NIS2 CSIRT Reporting Portals: Where to File in All 27 EU Countries — and Why the EU’s Own Directory Still Lists NIS1 Authorities
Article 23(1) of NIS2 does not say you report to the CSIRT. It says entities must notify, without undue delay, its CSIRT or, where applicable, its competent authority. That one clause is why there is no single European incident portal, and why the answer to where do I file? changes at every border.
The Directive left the door open to fixing that. Article 23(11) says the Commission may adopt implementing acts further specifying the type of information, the format and the procedure of a notification. May, not shall. It has not. Implementing Regulation 2024/2690 specified incident significance for eleven digital-provider categories and said nothing about format or procedure. So the submission channel, the login model, the field list and the out-of-hours route are all national design decisions, made 27 separate times.
This is a directory of what those decisions produced — and an honest account of how much of it the EU itself does not publish.
Which Country’s Portal Is Actually Yours
Before the portal question, settle the jurisdiction question, because getting it wrong means filing in the right format to the wrong regulator.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Article 26(1) sets the default: you fall under the jurisdiction of the Member State in which you are established. The single-jurisdiction "main establishment" rule is the exception, at Article 26(1)(b), and it covers only DNS providers, TLD registries, domain registration services, cloud, data centres, CDNs, MSPs, MSSPs, online marketplaces, search engines and social platforms. Electronic communications providers fall under every Member State where the service is provided. Public administration answers to the state that established it.
| Your situation | Where you file |
|---|---|
| Single entity, one Member State | That state’s CSIRT or competent authority. One portal, one clock. |
| Group with separately established in-scope entities in three states | Three filings, three portals, three clocks — each running from that entity’s own moment of awareness. |
| Cloud, CDN, MSP, MSSP, marketplace, search, social, DNS, TLD, data centre | Main establishment only (Art. 26(2) tie-breaks: where risk decisions are predominantly taken, then where cybersecurity operations run, then largest EU headcount). |
| Electronic communications provider | Every Member State where you provide the service. |
Article 37 mutual assistance and the Article 8(4) single-point-of-contact liaison function solve cross-border coordination on the authorities’ side. Neither reduces your filing count. If you are a three-country group, you need three sets of credentials before an incident, not after.
The EU’s Official Directory Exists — And You Cannot Navigate To It
There is a canonical, EU-level list of every national CSIRT, single point of contact and competent authority. The Commission publishes it as one page per Member State at digital-strategy.ec.europa.eu/en/policies/nis2-directive-<country>. All 27 exist and all 27 return HTTP 200. Four things about that directory matter more than its contents.
It is orphaned. The Commission’s own NIS2 policy page contains zero links to any of the 27 country pages. The country pages link only to their own 24 language variants — not to each other, and not back to an index. You reach the directory by knowing the URL pattern or by search. That is the practical reason so many compliance teams end up relying on a vendor blog for their filing address.
It is still a NIS1 directory wearing a NIS2 title. Every one of the 27 pages is headed "NIS2 Directive" and then lists National competent authority for DSPs and National competent authorities for OES. Operators of essential services and digital service providers are NIS1 categories. NIS2 replaced them with essential and important entities in October 2024. The taxonomy on the EU’s own page has not caught up.
It is dated. All 27 pages carry a "Last update" stamp of 7 or 8 July 2025. In the thirteen months since, Germany’s BSIG has entered into force, Czechia has replaced its cybersecurity act, the Netherlands has adopted the Cyberbeveiligingswet and Austria has passed the NISG 2026. Consequences are visible on the pages: the Netherlands entry still names Agentschap Telecom, renamed RDI in 2023; Italy still names Ministero dello Sviluppo Economico, renamed MIMIT in 2022; Ireland still names the Department of Communications, Climate Action and Environment. France’s entry for sectoral authorities reads, in full, Details tbd.
Its URLs are inconsistent. Czechia’s page is at nis2-directive-czech-republic. The obvious guess, nis2-directive-czechia, 404s. If you build a link-checker or a runbook against the pattern, that one row breaks silently.
