NIS 2 Directive
Security

Incident Handling & Reporting Policy Template

Defines procedures for detecting, managing, and reporting significant cybersecurity incidents, including the mandatory 24-hour early warning to the CSIRT under NIS 2 Article 23.

What This Policy Covers

Purpose and Scope-Policy objectives and NIS 2 incident reporting obligations.
Incident Classification-Severity levels and significant incident criteria under NIS 2.
Detection and Initial Response-Alert triage and initial containment procedures.
24-Hour Early Warning-Mandatory early warning to CSIRT within 24 hours of awareness.
72-Hour Incident Notification-Formal notification including initial assessment and IoCs.
Containment, Eradication, and Recovery-Step-by-step response and restoration procedures.
Final Report and Lessons Learned-One-month final report and post-incident review.
Roles and Responsibilities-Incident response team structure and CSIRT coordination.

Required Sections

A compliant Incident Handling & Reporting Policy for NIS 2 Directive must include the following8 sections. Each section addresses a specific control requirement that auditors will review.

1

Purpose and Scope

Policy objectives and NIS 2 incident reporting obligations.

2

Incident Classification

Severity levels and significant incident criteria under NIS 2.

3

Detection and Initial Response

Alert triage and initial containment procedures.

4

24-Hour Early Warning

Mandatory early warning to CSIRT within 24 hours of awareness.

5

72-Hour Incident Notification

Formal notification including initial assessment and IoCs.

6

Containment, Eradication, and Recovery

Step-by-step response and restoration procedures.

7

Final Report and Lessons Learned

One-month final report and post-incident review.

8

Roles and Responsibilities

Incident response team structure and CSIRT coordination.

Generate a Customized Version

This template shows the required structure. PoliWriter generates a fully customized Incident Handling & Reporting Policy that references your actual cloud providers, identity systems, tools, and team practices — ready for auditor review.

Policy Details

Category

Security

Sections

8 total (8 required)

Other NIS 2 Directive Templates