NIS2 CSIRT: The 8 Tasks in Article 11 — and the 2 Services That Only Happen If You Ask
Most in-scope organisations treat their national CSIRT as an inbox: somewhere to file a 24-hour early warning and hope for the best. That reading costs them. Article 11(3) of Directive (EU) 2022/2555 [8] gives CSIRTs eight tasks, and two of them contain services an essential or important entity can switch on simply by asking — including a scan of your own estate for high-impact vulnerabilities, run by the state.
Which CSIRT Is Yours, and Why “One or More” Matters
In plain terms: every EU country must have at least one CSIRT covering every NIS2 sector, but many run several — and yours may sit inside your regulator.
Article 10(1) requires each Member State to “designate or establish one or more CSIRTs” covering “at least the sectors, subsectors and types of entity referred to in Annexes I and II” [1]. “One or more” is doing real work: several states split CSIRT duties by sector, so the team that handles a hospital is not the team that handles a bank. Our breakdown of CSIRT reporting portals across all 27 countries maps which body actually receives your filing.
The same article permits a CSIRT to be “designated or established within a competent authority” [1]. Ireland is a clear example: the NCSC describes itself as the country’s “national cyber security authority & national CSIRT” and also acts as Lead Competent Authority [2]. Your operational helper and your supervisor can be the same organisation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
One thing the Directive does not do is ration CSIRT services by entity class:
| If your organisation is | CSIRT service entitlement | Basis |
|---|---|---|
| An essential entity | Full Article 11(3) service set | Art. 11(3) |
| An important entity | Identical set — Article 11(3) draws no distinction | Art. 11(3)(a), (e) |
| Outside NIS2 scope | No Article 11(3) entitlement, but may file voluntary notifications | Art. 30(1)(b) |
| A supplier to an in-scope entity | No direct entitlement; reached through your customer’s arrangements | Art. 29(2) |
Supervision is tiered: Article 33(1) confines the supervision of important entities to “ex post supervisory measures,” a limit Article 32 does not place on essential entities [3]. CSIRT support carries no such tiering. An important entity can request exactly what an essential entity can.
The Eight Tasks in Article 11(3): What Runs Automatically, What Waits for You
In plain terms: six tasks happen with or without your involvement. Two contain a service that starts only when an entity asks.
| Article 11(3) task | What it delivers to you | Who starts it |
|---|---|---|
| (a) National threat monitoring plus assistance with your own real-time monitoring | A national threat picture — and, separately, help watching your systems | Automatic + on request |
| (b) Early warnings, alerts, announcements, dissemination | Advisories, “if possible in near real-time” | Automatic |
| (c) Responding to incidents and providing assistance “where applicable” | Response support once you report | CSIRT judgement |
| (d) Forensic data, dynamic risk and incident analysis, situational awareness | The analytical capability behind any response | Automatic |
| (e) Proactive scanning of your systems for vulnerabilities with potential significant impact | A state-run vulnerability scan of your estate | On request only |
| (f) CSIRTs network participation and mutual assistance | Cross-border reach when an incident spans states | Automatic (CSIRT to CSIRT) |
| (g) Acting as coordinator for coordinated vulnerability disclosure “where applicable” | A trusted intermediary for vulnerability reports | Triggered by a disclosure |
| (h) Contributing to deployment of secure information-sharing tools | The channel you file and receive through | Automatic |
Article 11(3) also carries a power that needs no request and no consent: CSIRTs “may carry out proactive non-intrusive scanning of publicly accessible network and information systems of essential and important entities” [1]. If your national team emails you about an exposed management port you never reported, this is why. That scan is limited to publicly reachable systems and “shall not have any negative impact on the functioning of the entities’ services” — it is not authority to touch anything behind your perimeter.
The Two Services You Have to Ask For
The first is monitoring assistance. Task (a) obliges CSIRTs to provide, “upon request, … assistance to essential and important entities concerned regarding real-time or near real-time monitoring of their network and information systems” [1]. Recital 44 describes the intended shape: monitoring “the entity’s internet-facing assets, both on and off premises,” to manage risk from “newly identified supply chain compromises or critical vulnerabilities.” The same recital adds an operational detail worth acting on — the entity “should be encouraged to communicate to the CSIRT whether it runs a privileged management interface, as this could affect the speed of undertaking mitigating actions” [3]. Volunteer that fact when you make the request; it changes triage.
