Abstract blue network of connected nodes representing a coordinated NIS2 incident response exercise

How to Facilitate a NIS2 Tabletop Exercise: The 4-Week Countdown, the Two Roles to Split, and the Hotwash That Becomes Your Evidence

The exercise is not the deliverable. The record of it is. A competent authority will never watch you run a tabletop, so everything it can assess comes from three artefacts: the plan you wrote before, the notes someone took during, and the corrective actions you closed after. Facilitation is the craft of producing those three things while a roomful of people argue about a fictional ransomware note.

This is the guide for the person handed that job. If you are still choosing scenarios or building a scoring rubric, start with our companion piece on NIS2 tabletop exercise scenarios and scoring; for the technical, inject-driven variant, see NIS2 incident simulation design.

What NIS2 Requires You to Test — and the Word It Never Uses

In plain terms: NIS2 never mentions tabletop exercises. It requires you to test your incident handling procedures, your continuity and recovery plans, and your crisis management plan, and to hold a policy for judging whether your measures work at all. A tabletop is one accepted way to do that, not the requirement itself.

Article 21(2) of Directive (EU) 2022/2555 lists ten measure areas. Three carry your exercise: (b) incident handling, (c) business continuity, such as backup management and disaster recovery, and crisis management, and (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures [1][2]. The words "exercise", "tabletop", "drill" and "test" appear in none of the ten points. That absence cuts both ways: nobody can tell you your format is wrong, and nobody will accept the format alone as proof.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The detail sits one level down, in Commission Implementing Regulation (EU) 2024/2690, whose Annex carries three separate testing duties — reproduced verbatim in ENISA’s official implementation guidance [3]. Annex 3.1.3: the roles, responsibilities and procedures in your incident handling policy "shall be tested and reviewed and, where appropriate, updated at planned intervals and after significant incidents or significant changes to operations or risks". Annex 4.1.4: the business continuity and disaster recovery plans shall be tested at planned intervals, and entities "shall ensure that the plans incorporate lessons learnt from such tests". Annex 4.3.4: the crisis management plan shall be tested "on a regular basis or following significant incidents or significant changes to operations or risks".

Read the modal verbs. The regulation says at planned intervals and on a regular basis. It does not say annually. The annual cadence quoted everywhere as law comes from ENISA’s guidance under those same points — "Test the crisis management process annually" — and ENISA states that its guidance "is not legally binding and is only recommendations" [3]. Annual is the sensible default and the number a supervisor will have in mind. It is not the text.

ENISA does name the formats. Under 3.1.3 it lists four ways to test an incident handling policy: a tabletop exercise, a simulation based on a selected attack scenario, a red team/blue team exercise, and a past incident walk-through [3].

Does the Implementing Regulation Bind You?

Your entity Status of CIR 2024/2690 What that means
One of the eleven CIR Article 1 categories: DNS, TLD registries, cloud, data centres, CDNs, MSPs, MSSPs, marketplaces, search engines, social platforms, trust services Directly binding Annex 3.1.3, 4.1.4 and 4.3.4 are your requirements. Evidence each separately.
Any other essential or important entity: energy, transport, health, water, manufacturing, public administration Not binding Article 21(2)(b), (c) and (f) still bind. The Annex is the best interpretive reference, alongside national guidance.
Below the size thresholds, no sector-specific trigger Not applicable No NIS2 duty. The method below still works.

For the wider map, see our breakdown of Article 21’s ten security measures and the ENISA technical implementation guidance.

Who Is Allowed to Facilitate Your Own Exercise

In plain terms: Nothing in NIS2 says the facilitator must be independent. But the Annex requires you to write down who runs the test and who judges the result, and it sets an impartiality standard nearby that is hard to argue against once you have read it.

Annex 7.1 is the Article 21(2)(f) provision: entities "shall establish, implement and apply a policy and procedures to assess whether the cybersecurity risk-management measures taken by the relevant entity are effectively implemented and maintained" [3]. Annex 7.2 then forces six determinations, two of which nobody reads as staffing rules: (d) who is responsible for monitoring and measuring the effectiveness of the measures, and (f) who has to analyse and evaluate these results.

That is the facilitator and the evaluator, named in a regulation without either word appearing. NIST splits the job the same way and is more direct: the design team "usually designates an exercise facilitator, who leads the discussion among the exercise participants, and a data collector, who records information about the actions that occur during the exercise" [4]. One person cannot do both well — running a discussion consumes exactly the attention accurate note-taking needs.

