NIS2 Directive
NIS2 Chapter IV: Incident Reporting (Article 23)

NIS2 Directive Art.23.2: Tell affected service recipients about significant cyber threats and the remedies open to them

This duty is triggered by a threat rather than an incident. Where a significant cyber threat could affect the recipients of the entity's services, the entity must without undue delay communicate to those potentially affected recipients any measures or remedies they are able to take in response, and where appropriate inform them of the threat itself. The obligation is practical rather than declaratory: the communication has to tell the recipient what to do, which means the entity needs the ability to identify who is affected, reach them quickly, and say something actionable. Building that capability after the threat emerges is the failure mode, because contact data and approval routes take longer to assemble than the threat allows.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 15 controls across 12 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-DE.AE-07 Cyber threat intelligence and other contextual information are integrated into the analysis
  • NIST-CSF-ID.RA-03 Internal and external threats to the organization are identified and recorded
  • NIST-CSF-RS.CO-03 Information is shared with designated internal and external stakeholders

C5 (Germany) · 2 controls

  • C5-PSS-01 Guidelines and Recommendations for Cloud Customers
  • C5-PSS-03 Online Register of Known Vulnerabilities

APRA CPS 234 · 1 control

  • CPS234-20 Information Asset Classification

CMMC 2.0 · 1 control

DORA · 1 control

FedRAMP High · 1 control

  • SI-5 Security Alerts, Advisories, and Directives

FedRAMP Moderate · 1 control

  • SI-5 Security Alerts, Advisories, and Directives

ISO 27001:2022 · 1 control

  • 5.7 Threat intelligence

ISO 27002:2022 · 1 control

  • 5.7 Threat intelligence
  • 03.14.03 Security Alerts, Advisories, and Directives
  • NIST800-SI-5 SI-5 Security Alerts, Advisories, and Directives

SOC 2 · 1 control

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Incident Reporting (Article 23)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.23.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 15 it maps to, and the evidence behind each claim, over MCP and REST.