The second is the scan. Task (e) covers “proactive scanning of the network and information systems of the entity concerned to detect vulnerabilities with a potential significant impact” [1]. Unlike the non-intrusive sweep above, this one reaches your actual estate, which is why Recital 43 signals that it should be provided “in accordance with Regulation (EU) 2016/679” [3] — the GDPR applies to the scan on its own force, not because the recital says so.
There is no prescribed request form. Article 11(1)(a) requires CSIRTs to “clearly specify the communication channels and make them known to constituency” [1], so the route is your CSIRT’s published contact channel. Put the request in writing, name the systems and IP ranges in scope, cite Article 11(3)(e) or 11(3)(a), give a named technical contact, and keep the correspondence — it doubles as due-diligence evidence under Article 21.
What Your CSIRT Owes You After the 24-Hour Early Warning
In plain terms: filing triggers a reciprocal duty. Two of the four things it covers only happen if you ask.
Article 23(5) requires the CSIRT or competent authority to provide, “without undue delay and where possible within 24 hours of receiving the early warning,” a response including initial feedback [4]. Note the qualifier: “where possible” is softer than the entity-side deadline in Article 23(4)(a), which is unconditional.
Unpacking the provision by trigger:
- Initial feedback — provided as part of the response. No request needed.
- Guidance or operational advice on mitigation measures — “upon request of the entity” [4].
- Additional technical support — “The CSIRT shall provide additional technical support if the entity concerned so requests” [4]. Binding, but request-gated.
- Law-enforcement reporting guidance — owed where the incident “is suspected to be of criminal nature,” without a request.
An entity that files and waits receives initial feedback and nothing more. Asking for mitigation advice and technical support in the same message as the early warning is the single highest-value habit here. If you filed with the competent authority rather than the CSIRT, guidance comes from that authority “in cooperation with the CSIRT,” and Article 23(1) obliges it to forward your notification onward [4]. The 72-hour notification stage does not reset this duty; it attaches to the early warning. Our NIS2 incident reporting guide walks the full 24-hour, 72-hour and one-month sequence from the entity side.
Three Provisions That Let a CSIRT Say No
Article 11(3) reads like a service catalogue, but three clauses limit what you can count on.
Risk-based prioritisation. The final subparagraph of Article 11(3) states that “the CSIRTs may prioritise particular tasks on the basis of a risk-based approach” [1]. Your scan request is a task that can be queued behind others.
“Jointly.” Article 11(2) obliges Member States to ensure their CSIRTs “jointly have the technical capabilities necessary to carry out the tasks referred to in paragraph 3″ [1]. In a multi-CSIRT country, no single team must hold every capability — the one you contact may not be the one that can scan.
Conditioners inside the tasks. Task (c) applies “where applicable,” (g) “where applicable,” (b) “if possible in near real-time,” and (f) “in accordance with their capacities and competencies” [1].
Practice matches the text. A Tilburg University study for NCSC-NL examining six national teams found GovCERT Austria “primarily committed to facilitate information exchange and coordination, but not on-site incident response,” prioritising by “type and severity of the incident, type of constituency, size and user community affected, and available resources”; CERT-EE weighing whether to prioritise “those entities with less in-house technical capabilities”; and CERT-Bund working on “scaling up … to deal with growing constituencies” [5]. The same study reports the Commission’s pre-adoption impact assessment estimate of roughly a 10-15% increase in staff handling incident reporting [5] — modest against a scope expansion that multiplied the constituency several times over. Claim CSIRT support early, but do not let it stand in for a retained incident-response capability.
Does Talking to Your CSIRT Create Regulatory Exposure?
This is the question that keeps entities from calling, and the Directive answers part of it plainly. Article 23(1) states that “the mere act of notification shall not subject the notifying entity to increased liability” [4]. For voluntary reports, Article 30(2) adds that voluntary reporting “shall not result in the imposition of any additional obligations upon the notifying entity to which it would not have been subject had it not submitted the notification” [3].