On independence, be precise. The CIR imposes a hard impartiality rule on independent reviews, not on exercises: under Annex 2.3.2, an internal reviewer "shall not be in the line of authority of the personnel of the area under review", and where the entity is too small for that separation it "shall put in place alternative measures to guarantee the impartiality of the reviews" [3]. ENISA pulls that standard across into the effectiveness chapter, advising that employees running effectiveness assessments "should not come from the department or division whose systems are being inspected".

So the honest position is a ladder, and it is our reading rather than the regulation’s. Weakest: the author of the incident response plan facilitates the test of it and writes the report — every finding is self-marked. Workable: an internal facilitator from outside the tested function, with a note-taker from a third team. Strongest for a first cycle: internal facilitator with an external evaluator, or the reverse. Commercial guides often assert that an external facilitator is non-negotiable; that claim has no regulatory basis. The separation of the two roles does.

Run the Exercise You Are Actually Ready For

In plain terms: A discussion-based tabletop needs almost nothing except a written plan to discuss. Anything more ambitious has prerequisites, and running it early produces a failed exercise and a worse evidence record than running nothing.

Germany’s BSI — the national competent authority there — publishes a full exercise toolkit whose exercise-type table is the most useful readiness gate available in the EU [7]. It rates each format on complexity, effort and, crucially, the BCM maturity level needed before attempting it.

Format (BSI term) Prerequisite Complexity Maturity needed
Plan-Review — desk review of the document A plan or concept exists Low Low
Planbesprechung — scenario discussion, glossed by BSI itself as Table Top A plan or concept exists Low Low
Stabsübung — crisis-team exercise Communication paths and decision processes inside the crisis team are defined Low to medium Medium
Stabsrahmenübung — crisis team plus operational teams As above, plus agreed coordination with operational teams Medium to high High
Simulation or Vollübung — full simulation, live exercise The emergency organisation is implemented in structure and process High to very high High

The hard gate sits underneath. BSI states that every exercise of medium complexity or above presupposes four phases already completed once: initiation of emergency management, design including business impact and risk analysis, implementation of the continuity concept, and a documented emergency handbook [7]. For a simple discussion at the green table, "no special prerequisites are necessary other than the existence of the emergency plan."

So if you hold a business continuity plan and a crisis management plan on paper but have never run either, the tabletop is the correct first exercise, not a compromise. And because BSI advises raising complexity in steps, your programme is a multi-year ladder — say so in the report. A supervisor reading "year one tabletop, year two crisis-team exercise, year three partial simulation" sees a programme; reading "we ran a tabletop" three years running, they see a plateau.

The Four-Week Countdown

In plain terms: Four weeks is the working minimum for a single-entity tabletop. Below that the scenario gets thin and the invitation lands too late for senior people to attend, which is the most common way these exercises fail.

NIST sets the floor: "planning for exercises typically starts at least one month in advance (three months for large, complex exercises)" [4]. CISA’s fourteen-step programme for critical-infrastructure exercises assumes three months or more, with a T-minus marker on every step — concept and objectives at three months, midterm planning at six to eight weeks, invitations at five to seven weeks, final planning at two weeks [6].

The track below compresses that sequence for one organisation running an internal exercise. It is practical guidance, not a standard, and it works because CISA sanctions the compression that saves the most time: "The C&O and Initial Planning Meeting (IPM) can be combined to shorten the planning timeline" [6].

When What the facilitator does Effort
T−4 weeks Write a one-page mandate: which plan is on trial, three to five objectives, scope boundaries, what is explicitly out of play. Name the facilitator and note-taker in writing — that is your Annex 7.2(d)/(f) answer. Book the room, issue the calendar hold. Medium
T−3 weeks Build the facilitator guide on NIST’s four-part structure: purpose; scope and objectives; the scenario as a sequential narrative; the question bank [4]. Write more questions than you expect to need. High
T−2 weeks Send the invitation from management, not from the security team; CISA is specific that it "should come from your organization’s management" [6]. Freeze the scope, walk the question bank through with the note-taker, agree the capture fields. No major design changes after this point. Medium
T−1 week Send the participant pack. NIST’s timing is worth obeying: roughly a week ahead, because "if they are sent too far in advance, the content may be forgotten" [4]. Confirm logistics, prepare the room. Low
T−0 Run it. Nothing new is designed on the day. High

One thing does not compress. Compress the planning meetings; never compress the question bank.

