NIS2 EU-CyCLONe: No Severity Threshold Triggers It — and the Agreed Scale Isn’t Due Until 2027
Article 16 of NIS2 creates a network your organisation will never contact, never be notified by, and never see the output of. It is also the rung of the EU escalation ladder where your incident stops being a technical problem and becomes a political one.
The question every crisis plan eventually asks is: how big does an incident have to be before EU-CyCLONe gets involved? The law does not answer it. There is no threshold, no percentage, and no severity level — and the scale that will eventually exist is not due until 2027.
What EU-CyCLONe Is — and Which Authority Actually Sits in It
In plain terms: EU-CyCLONe is the meeting room where national cyber crisis managers coordinate during an incident too big for one country. It is not a reporting portal, not a threat-intelligence feed, and not something entities join.
Directive (EU) 2022/2555 Article 16(1) establishes it “to support the coordinated management of large-scale cybersecurity incidents and crises at operational level and to ensure the regular exchange of relevant information among Member States and Union institutions, bodies, offices and agencies” [1].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The composition is where most explainers go wrong. Article 16(2) seats “representatives of Member States’ cyber crisis management authorities” — and that is a third national designation, created by Article 9(1), separate from both the competent authority and the CSIRT you actually deal with. Where a Member State designates more than one, Article 9(2) requires it to name which one coordinates [1].
| National designation | NIS2 basis | Which EU body it sits in |
|---|---|---|
| Competent authority | Article 8(1) | NIS Cooperation Group (Article 14) |
| CSIRT | Article 10 | CSIRTs network (Article 15), with CERT-EU |
| Cyber crisis management authority | Article 9(1) | EU-CyCLONe (Article 16) |
| Single point of contact | Article 8(3) | No seat in any EU network |
Many countries merge these roles into one agency, which hides the distinction — but the roles remain legally separate, and the crisis authority is the one carrying your incident into Brussels. Awkwardly, it is also the one the EU does not publish: the Commission’s own country page for NIS2 in Germany lists the single point of contact, the competent authorities and the national CSIRT — and names no Article 9 crisis authority at all [6]. If you want to know who represents you, the national transposition law is the source, not the EU directory.
The Commission is a full member only where a potential or ongoing large-scale incident has, or is likely to have, a significant impact on services within NIS2’s scope; otherwise it attends as an observer. ENISA provides the secretariat [1]. The chair is the representative of the Member State holding the Council Presidency [4].
There Is No Severity Threshold — and the Agreed Scale Isn’t Due Until 2027
Ask an AI assistant when EU-CyCLONe activates and you will likely be told it happens “once an incident reaches Severity Level 3 (High) or above” on a five-level 0–4 scale. That scale does not exist in any adopted EU instrument. Searching the full adopted text of the EU blueprint for cyber crisis management returns two occurrences of “severity” — both inside a single paragraph — and zero occurrences of “five” or “Level 3” [3]. Do not build an escalation playbook around it.
What the law does give you is a definition, not a metric. Article 6(7) defines a large-scale cybersecurity incident as “an incident which causes a level of disruption that exceeds a Member State’s capacity to respond to it or which has a significant impact on at least two Member States” [1]. That is a capability test and a spillover test — deliberately judgement-based.
The severity scale is a future deliverable. Paragraph (30) of the Blueprint asks EU-CyCLONe, supported by ENISA and after consulting the CSIRTs network and the Cooperation Group, to agree “a common aligned taxonomy of incident severity levels” within 24 months of adoption. The Blueprint was adopted on 6 June 2025, which puts the deadline around June 2027. The taxonomy is to compare severity by weighing impact on service delivery, the number of affected entities and their relevance, knock-on impact on other services, and monetary, reputational and political damage [3].
Two cautions on that source. The Blueprint is a Council Recommendation addressed to Member States and Union bodies — it is not binding and creates no duties for regulated entities. And a deadline to agree a taxonomy is not the same as a taxonomy existing.
Activation is also discretionary rather than automatic. Blueprint paragraph (49) states that activation of the CSIRTs network and EU-CyCLONe “can be independent from each other,” and that “the decision to activate rests solely and independently with each respective network.” Paragraph (50) gives the CSIRTs network an advisory role — it “should advise EU-CyCLONe on whether an observed cybersecurity incident may be deemed a potential or ongoing large-scale cybersecurity incident” [3]. Nobody is obliged to promote your incident upward.
The proportionality principle in paragraph (5)(a) sets the realistic expectation plainly: “most cybersecurity incidents affecting Member States fall below what could be considered a national or Union large-scale cybersecurity incident or cyber crisis” [3]. That the criteria remain unsettled is visible in the network’s own preparation — ENISA’s BlueOLEx 2024 exercise on 8 November 2024 gathered executives from Member State crisis authorities specifically to test information sharing and “criteria for escalation” [5].
What EU-CyCLONe Does Once It Engages
Article 16(3) assigns five tasks. Recital 71 — interpretive, not binding — describes the design intent: EU-CyCLONe works “as an intermediary between the technical and political level,” building on CSIRTs network findings to produce impact analysis [1].
| Article 16(3) task | What it means during a live incident |
|---|---|
| (a) Increase preparedness | Exercises and procedures agreed before anything happens |
| (b) Shared situational awareness | One agreed picture across 27 capitals instead of 27 versions |
| (c) Assess consequences and propose mitigation | Converts technical findings into cross-border impact analysis |
| (d) Coordinate management, support political decisions | Briefs ministers and the Council; does not command responders |
| (e) Discuss national response plans | Only on request of the Member State concerned |
Note what is absent: no power to direct your response, no power to instruct your regulator, and no operational role in your recovery. Its output is analysis and coordination. Under the Blueprint, situational reports from EU-CyCLONe and the CSIRTs network remain the main instruments of common situational awareness, the Council may request briefings from EU-CyCLONe, and where the Integrated Political Crisis Response is activated in full mode those reports feed the political level [3]. EU-CyCLONe also reports regularly to the Cooperation Group under Article 16(5), and to the European Parliament and the Council every 18 months under Article 16(7) [1].
