NIS2 Single Point of Contact: What Article 8 Requires — and Why It’s Not Your Reporting Address
If you are in scope of NIS2 and you go looking for your country’s single point of contact so you can file an incident report there, you are looking at the wrong desk. The single point of contact (SPOC) is an authority-to-authority channel. Under Article 23(1), entities notify their CSIRT or, where applicable, their competent authority — the SPOC is fed by those bodies, not by you.
That distinction matters more than it sounds, because in 16 of the 27 Member State entries the European Commission publishes, the SPOC is the same organisation as the competent authority. Same building, different legal hat — and the hat determines which obligation you are discharging.
What Article 8 Actually Requires
In plain terms: every EU country must name a cybersecurity supervisor, and must also name one office whose job is talking to the other 26 countries. Those can be the same office.
Article 8(1) requires each Member State to “designate or establish one or more competent authorities responsible for cybersecurity and for the supervisory tasks referred to in Chapter VII” — the bodies that supervise you and can fine you. Article 8(3) then requires a single point of contact, and adds a merge rule: “Where a Member State designates or establishes only one competent authority pursuant to paragraph 1, that competent authority shall also be the single point of contact.” [1] That rule is conditional, not general. It forces the merge only where a country has exactly one competent authority. Countries with several are free to merge anyway — most have — but are not obliged to.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
Article 8(4) defines the purpose, and it points in two directions at once. Each SPOC “shall exercise a liaison function to ensure cross-border cooperation of its Member State’s authorities with the relevant authorities of other Member States, and, where appropriate, with the Commission and ENISA, as well as to ensure cross-sectoral cooperation with other competent authorities within its Member State.” [1] Outward to the other Member States; inward across the sectoral regulators at home. Neither direction points at the regulated entity.
Where the SPOC Fits Into Your Article 23 Incident Notification
Your Article 23 clock — 24-hour early warning, 72-hour notification, one-month final report — runs against the CSIRT or the competent authority. The SPOC enters afterwards, and only under specific conditions.
Article 23(1), third subparagraph, touches you only indirectly: “In the case of a cross-border or cross-sectoral significant incident, Member States shall ensure that their single points of contact are provided in due time with relevant information.” [2] The duty falls on the Member State, not on you.
Article 23(8) is narrower, and its trigger is easy to miss: “At the request of the CSIRT or the competent authority, the single point of contact shall forward notifications received pursuant to paragraph 1 to the single points of contact of other affected Member States.” [2] SPOC-to-SPOC forwarding is request-gated — it does not fire automatically because an incident crossed a border. Recital 40, which is interpretive rather than binding, frames the same design: SPOCs “should therefore be tasked with forwarding notifications of significant incidents with cross-border impact… upon the request of the CSIRT or the competent authority.” [4] Article 23(6) sits alongside it, requiring the CSIRT, competent authority or SPOC to inform other affected Member States and ENISA without undue delay where an incident concerns two or more Member States. [2] Under Article 23(9) the SPOC then sends ENISA a quarterly summary of anonymised, aggregated incident data. [2] Your incident becomes a statistic there; it is not a second filing obligation.
The consequence for a group operating across several Member States is unwelcome: SPOC liaison does not consolidate your filings. Each separately established in-scope entity still reports in its own Member State, on its own clock. The rules behind that sit in Article 26 and the main-establishment exception.
The Three Bodies, From Your Side of the Desk
Most explanations list the national bodies and stop. The useful version tells you which one you will actually deal with, and for what.
| Body | Legal basis | What it does | When you deal with it |
|---|---|---|---|
| Competent authority | Art. 8(1)-(2) | Supervises implementation, inspects, enforces, fines | Registration under Art. 27; audits and information requests; enforcement; incident notification where national law routes it here |
| CSIRT | Art. 10-11 | Monitors threats, issues warnings, responds to incidents, assists affected entities, coordinates vulnerability disclosure | Your Art. 23 notifications in most states; technical assistance during an incident; alerts and advisories |
| Single point of contact | Art. 8(3)-(4) | Liaison: cross-border with other Member States, the Commission and ENISA; cross-sectoral at home | Effectively never, directly. It receives your information through the CSIRT or competent authority |
| Crisis management authority | Art. 9 | Manages large-scale cybersecurity incidents and crises; sits in EU-CyCLONe | Only in a national-scale crisis, and usually through your CSIRT |
The fourth row is the one most guides omit. Article 9 requires a separate designation for managing large-scale incidents and crises, notified to the Commission and the EU-CyCLONe network. [6] It is not the SPOC — which is why mapping “our country’s cyber authority” onto a single name usually goes wrong.
