Skip to content

Incident reporting and communications

NIS2 incident obligations require both governance readiness and execution evidence. Modulos splits these duties between OFF-15 and MFF-15.

Organization-level reporting governance (OFF-15)

RequirementTopicDirective reference
ORF-350Significant incident determination governanceArt. 23(3)
ORF-351Recipient incident and threat communicationArt. 23(1)-(2)
ORF-35224-hour early warning procedureArt. 23(4)(a)
ORF-35372-hour incident notification procedureArt. 23(4)(b)
ORF-354Intermediate, final, and progress reporting procedureArt. 23(4)(c)-(e)
ORF-358Information-sharing arrangement notification dutyArt. 29(4)
ORF-359Voluntary notification governanceArt. 30(1)-(2)
ORF-360Supervisory cooperation and enforcement responseArts. 32, 33

AI-service reporting execution (MFF-15)

RequirementTopicDirective reference
MRF-286Significant incident detection and impact assessmentArt. 23(3)
MRF-287Recipient notification and threat communication workflowArt. 23(1)-(2)
MRF-28824-hour early warning workflowArt. 23(4)(a)
MRF-28972-hour incident notification workflowArt. 23(4)(b)
MRF-290Intermediate, final, and progress reporting workflowArt. 23(4)(c)-(e)
MRF-291Implementing-regulation significant-incident criteria executionArts. 23(3), 23(11); Reg. 2024/2690
MRF-292Trust service 24-hour notification workflowArt. 23(4)(b), second subparagraph

Staged reporting timeline in execution terms

StageTypical trigger in workflowNIS2 timing reference
Early warningInitial classification suggests significant incident and includes suspected malicious or unlawful-act and cross-border indicators24 hours
Incident notificationConfirmed materiality and initial impact details72 hours
Intermediate/final/progress reportsOngoing investigation and closure packageArt. 23(4)(c)-(e) sequence, including one-month final report

Special applicability points

  • ORF-353 remains a broad reporting requirement. Trust-service providers then apply the additional 24-hour derogation path described in the requirement text.
  • MRF-292 is the AI-service execution requirement for that trust-service-provider special case.
  • MRF-291 is only relevant where the supported entity type is covered by Implementing Regulation 2024/2690.
  • ORF-358 and ORF-359 are not universal duties; they are relevant when the organization participates in information-sharing arrangements or operates a voluntary-notification path.

Where to run this in Modulos

  • Project → Requirements for obligation status tracking
  • Project → Controls for reporting workflow execution and review
  • Project → Evidence for authority notices, timelines, and communication records

Disclaimer

This page is for general informational purposes and does not constitute legal advice.