NIS2 Directive
NIS2 Chapter IV: Incident Reporting (Article 23)

NIS2 Directive Art.23.2: Tell affected service recipients about significant cyber threats and the remedies open to them

This duty is triggered by a threat rather than an incident. Where a significant cyber threat could affect the recipients of the entity's services, the entity must without undue delay communicate to those potentially affected recipients any measures or remedies they are able to take in response, and where appropriate inform them of the threat itself. The obligation is practical rather than declaratory: the communication has to tell the recipient what to do, which means the entity needs the ability to identify who is affected, reach them quickly, and say something actionable. Building that capability after the threat emerges is the failure mode, because contact data and approval routes take longer to assemble than the threat allows.

Other controls in NIS2 Chapter IV: Incident Reporting (Article 23)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.23.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.