record.

How does ManySignal determine if an incident is 'significant' under NIS2?

NIS2 Article 23(3) defines a significant incident as one that: has caused or is capable of causing severe operational disruption, financial loss, or substantial damage to individuals. ENISA and national competent authorities have published additional sector-specific significance criteria. ManySignal's incident classification engine applies NIS2 significance criteria — including service disruption duration thresholds, affected user count, and financial impact estimates — and flags incidents that likely meet the 'significant' threshold for analyst confirmation.

Which national CSIRT or competent authority should our organisation notify under NIS2?

Each EU member state designates one or more national CSIRTs and competent authorities for NIS2 reporting. Examples: CERT-FR / ANSSI (France), BSI / CERT-Bund (Germany), NCSC-IE (Ireland), CSIRT-IT / ACN (Italy), CCN-CERT / INCIBE (Spain). ManySignal's incident management allows customers to configure their applicable national authority and pre-populate the reporting contact and reporting format for that authority.

Does NIS2 require penetration testing, and does ManySignal help with this?

NIS2 Article 21(2)(m) requires entities to use multi-factor authentication and continuous authentication solutions. Article 21(2)(n) requires use of encryption. NIS2 does not explicitly mandate penetration testing, but ENISA guidelines recommend regular security assessments. ManySignal integrates with penetration testing results (via import of findings as detection rules) and provides continuous monitoring evidence that complements scheduled assessments.

Deploy NIS2-ready monitoring in the EU

Configure your sector-specific NIS2 significant incident thresholds, national CSIRT notification contacts, and evidence export format — all in your first deployment session.