Where Your Incident Report Goes — and Why You Never Hear Back
Your 24-hour early warning enters at the bottom of a five-rung chain: you notify your CSIRT or competent authority under Article 23(1); Article 23(6) has them inform other affected Member States and ENISA; the CSIRT feeds the CSIRTs network under Article 15; the CSIRTs network may advise EU-CyCLONe; and EU-CyCLONe briefs the political level [1][3].
Your right to information stops at the first rung. Article 23(5) is the only feedback duty in the chain — your CSIRT or competent authority must respond without undue delay and, where possible, within 24 hours of the early warning, with initial feedback and, on request, guidance on mitigation [1]. Nothing in Article 16 owes you notice that your incident was discussed, escalated, or briefed to the Council. Entities have no seat; the only non-state participation Article 16(2) contemplates is discretionary observer status “where appropriate,” at the network’s invitation [1].
This is by design rather than oversight. Confidentiality is one of the Blueprint’s guiding principles, and the instrument contains no duty to publish which incidents were handled [3]. For a fuller walk-through of the chain, see our guide to critical infrastructure attack escalation.
What This Means for Your Role
| Role | What to do about EU-CyCLONe |
|---|---|
| CISO / IT security manager | Nothing operational. Your escalation ends at the national CSIRT. Remove any playbook step that references an EU severity level. |
| Compliance officer | Identify your Article 9 crisis authority by name and record it alongside your competent authority and CSIRT. It is a distinct designation and often absent from EU directories. |
| Board / C-suite | Understand that in a large-scale incident, decisions about your sector may be discussed in Brussels without your input or knowledge. Plan communications accordingly. |
| SME owner | Effectively no impact. Proportionality means most incidents never approach this level. Focus on your Article 23 reporting duties. |
Three concrete actions follow. First, name your Article 9 authority — and its coordinator, if your Member State designated more than one — from the national transposition law, not the Commission’s country page. Second, align your crisis management plan with the national large-scale response plan required by Article 9(4), which must set out how your Member State participates at Union level [1]. Third, know the assistance route: the EU Cybersecurity Reserve under the Cyber Solidarity Act is established by Article 14 and requested under Article 15 [7] — requests come from Member States, not from you, so your path to EU-level incident response support runs through your national crisis authority.
What Changes by 2027
Three developments are worth tracking. The severity taxonomy is due to be agreed around June 2027, which will give escalation a common vocabulary for the first time. The 18-month Article 16(7) reports to Parliament and Council are the main public accountability window into a network that otherwise publishes little. And under the Blueprint, Cross-Border Cyber Hubs established by the Cyber Solidarity Act should pass information about a potential or ongoing large-scale incident to EU-CyCLONe and the CSIRTs network without undue delay [3][7] — meaning EU-level awareness can now begin with EU detection rather than with your report. The Blueprint also asked the Commission, with ENISA and the networks, to produce detailed process flow diagrams of information flows and decision-making within one year of publication — due around June 2026, and the closest thing to a published map of how escalation actually runs [3].
Frequently Asked Questions
Does EU-CyCLONe create any obligation for my organisation?
No. Article 16 addresses Member States, the Commission and ENISA. Your duties sit in Articles 21 and 23 [1].
Can I report an incident directly to EU-CyCLONe?
No. Reporting runs to your national CSIRT or competent authority under Article 23. There is no entity-facing channel [1].
Will I be told if my incident reached EU-CyCLONe?
There is no duty to tell you. Your only information right is the Article 23(5) feedback from the authority you notified [1].
Is EU-CyCLONe the same as the CSIRTs network?
No. The CSIRTs network (Article 15) is technical and composed of CSIRTs plus CERT-EU. EU-CyCLONe (Article 16) is operational-to-political and composed of crisis management authorities. Each decides its own activation independently [1][3].
When was EU-CyCLONe created?
It launched in 2020 as a voluntary network and was formalised on 16 January 2023, when NIS2 entered into force [4].
The Practical Conclusion
EU-CyCLONe is the clearest example of a NIS2 body that shapes what happens to you without ever touching you. There is no threshold to plan for, no notification to expect, and no seat to request — and the honest answer to “what triggers it?” is that 27 Member States’ crisis authorities decide, case by case, with a shared vocabulary still two years away. The useful response is not to prepare for EU-CyCLONe. It is to know which national authority speaks for you there, and to make sure the report you file is good enough to survive the trip upward.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex (linked above). Articles 6(7), 8, 9, 10, 15, 16, 23; Recitals 68 and 71.
- NIS 2 Directive, Article 16: European cyber crisis liaison organisation network (EU-CyCLONe) — article-level text of the final Official Journal wording.
- Council Recommendation of 6 June 2025 on an EU blueprint for cyber crisis management (C/2025/3445), OJ C, 20.6.2025 — EUR-Lex (linked above). Non-binding.
- EU CyCLONe — European Union Agency for Cybersecurity (ENISA).
- BlueOLEx 2024 exercise: EU-CyCLONe test its cyber crisis response preparedness — ENISA, 8 November 2024 (linked above).
- NIS2 Directive — Germany — European Commission, Shaping Europe’s digital future (linked above).
- Regulation (EU) 2025/38 (Cyber Solidarity Act) — EUR-Lex (linked above). Articles 14 and 15.
- Council Implementing Decision (EU) 2018/1993 — EU Integrated Political Crisis Response (IPCR) arrangements.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