Notice the SPOC’s position in the EU architecture. The CSIRTs network is composed of “representatives of the CSIRTs designated or established pursuant to Article 10” plus CERT-EU [8]; the Cooperation Group, of representatives of Member States, the Commission and ENISA [7]; EU-CyCLONe draws on the Article 9 crisis authorities. [6] The directive names the CSIRT and the crisis authority as members of specific Union bodies. It does not name the SPOC as a member of any of them — the SPOC is a bilateral channel between capitals, not a seat at a table.
The Touchpoints You Will Not See
Three provisions route your data or your regulatory exposure through the SPOC without any action on your part.
Cross-border enforcement. Article 37(1)(a) provides that competent authorities applying supervisory or enforcement measures in one Member State shall, “via the single point of contact, inform and consult the competent authorities in the other Member States concerned on the supervisory and enforcement measures taken.” [9] If a regulator opens action against your entity in one country, the SPOC is the pipe through which the other affected regulators hear about it.
Registry data. Under Article 27, listed digital entities — DNS providers, TLD registries, cloud providers, data centres, CDNs, managed service providers, online marketplaces and social platforms — submit their details to the competent authorities. The single points of contact then forward that data to ENISA for the Union registry, without the IP ranges. [10]
Sector-specific regimes. Article 4 disapplies parts of NIS2 where a sector-specific Union act imposes at least equivalent obligations, and Article 4(2)(b) conditions that equivalence on the sector act providing “immediate access, where appropriate automatic and direct, to the incident notifications by the CSIRTs, the competent authorities or the single points of contact” under NIS2. [3] For financial entities reporting under DORA, the SPOC’s visibility is part of the price of the carve-out.
Which Model Does Your Member State Use?
Article 8(6) requires each Member State to notify the Commission of its competent authority and SPOC, to make its competent authority public, and requires that “the Commission shall make a list of the single points of contact publicly available.” [1] That list exists, but not as a list — it is spread across 27 country pages reachable from the Commission’s NIS transposition directory. [12] Treat them as a starting point, not as current law: checked on 20 August 2026, they are still stamped “Last update 7 July 2025” (8 July for Italy) and still label competent authorities using the NIS1 categories — “for DSPs” and “for OES” — which fell away when Article 44 repealed Directive (EU) 2016/1148 with effect from 18 October 2024. [17]
We read all 27 and classified them. In 16 of 27 the SPOC is the same organisation as the listed competent authority. In at least 7 it is also the national CSIRT — a floor rather than a total, because five pages (Croatia, Finland, Italy, Latvia, Poland) do not present a CSIRT entry in a comparable format. In four — Estonia, Germany, Lithuania and Romania — one organisation holds all three roles.
Germany is the fully merged case: the Commission lists the Federal Office for Information Security (BSI) as SPOC and records the competent authority and national CSIRT as “Same as Single point of contact.” [13] German law says it more precisely. BSIG 2025 § 40(1) makes the BSI the “nationale Verbindungsstelle” — national liaison point — as well as the central reporting and contact office, and § 40(2) spells out the Article 8(4) job: coordinating the cross-border and cross-sectoral cooperation of the Länder supervisory authorities, the Bundesnetzagentur and BaFin. [15] Even in the most centralised model, other competent authorities exist; the SPOC coordinates them. Our Germany competent authority guide covers the sectoral split.