Two caveats matter. The separation between CSIRT and supervisor is optional: Recital 41 says only that where a CSIRT sits inside a competent authority, Member States “should be able to consider functional separation between the operational tasks provided by the CSIRTs … and the supervisory activities of the competent authorities” [3]. That is a permissive recital, not a binding article — check how your own Member State structured it rather than assuming a wall exists. And you do not control disclosure: under Article 23(7) the CSIRT or competent authority may inform the public itself, or require you to, after consulting you [4].
As a practical reading rather than settled law, the Article 23(1) shield protects the act of notifying, not the underlying security failure. It removes a reason not to call. It is not immunity.
Beyond Incidents: Vulnerability Coordination, ISACs, and Near Misses
Each Member State designates one of its CSIRTs as coordinator for coordinated vulnerability disclosure under Article 12(1), acting as “a trusted intermediary” whose tasks include “identifying and contacting the entities concerned” and “negotiating disclosure timelines” [6]. Anyone may report a vulnerability to that coordinator, anonymously on request. If your product is the subject, you may hear about it from the coordinator rather than the researcher — and the timeline is negotiated, not yours to set. Where a vulnerability affects entities in more than one country, Article 12(1) routes the coordinators’ cooperation through the CSIRTs network [6], whose members are the Member States’ appointed CSIRTs plus CERT-EU, with ENISA acting as secretariat [7]. That same network carries cross-border incident coordination. Our guide to building a vulnerability disclosure policy covers the entity-side process.
On information sharing, Article 10(4) has CSIRTs cooperate with “sectoral or cross-sectoral communities” under Article 29 [1]. One obligation here is regularly missed: Article 29(4) requires entities to notify the competent authority when they enter such an arrangement and again when they withdraw [3]. Joining an ISAC is a notifiable event.
Finally, Article 30(1) allows voluntary notification of incidents, cyber threats and near misses — and extends it to entities outside NIS2 scope entirely [3]. The trade-off is queue position: Article 30(2) permits Member States to “prioritise the processing of mandatory notifications over voluntary notifications” [3].
What This Means for Your Role
| Role | Action this quarter |
|---|---|
| CISO / IT security manager | Submit an Article 11(3)(e) scan request naming in-scope ranges, and disclose any privileged management interface per Recital 44. Confirm whether your national team performs on-site response at all. |
| Compliance officer | Add “request mitigation guidance and technical support” as a standing line in the 24-hour early warning template, so Article 23(5) is triggered in full. File CSIRT correspondence as Article 21 due-diligence evidence. |
| SME owner / non-technical | Identify which body is your CSIRT and whether it is also your regulator. Save its contact channel where on-call staff can reach it at 2 a.m. |
| Board / C-suite | Do not budget CSIRT assistance as a control. Risk-based prioritisation under Article 11(3) means it may not arrive in time. |
Frequently Asked Questions
Is my CSIRT the same body as my competent authority?
Sometimes. Article 10(1) permits a CSIRT to sit within a competent authority, and several states use that model — Ireland’s NCSC is both national CSIRT and Lead Competent Authority [2]. Others separate them. Check your national transposition, because it determines who sees what.
Will my CSIRT send responders on site during an incident?
Article 11(3)(c) requires responding to incidents and providing assistance “where applicable,” which does not guarantee on-site presence. At least one national team studied for NCSC-NL provides coordination and information exchange “but not on-site incident response” [5]. Confirm your own team’s model before you plan around it.
Do essential entities get better CSIRT service than important entities?
No. Article 11(3) refers to “essential and important entities” throughout, and the scanning right in 11(3)(e) is granted to “an essential or important entity” [1]. The tiering in NIS2 applies to supervision, not CSIRT support.
Sources
- European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Articles 10, 11 and 29 — nis-2-directive.com (linked above)
- National Cyber Security Centre Ireland, NIS2 FAQ — ncsc.gov.ie
- European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Recitals 41, 43 and 44 and Articles 29 and 30 — nis2-info.eu full text
- European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Article 23 — nis-2-directive.com
- Kamara, I. & van den Boom, J., Computer Security Incident Response Teams in the reformed Network and Information Security Directive: good practices, Tilburg Institute for Law, Technology, and Society, study funded by NCSC-NL, July 2022 — ncsc.nl
- European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Article 12 — nis-2-directive.com (linked above)
- European Union Agency for Cybersecurity (ENISA), CSIRTs Network — enisa.europa.eu
- Official consolidated text of Directive (EU) 2022/2555 — eur-lex.europa.eu
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