None of this makes the directory useless. The phone numbers, email addresses and CSIRT names are still the best EU-level starting point that exists, and for several states they are the only consolidated English-language source. It means you treat it as a lead, then confirm against the national authority’s own site — which is exactly what the table below does.
The 27-Country CSIRT Reference
Two columns here come from different places, and the difference matters. Named CSIRT and Published contact hours are what the Commission’s country page states as of its July 2025 stamp. Verified portal means we sent a request to that URL on 12 August 2026 and it answered.
| Member State | National CSIRT named by the Commission | Published contact hours | Portal / channel |
|---|---|---|---|
| Austria | CERT.at (GovCERT for public administration; Austrian Energy CERT for energy) | Mo–Fr 08:00–18:00 CET | nis.cert.at — login required, verified live; Commission describes it as a 24×7 NIS reporting portal |
| Belgium | CCB — CERT.be | 24/7 | notif.safeonweb.be — no prior authentication; emergency call to +32 2 501 05 60 may be considered equivalent if the form is unreachable |
| Bulgaria | National CSIRT bg | 09:00–18:00 UTC+2 | Email/phone published; no national portal confirmed |
| Croatia | Two: CARNET (finance, digital infra) and the Information Systems Security Bureau (energy, transport, health, water, public services) | Not published | Phone published; sector determines which CSIRT |
| Cyprus | CSIRT-CY | Not published | Email/phone published |
| Czechia | GovCERT (NÚKIB) and CSIRT.CZ (CZ.NIC) — a NIS1-era split | Not published | portal.nukib.gov.cz — verified live, no prior registration needed |
| Denmark | CFCS (same body as the single point of contact) | 24/7 | Email published; supervision split with the Danish Business Authority |
| Estonia | RIA / CERT-EE | Not published | Email/phone published |
| Finland | NCSC-FI (Traficom) | 09:00–15:00 Mon–Fri | Traficom e-service form, English available; routes to the sectoral supervisor and copies NCSC-FI |
| France | CERT-FR | 24/7 | No national NIS2 portal confirmed — transposition still incomplete as of August 2026; sectoral authorities listed as "Details tbd." |
| Germany | BSI (also SPOC and competent authority) | Not published | portal.bsi.bund.de — verified live, registration required |
| Greece | Hellenic CSIRT | Not published | Email/phone published |
| Hungary | National Cyber Security Centre CSIRT | Not published | Email/phone published |
| Ireland | CSIRT-IE / NCSC-IE | 09:00–16:30 | No national NIS2 portal confirmed — transposition still incomplete as of August 2026 |
| Italy | CSIRT Italia (ACN) | Not published (SPOC: Mon–Fri 09:00–17:00) | portale.acn.gov.it — verified live, login-gated |
| Latvia | CERT.LV | Not published | Email/phone published |
| Lithuania | NCSC / CERT-LT | Mo–Fr 08:00–17:00, 24/7 for urgent cases | Email/phone published |
| Luxembourg | CERT Gouvernemental / CERT National | 08:00–17:00 | Email/phone published |
| Malta | CSIRTMalta | Not published | Email/phone published |
| Netherlands | NCSC (plus CSIRT-DSP for digital providers) | 24/7 | Cyberbeveiligingswet in force 15 August 2026; RDI is the supervisor, not NCSC-NL |
| Poland | Three: CSIRT NASK, CSIRT MON, CSIRT GOV | NASK 24/7, MON 24/7, GOV not published | Which of the three you report to depends on your sector and ownership |
| Portugal | CERT.PT (CNCS) | 09:00–18:00, plus a published out-of-hours emergency number | Email/phone published |
| Romania | CERT-RO | 24/7 | Email/phone published |
| Slovakia | SK-CERT (NBU) | 24/7 | Email/phone published |
| Slovenia | SI-CERT | Not published | Email/phone published |
| Spain | Two: INCIBE-CERT (private sector), CCN-CERT (public sector) | Both 24/7 | No national NIS2 portal confirmed — transposition still incomplete as of August 2026 |
| Sweden | MSB / CERT-SE | Not published | Email/phone published |
Read the table as a work list, not a finished answer. For any row that says "email/phone published", your job before an incident is to open that authority’s own site and find out whether a portal has launched since July 2025 — several almost certainly have, and the EU directory would not show it.