The 150-Minute Room

NIST puts typical tabletop duration at two to eight hours [4]. For a NIS2 exercise built around notification decisions the short end is right: the interesting failures surface in the first ninety minutes, and executives who leave early take the evidence with them.

Clock Block What the facilitator listens for
0:00–0:10 Welcome, self-introductions by name and role, ground rules Who is missing, and whose deputy came instead
0:10–0:20 Briefing: scope, objectives, what is out of play Anyone who thinks this tests them rather than the plan
0:20–0:50 Module 1 — detection and awareness The moment someone says the clock has started, and on what basis
0:50–1:20 Module 2 — classification and the 24-hour decision Whether anyone can name who signs the early warning, and whether they reach for the significance test or for instinct
1:20–1:30 Break The corridor remark that contradicts what was said at the table
1:30–2:00 Module 3 — containment, continuity, customer communications Whether continuity activation and containment are sequenced or assumed
2:00–2:15 Module 4 — the 72-hour update and the board What the room thinks it must send at 72 hours versus what it may hold back
2:15–2:30 Hotwash, players still present Self-assessment in their own words, on the record

Seat people away from their own teams. NIST’s reasoning is that mixed seating "encourage[s] independent thought processes and provide[s] exposure to other operational areas" [4]; in practice it breaks the habit of a department caucusing before answering. The rest of the job is group management.

CISA’s competency list is candid about it: keep side conversations to a minimum, hold discussion within time limits, "control group dynamics and strong personalities", and speak competently "without dominating conversation" [5]. Three failure modes account for most bad exercises:

  • The dominant voice. One senior person answers everything and the room defers. Direct questions by role, not to the table: "Legal, at this point, what is your advice?"
  • Resolution by assertion. Someone says "we would just call the CSIRT" and the group moves on. The follow-up is always: who, using which contact details, from which document, saying what?
  • The plan-versus-practice gap. The room describes what it would really do, which is not what the plan says. Do not correct it. That divergence is the most valuable finding an exercise produces — make sure the note-taker captures both versions.

What the Note-Taker Captures — and Never Does

Notes are the evidence, so capture decisions in fixed fields rather than prose. CISA’s evaluator handbook gives five [5]: who, by name or position, made the decision; what occurred; why, meaning the trigger; how, meaning the process; and the outcome, including who owns any solution and by when. Two NIS2-specific fields complete the template:

Field Why it earns its place
Who decided (name or role) Annex 7.2(d) wants named responsibility; a role nobody in the room can name is itself a finding
What was decided The observable event the report is built on
Trigger Separates a decision driven by the plan from one driven by a person
Process used Names the document actually reached for, often not the one you were testing
Outcome, owner, timeframe Feeds the improvement plan directly, with no re-interviewing
Deviation from the written plan Annex 4.1.4 requires plans to incorporate lessons learnt; a deviation is a lesson with a document reference attached
Clock reference Records what the room believed about the 24-hour and 72-hour points, the fastest route to a reporting misconception

CISA is equally clear on what the evaluator must not do: do not prompt players, do not get in the way, and do not answer questions for players — refer them to the facilitator [5]. A note-taker who starts helping has destroyed the observation they were there to make.

The Hotwash and the Six Weeks After

Run the hotwash immediately, players still present. NIST frames it as three questions: where did you excel, where would more training help, which parts of the plan should change [4]. CISA adds the ones that generate corrective actions: were the objectives met and why or why not, what were the major gaps, what are the next steps short and long term [5]. Then send the players away and hold a separate facilitator and evaluator debrief — CISA’s "three ups and three downs", reconciled into common themes [5].

Analysis follows a fixed sequence: review the notes, compare what players said against what the plans say, identify and explain deviations, list recommendations [5]. For each objective not met, find the root cause — "the source of, or underlying reason behind, an identified issue" — not the symptom. A room that missed the 24-hour decision because nobody knew who signs has a governance root cause, not a training one. CISA’s post-exercise clock is worth borrowing: draft the after-action report and improvement plan within three to four weeks, hold the after-action meeting five to six weeks after the exercise, finalise within two weeks of that meeting [6].

BSI adds a split most reports miss: divide both findings and corrective actions into those about the exercise process itself and those about the tested process or asset [7]. "The scenario was too easy" and "the escalation path is undocumented" are different objects with different owners, and merging them lets exercise-design complaints crowd out real compliance findings.