Austria is the opposite: three genuinely different organisations — the Federal Ministry of the Interior as SPOC, the Federal Chancellery among the competent authorities, and CERT.at as the national CSIRT. [14] Three bodies, three mandates, and a routing decision you have to get right before you need it. Our Austria competent authority guide tracks the current position.
National positions are still moving, so confirm yours on the national authority’s own site before building a runbook on it. Ireland’s NCSC calls itself the “Lead Competent Authority” for sectors not assigned to other regulators, while noting that “further guidance on thresholds and reporting of incidents will be provided in due course.” [16] Germany’s Commission page records a reasoned opinion sent on 7 May 2025 for failure to notify full transposition. [13]
What to Do With This
Compliance officers: record two names in your incident register, not one — the body you notify under Article 23, and the body that supervises you under Article 8(1). Where they are the same organisation, record the specific portal and form for each function. Do not enter the SPOC as a reporting destination.
CISOs and IT security managers: your operational counterparty is the CSIRT, because Article 11(3) is where the capability sits — threat monitoring, alerts, incident response, forensic support and coordinated vulnerability disclosure. [5] Build that relationship before an incident — our guide to what a CSIRT actually owes you under Article 11 maps which services you have to ask for, and the guide to national CSIRT reporting portals lists where filings land.
Smaller in-scope businesses: you need one answer — which national body receives your report, and on which form. Write it into your response plan with a phone number and stop there; the SPOC is not a step in your process. The incident reporting overview sets out the 24-hour, 72-hour and one-month sequence.
Multi-country operators: map each establishment to its own CSIRT, competent authority and deadline. The SPOC network coordinates authorities; it does not reduce the number of reports you file.
Frequently Asked Questions
Can I send my incident report to the single point of contact? Article 23(1) directs notifications to the CSIRT or, where applicable, the competent authority. [2] In the 16 Member States where the SPOC is also the competent authority, writing to that organisation reaches the right desk — but you are filing with it in its competent-authority capacity, not its SPOC capacity. Use the channel your national authority publishes.
Does the SPOC forward my report to other affected countries automatically? No. Article 23(8) makes SPOC-to-SPOC forwarding conditional on a request from the CSIRT or the competent authority. [2] Separately, Article 23(6) requires the CSIRT, competent authority or SPOC to inform other affected Member States and ENISA where an incident concerns two or more of them. [2]
The Short Version
Of the designations NIS2 requires, only two face you: the competent authority supervises and enforces, the CSIRT receives your notifications and helps during an incident. The single point of contact is the channel between capitals — carrying your incident data across borders under Article 23(8), your registry data to ENISA under Article 27, and news of enforcement against you under Article 37(1)(a), all without you ever addressing an envelope to it. So find out whether your Member State merged these roles into one organisation or split them across three, and write the answer into your incident response plan. In Germany it is one phone number. In Austria it is three.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- NIS2 Directive, Article 8 — Competent authorities and single points of contact
- NIS2 Directive, Article 23 — Reporting obligations
- NIS2 Directive, Article 4 — Sector-specific Union legal acts
- NIS2 Directive, Recitals 24, 39 and 40 (non-binding interpretive text)
- NIS2 Directive, Article 11 — Requirements, technical capabilities and tasks of CSIRTs
- NIS2 Directive, Article 9 — National cyber crisis management frameworks
- NIS2 Directive, Article 14 — Cooperation Group
- NIS2 Directive, Article 15 — CSIRTs network
- NIS2 Directive, Article 37 — Mutual assistance
- NIS2 Directive, Article 27 — Registry of entities
- Directive (EU) 2022/2555 (NIS2) — official text, EUR-Lex
- European Commission — NIS Directive transposition (directory of 27 country pages)
- European Commission — NIS2 Directive implementation in Germany
- European Commission — NIS2 Directive implementation in Austria
- BSIG 2025 (Germany), § 40 — Nationale Verbindungsstelle sowie zentrale Melde- und Anlaufstelle
- National Cyber Security Centre Ireland — NIS2 FAQ
- NIS2 Directive, Article 44 — Repeal of Directive (EU) 2016/1148
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