Four Ways Member States Built the Front Door
The four national designs we could verify directly are genuinely different products, not variations on a theme. If you operate in more than one of these states, you cannot write one runbook step and reuse it.
Germany — registration-gated. Reports go through the BSI-Portal at portal.bsi.bund.de. Registration is a separate, prior process with its own guidance document, and the report itself is filed from the portal home page via a red Sicherheitsvorfall melden button. The German form asks for more than the Directive does: alongside classification, description, impact and the occurrence and discovery timestamps, it asks for a cause assessment and the measures already implemented. In the Directive those are Article 23(4)(d) final-report fields, a month later. Germany pulls them forward.
Czechia — open form, tiered fallback. NÚKIB’s portal takes an incident form with no prior registration. If the portal is down, the fallback email splits by obligation regime: cert@nukib.gov.cz for higher-obligation providers, abuse@csirt.cz for lower. There are two phone numbers, one for business hours and one for outside them — and NÚKIB states plainly that a phone report does not fulfil the function of an official channel. It buys you speed; the written form still has to follow.
Finland — one form, many recipients. Traficom runs a single e-service that, in its own words, enables notification to the supervisory authorities of different sectors, and confirms that all notifications sent via the service are also notified to the CSIRT at the National Cyber Security Centre Finland. One submission satisfies the sectoral supervisor and the CSIRT at once, and the same form lets you ask the CSIRT for help handling the incident. The form is available in English.
Austria — login, with a rehearsal mode. CERT.at’s NIS-Meldesystem requires a login and offers four submission types: mandatory reporting for essential services, mandatory reporting for digital services, voluntary reporting, and a test report. A sanctioned test-submission facility is rare, and it is the single most useful thing on this list: it lets you prove your credentials work and your people know the flow without filing anything real.
Belgium sits alongside these as a fifth model — the CCB form at notif.safeonweb.be needs no prior authentication at all, but caps its free-text fields at 500 characters each, which forces a discipline the German form does not.
The language picture follows the same pattern. Finland’s form exposes an English parameter; Austria’s portal is German with an English toggle; Germany’s is German; Czechia’s is Czech. Treat English as available-until-proven-otherwise only where you have checked, and have someone who reads the local language on the call list either way.
The After-Hours Problem Nobody Publishes
Here is the finding that should change a runbook. On the Commission’s own country pages, 12 of the 27 entries publish no contact hours at all for the national CSIRT: Croatia, Cyprus, Czechia, Estonia, Germany, Greece, Hungary, Italy, Latvia, Malta, Slovenia and Sweden. Of the states that do publish hours, several are firmly office-hours — Finland’s NCSC-FI at 09:00–15:00 Monday to Friday is the narrowest published window in the EU.
Against that, Article 23(4)(a) gives you 24 hours from awareness, and Article 23(5) obliges the CSIRT or competent authority to come back to you without undue delay and where possible within 24 hours of receiving the early warning. The obligation is mutual. But a 24-hour clock that starts at 18:30 on a Friday runs against a counterparty whose published availability, in half the Union, is simply unknown.
Two things resolve this, and neither is exotic. First, distinguish the portal from the team: a web form generally accepts a submission at any hour even when nobody reads it until Monday, which is why Austria’s Commission entry can describe a 24×7 portal behind an office-hours CSIRT. Filing into a quiet portal still stops your clock. Second, find the out-of-hours number now, while nothing is on fire. Czechia publishes a separate after-hours line. Portugal publishes an emergency contact for outside 09:00–18:00. Belgium’s guidance says an emergency call may be considered equivalent to the notification where the form is unreachable — note the permissive verb; that is a documented fallback, not a substitute you can plan around.
What to Do Before Your First Incident
Everything above is only useful if it turns into stored state. Different roles own different parts of it.
| Role | Owns | Effort |
|---|---|---|
| Compliance officer / legal | Confirming jurisdiction under Article 26 for every in-scope entity in the group, and the resulting filing count | Medium |
| Incident response lead | Portal credentials, the out-of-hours number, and a dry run where the portal allows one | Low |
| CISO | Deciding who is authorised to press submit, and ensuring the 24-hour and 72-hour drafts exist as templates rather than blank pages | Medium |
| Board | Nothing operational — but note that Article 20(1) ties management-body liability to Article 21, and incident handling is an Article 21(2)(b) measure | Low |
The pre-incident checklist is short:
- Confirm your filing jurisdiction, per entity, under Article 26 — then count your portals.