The Evidence Pack and Who Owns It

Every artefact should answer to a requirement. This mapping is ours, built from the Annex points and ENISA’s stated evidence examples [3]:

Artefact Answers to Owner
Exercise mandate and facilitator guide Annex 7.2(a)–(c): what is measured, by what method, and when Facilitator
Written designation of facilitator and evaluator Annex 7.2(d) and (f) CISO or NIS2 officer
Attendance record and participant pack Shows the tested roles were the roles named in the policy; supports the training record Note-taker
Structured observation notes Annex 3.1.3 — "records of testing and drills" is ENISA’s own evidence example Evaluator
After-action report Annex 3.1.3, 4.1.4 and 4.3.4 — that the test happened, and what it found Evaluator
Improvement plan and corrective actions register, with owners and dates Annex 4.1.4’s "incorporate lessons learnt", and Article 21(4)’s duty to take corrective measures without undue delay [2] Compliance officer
Updated plan versions with change history Closes the loop: the plan changed because the test found something Plan owner
Management sign-off on the results Article 20 oversight; keeps the board’s Article 21 approval current Management body

The most common gap is the last two rows: organisations run the exercise, write the report, and never update the plan — leaving a documented finding with no documented remedy. That is worse than not testing, and an audit preparation review surfaces it first. If the underlying documents are not in shape, fix the incident response policy, plan and playbook hierarchy before booking a room.

Frequently Asked Questions

Does NIS2 legally require an annual tabletop exercise?

No. CIR 2024/2690 requires testing "at planned intervals" and "on a regular basis". The annual figure comes from ENISA’s guidance, which is expressly non-binding [3]. Annual is a defensible default and the cadence a supervisor will expect, but a documented risk-based interval is a legitimate alternative.

Can the CISO facilitate the exercise?

Nothing prohibits it. But if the CISO owns the plan being tested, the exercise is self-marked. The workable minimum is a facilitator from outside the function under test plus a note-taker from a third team — the pattern Annex 2.3.2 imposes for independent reviews, applied here voluntarily [3].

How long should a NIS2 tabletop exercise be?

NIST puts typical duration at two to eight hours [4]. For a notification-focused NIS2 exercise, 150 minutes of player time plus a 15-minute staff debrief covers detection, classification, the 24-hour decision, containment and the 72-hour update.

What if we have never run any exercise before?

Start with the discussion-based tabletop. BSI rates it lowest in complexity and lowest in required maturity, with no prerequisite beyond a written plan to discuss; anything at medium complexity or above presupposes a completed business impact analysis, risk analysis and emergency handbook [7].

Do we have to send the exercise report to our competent authority?

No. NIS2 creates no duty to submit exercise reports. They are internal evidence, produced when a supervisor asks how you assess the effectiveness of your measures under Article 21(2)(f).

Key Takeaways

  • Article 21(2) never uses the word "exercise". The testing duties live in CIR Annex 3.1.3, 4.1.4 and 4.3.4; the effectiveness policy in 7.1 and 7.2.
  • "At least annually" is ENISA guidance, not regulation. State your chosen interval and its basis in your own policy.
  • Split facilitation from evaluation and write both names down. That answers Annex 7.2(d) and (f).
  • An exercise with no updated plan and no closed corrective action is a documented failure with no documented remedy.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. Article 21, Directive (EU) 2022/2555 — Cybersecurity risk-management measures (nis2resources.eu, primary-text mirror)
  2. NIS 2 Directive, Article 21 full text (nis-2-directive.com, second independent mirror). Official consolidated text: EUR-Lex, CELEX 32022L2555.
  3. ENISA, Technical Implementation Guidance on Cybersecurity Risk Management Measures, version 1.0, June 2025 — reproduces the Annex to Commission Implementing Regulation (EU) 2024/2690 (EUR-Lex, CELEX 32024R2690) verbatim.
  4. NIST SP 800-84, Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities
  5. CISA, Critical Infrastructure Tabletop Exercise Program — Facilitator / Evaluator Handbook, 2020 (cisa.gov)
  6. CISA Tabletop Exercise Package (CTEP) — Exercise Planner Handbook, 2020 (cisa.gov), the fourteen-step planning timeline
  7. BSI, IT-Notfallmanagement — Übungsbaukasten: Anleitung zur Nutzung (bsi.bund.de), Bundesamt für Sicherheit in der Informationstechnik, 31 August 2022
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: