NIS2 Directive
NIS2 Chapter IV: Incident Reporting (Article 23)

NIS2 Directive Art.23.4.b: Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise

Within 72 hours of becoming aware, the entity updates the early warning and provides an initial assessment of the significant incident covering its severity and impact, together with indicators of compromise where those are available. The 72 hours runs from awareness, not from the early warning, so the two clocks start together. Trust service providers are held to a shorter deadline: for significant incidents affecting the provision of their trust services they must notify within 24 hours. The practical demand here is investigative rather than administrative, since the entity needs enough forensic capability within three days to characterise severity and impact honestly and to extract indicators worth sharing. Producing indicators requires that the telemetry existed before the incident.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 8 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 3 controls

DORA · 3 controls

  • DORA-Art.17 ICT-related incident management process
  • DORA-Art.18 Classification of ICT-related incidents and cyber threats
  • DORA-Art.19 Reporting of major ICT-related incidents
  • NIST-CSF-DE.AE-04 The estimated impact and scope of adverse events are understood
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring
  • NIST-CSF-RS.AN-07 Incident data and metadata are collected, and their integrity and provenance are preserved

ISO 27001:2022 · 2 controls

ISO 27002:2022 · 2 controls

APRA CPS 234 · 1 control

  • CPS234-35 APRA Notification of Material Incidents within 72 Hours

EU AI Act · 1 control

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NIS2 Chapter IV: Incident Reporting (Article 23)

You are reading one control. How much of NIS2 Directive have you already done?

NIS2 Directive Art.23.4.b is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.