Skip to main content
Art. 21(2)(b)Last updated: May 2026

NIS2 Incident Response Planner

Define your team roles, P1/P2/P3 severity criteria, and NIS2 reporting triggers. The output is a print-ready quick reference card for your incident response team.

1
2
3
4

This planner helps you build a NIS2-compliant incident response quick reference card. Fill in your team roles and severity levels and you get a card your team can use on the day.

👥

Step 1: Assign team roles

Name the person responsible for each role in an incident.

🔴

Step 2: Define severity levels

Set P1/P2/P3 criteria specific to your organisation.

📋

Step 3: Get your card

Review your complete IR quick reference, ready to print.

NIS2 requirement: Article 21(2)(b) requires formal incident response plans with defined roles, classification criteria, and escalation paths linked to the 24-72-1 reporting obligation.
📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →

NIS2 Article 21(2)(b): What is Required?

Article 21(2)(b) of the NIS2 Directive requires formal incident handling plans covering detection, containment, eradication, recovery, and post-incident review.

The plan must include escalation paths and classification criteria tied to the NIS2 reporting obligation under Article 23: early warning within 24 hours, full notification within 72 hours, and a final report within 1 month.

What Counts as a Significant Incident?

Not every incident triggers NIS2 reporting. An incident is significant if it meets at least one of the following criteria:

  • Considerable disruption of the services provided or financial loss for the entity
  • Impact on other natural or legal persons by causing considerable material or non-material damage
  • Unauthorised access to the network and information systems
  • Incidents affecting a significant number of users or critical operations