Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
NIS2
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Entity of a type listed in Annex I or II, medium-sized or larger, active in the Union
Entity covered irrespective of its size
Essential entity
Important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks
TLD name registries and entities providing domain name registration services
Essential or important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks without an establishment in the Union
Company in NACE Rev. 2 Section C divisions 26 to 30, medium-sized or larger, active in the Union
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
No later than one month after the notification under Article 23(4), point (b), the entity submits a final report. It contains a detailed description of the incident, including its severity and impact, the type of threat or root cause that is likely to have triggered the incident, the applied and ongoing mitigation measures and, where applicable, the cross-border impact. Two variants belong to the same task: on the request of a CSIRT or the competent authority, the entity submits an intermediate report on relevant status updates (Article 23(4), point (c)). Where the incident is still ongoing at the time the final report is due, the entity submits a progress report at that time and the final report within one month of handling the incident (Article 23(4), point (e)).
Description (German)
Spätestens einen Monat nach der Meldung nach Artikel 23 Absatz 4 Buchstabe b legt die Einrichtung einen Abschlussbericht vor. Er enthält eine ausführliche Beschreibung des Sicherheitsvorfalls einschließlich seines Schweregrads und seiner Auswirkungen, Angaben zur Art der Bedrohung und zur zugrunde liegenden Ursache, Angaben zu den getroffenen und laufenden Abhilfemaßnahmen sowie gegebenenfalls die grenzüberschreitenden Auswirkungen. Zwei Varianten gehören zu derselben Aufgabe: Auf Ersuchen eines CSIRT oder der zuständigen Behörde legt die Einrichtung zwischenzeitlich einen Zwischenbericht über relevante Statusaktualisierungen vor (Artikel 23 Absatz 4 Buchstabe c). Dauert der Sicherheitsvorfall zum Zeitpunkt der Vorlage des Abschlussberichts noch an, legt die Einrichtung zu diesem Zeitpunkt einen Fortschrittsbericht und den Abschlussbericht innerhalb eines Monats nach Behandlung des Sicherheitsvorfalls vor (Artikel 23 Absatz 4 Buchstabe e).
Affected products/services (English)
Affected products/services (German)
Checking responsibility (English)
The notifying entity; the recipient is the CSIRT or, where applicable, the competent authority.
Checking responsibility (German)
Die meldende Einrichtung; Empfänger ist das CSIRT oder gegebenenfalls die zuständige Behörde.
Check method (English)
Check method (German)
Withdrawn at
Cancel
Delete this obligation