Digital Omnibus tracker

NIS2 Directive · Directive (EU) 2022/2555

Article 23

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 4 parts · 4 Council drafts · 7 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

European Commission proposal

All Commission’s changes to NIS2 Directive

The wording proposed by the Commission at the start of this legislative file.

Full article with Commission changes

Article with proposed changes

Official consolidated text dated 14 December 2022, with all 2 Commission proposal changes affecting this article applied.

Article 23

Reporting obligations

  1. 1.

    Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a. Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. Each Member State shall ensure that those entities report, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. The mere act of notification shall not subject the notifying entity to increased liability.

    Where the entities concerned notify the competent authority of a significant incident under the first subparagraph, the Member State shall ensure that that competent authority forwards the notification to the CSIRT upon receipt.

    In the case of a cross-border or cross-sectoral significant incident, Member States shall ensure that their single points of contact are provided in due time with relevant information notified in accordance with paragraph 4.

  2. 2.

    Where applicable, Member States shall ensure that essential and important entities communicate, without undue delay, to the recipients of their services that are potentially affected by a significant cyber threat any measures or remedies that those recipients are able to take in response to that threat. Where appropriate, the entities shall also inform those recipients of the significant cyber threat itself.

  3. 3.

    An incident shall be considered to be significant if:

    1. (a)

      it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned;

    2. (b)

      it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

  4. 4.

    Member States shall ensure that, for the purpose of notification under paragraph 1, the entities concerned submit to the CSIRT or, where applicable, the competent authority:

    By way of derogation from the first subparagraph, point (b), a trust service provider shall, with regard to significant incidents that have an impact on the provision of its trust services, notify the CSIRT or, where applicable, the competent authority, without undue delay and in any event within 24 hours of becoming aware of the significant incident.

    1. (a)

      without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;

    2. (b)

      without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;

    3. (c)

      upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates;

    4. (d)

      a final report not later than one month after the submission of the incident notification under point (b), including the following:

      1. (i)

        a detailed description of the incident, including its severity and impact;

      2. (ii)

        the type of threat or root cause that is likely to have triggered the incident;

      3. (iii)

        applied and ongoing mitigation measures;

      4. (iv)

        where applicable, the cross-border impact of the incident;

    5. (e)

      in the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident.

  5. 5.

    The CSIRT or the competent authority shall provide, without undue delay and where possible within 24 hours of receiving the early warning referred to in paragraph 4, point (a), a response to the notifying entity, including initial feedback on the significant incident and, upon request of the entity, guidance or operational advice on the implementation of possible mitigation measures. Where the CSIRT is not the initial recipient of the notification referred to in paragraph 1, the guidance shall be provided by the competent authority in cooperation with the CSIRT. The CSIRT shall provide additional technical support if the entity concerned so requests. Where the significant incident is suspected to be of criminal nature, the CSIRT or the competent authority shall also provide guidance on reporting the significant incident to law enforcement authorities.

  6. 6.

    Where appropriate, and in particular where the significant incident concerns two or more Member States, the CSIRT, the competent authority or the single point of contact shall inform, without undue delay, the other affected Member States and ENISA of the significant incident. Such information shall include the type of information received in accordance with paragraph 4. In so doing, the CSIRT, the competent authority or the single point of contact shall, in accordance with Union or national law, preserve the entity’s security and commercial interests as well as the confidentiality of the information provided.

  7. 7.

    Where public awareness is necessary to prevent a significant incident or to deal with an ongoing significant incident, or where disclosure of the significant incident is otherwise in the public interest, a Member State’s CSIRT or, where applicable, its competent authority, and, where appropriate, the CSIRTs or the competent authorities of other Member States concerned, may, after consulting the entity concerned, inform the public about the significant incident or require the entity to do so.

  8. 8.

    At the request of the CSIRT or the competent authority, the single point of contact shall forward notifications received pursuant to paragraph 1 to the single points of contact of other affected Member States.

  9. 9.

    The single point of contact shall submit to ENISA every three months a summary report, including anonymised and aggregated data on significant incidents, incidents, cyber threats and near misses notified in accordance with paragraph 1 of this Article and with Article 30. In order to contribute to the provision of comparable information, ENISA may adopt technical guidance on the parameters of the information to be included in the summary report. ENISA shall inform the Cooperation Group and the CSIRTs network about its findings on notifications received every six months.

  10. 10.

    The CSIRTs or, where applicable, the competent authorities shall provide to the competent authorities under Directive (EU) 2022/2557 information about significant incidents, incidents, cyber threats and near misses notified in accordance with paragraph 1 of this Article and with Article 30 by entities identified as critical entities under Directive (EU) 2022/2557.

  11. 11.

    The Commission may adopt implementing acts further specifying the type of information, the format and the procedure of a notification submitted pursuant to paragraph 1 of this Article and to Article 30 and of a communication submitted pursuant to paragraph 2 of this Article.

    By 17 October 2024, the Commission shall, with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines and of social networking services platforms, adopt implementing acts further specifying the cases in which an incident shall be considered to be significant as referred to in paragraph 3. The Commission may adopt such implementing acts with regard to other essential and important entities.

    The Commission shall exchange advice and cooperate with the Cooperation Group on the draft implementing acts referred to in the first and second subparagraphs of this paragraph in accordance with Article 14(4), point (e).

    Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 39(2).

  12. 12.

    When a manufacturer notifies a severe incident pursuant to Article 14(3) of Regulation (EU) 2024/2847 and the incident reporting under that Article contains relevant information as required under paragraph 4 of this Article, the reporting of the manufacturer under Article 14(3) of Regulation (EU) 2024/2847 shall constitute reporting of information under paragraph 4 of this Article.

Commission source wording and instructions

Article 23(1), first sentence

Commission proposal

Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a.

Article 23(12)

Commission proposal

When a manufacturer notifies a severe incident pursuant to Article 14(3) of Regulation (EU) 2024/2847 and the incident reporting under that Article contains relevant information as required under paragraph 4 of this Article, the reporting of the manufacturer under Article 14(3) of Regulation (EU) 2024/2847 shall constitute reporting of information under paragraph 4 of this Article.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 23(1), first sentence

May Presidency compromise

Council wording reconstructed for this provision from the official operation

Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the national entry point pursuant to Article 23b.

Article 23(12)

May Presidency compromise

When a manufacturer notifies a severe incident pursuant to Article 14(3) of Regulation (EU) 2024/2847 and the incident reporting under that Article contains relevant information as required under paragraph 4 of this Article, the reporting of the manufacturer under Article 14(3) of Regulation (EU) 2024/2847 shall constitute reporting of information under paragraph 4 of this Article.

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 280 · Victor Negrescu JURI
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a. Member States shall ensure that guidance and support on incident reporting, including standard templates and explanatory material, are made easily accessible, in particular for SMEs that qualify as important entities, to strengthen their cybersecurity posture and facilitate compliance.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Regulation (EU) 2023/2854 / Article 23

Alternative wording Amendment 281 · Daniel Buda JURI
‘Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entryreporting channel designated by the competent Member State, including through a national contact point, through a national interface or, where the competent Member State has so decided, through the interoperable European framework established pursuant to Article 23a.’
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Directive (EU) 2022/2555 / Article 23 – paragraph 1 – point a

Alternative wording Amendment 282 · Ton Diepeveen, Pascale Piera JURI
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entry point established pursuant to Article 23a.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Directive 2002/58/EC / Article 23 – paragraph 1

Additional proposed wording Amendment 512 · Sophia Kircher IMCO
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 1 / Directive (EU) 2022/2555 / Article 23 – paragraph 1 – point 3b a (new)

Alternative wording Amendment 515 · Virginie Joron IMCO
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) via the single-entrynational pointsingle points of entry established pursuant to Article 23a.;
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Directive (EU) 2022/2555 / Article 23 – paragraph 1

Alternative wording Amendment 1806 · Markus Buchheit ITRE · LIBE
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that hashaving a significant impact on the provision of their services. asMember States may provide for national digital reporting channels for that purpose. Notification through tools referred to in paragraphArticle 323a may be required only in cases of thiscross-border Articleor (significantUnion-wide incident)systemic via the single-entry point established pursuant to Article 23arelevance.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Directive (EU) 2022/2555 / Article 23 – paragraph 1

Alternative wording Amendment 1807 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Ewa Zajączkowska-Hernik, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
Each Member State shall ensure that essentialtheir andnational importantsingle-entry entitiespoints notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of this Article of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 of this Article (significant incident) viato the EU single-entry point established pursuant to Article 23a.
Preview
against:
Source identification

Header printed in the source: Article 6 – paragraph 1 – point 2 – point a / Directive (EU) 2022/2555 / Article 23 – paragraph 1