This duty is triggered by a threat rather than an incident. Where a significant cyber threat could affect the recipients of the entity's services, the entity must without undue delay communicate to those potentially affected recipients any measures or remedies they are able to take in response, and where appropriate inform them of the threat itself. The obligation is practical rather than declaratory: the communication has to tell the recipient what to do, which means the entity needs the ability to identify who is affected, reach them quickly, and say something actionable. Building that capability after the threat emerges is the failure mode, because contact data and approval routes take longer to assemble than the threat allows.
NIS2 Directive Art.23.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.