- Register in each portal that requires registration. Germany’s does. Italy’s does. Austria’s does. Registration is not something you complete inside a 24-hour window.
- Record the fallback channel for each: the email address, the out-of-hours phone number, and whether that channel is officially recognised or merely fast.
- Where a test submission is offered, use it, and record who completed it and when.
- Re-verify every entry against the national authority’s own site at least twice a year — ENISA updates its CSIRT inventory twice a year (Q2 and Q4), and the Commission’s country pages have gone thirteen months without a refresh.
If you are still working out whether the incident you are looking at is reportable at all, that is a separate gate that runs before any of this — start with the significant incident test, then the 24-hour early warning and 72-hour notification content requirements. For a deeper look at the actual form fields in eight countries, including a walk-through of a real early-warning form, see our companion guide on CSIRT notification forms and required fields. The broader duty is covered in the NIS2 incident reporting guide, and the exposure for getting it wrong in the penalties guide.
Frequently Asked Questions
Is there a single EU-wide NIS2 incident reporting portal?
No. Article 23(1) routes reports to the national CSIRT or, where applicable, the national competent authority. Article 23(11) gave the Commission a discretionary power to specify the format and procedure of a notification, and that power has not been used. The CSIRTs Network under Article 15 connects the national teams to each other — it is not a filing channel for entities.
Do I report to the CSIRT or to the competent authority?
Whichever your Member State designated. In Germany the BSI is the CSIRT, the single point of contact and the competent authority. In the Netherlands they are separate bodies, with RDI supervising and NCSC-NL acting as CSIRT. Croatia and Spain each run two national CSIRTs split by sector; Poland runs three.
What if the portal is down when my 24 hours are running?
Use the published fallback and document that you did. Czechia names an after-hours phone line while stating it is not the official channel; Belgium’s guidance says an emergency call may be considered equivalent where the form is unreachable. Neither replaces the written filing — both preserve your evidence that you tried.
My group operates in five Member States. Can I file once?
Only if the entities are not separately established. NIS2 has no GDPR-style one-stop shop. Under Article 26(1) the default is jurisdiction where you are established, so separately established in-scope entities file separately, each on its own clock. The main-establishment exception in Article 26(1)(b) applies to a closed list of digital service categories.
Can I rely on the European Commission’s country pages?
As a starting point, yes. As your only source, no. All 27 are stamped July 2025, still use the NIS1 operator-of-essential-services and digital-service-provider categories, and are not linked from the Commission’s own NIS2 policy page. Confirm against the national authority’s site.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS 2 Directive, Article 23: Reporting obligations — Directive (EU) 2022/2555, article-level text
- NIS2 Directive — Germany (national authorities and CSIRT) — European Commission, DG CNECT. All 27 country pages follow this URL pattern and were retrieved on 12 August 2026
- The NIS2 Directive — European Commission policy page
- CSIRTs Network — ENISA
- CSIRTs by Country — Interactive Map and European CSIRT Inventory — ENISA
- Hlášení incidentů (Incident reporting) — NÚKIB, Czechia
- Incident notification under the NIS 2 Directive — Traficom / NCSC-FI, Finland
- NIS-Meldesystem (login) — CERT.at, Austria
- Portale ACN — Agenzia per la Cybersicurezza Nazionale, Italy
- NIS2 Notification Guide (v1.2, October 2024) — Centre for Cybersecurity Belgium, ccb.belgium.be. Source of the no-prior-authentication route, the 500-character field caps and the emergency-call fallback; the CCB blocks automated retrieval, so it is cited here without a link
- Anleitung zur Meldung im BSI-Portal — Bundesamt für Sicherheit in der Informationstechnik, Germany (bsi.bund.de). Portal verified live at portal.bsi.bund.de
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
