Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

N.1.22 Reporting incidents to external parties

Control Overview

This control mandates that the organization implements a formalized procedure to meet its strict legal and contractual incident notification obligations. Under the NIS 2 directive, entities must maintain clear mechanisms to report "significant incidents" to competent national authorities, government bodies, and Computer Security Incident Response Teams (CSIRTs) within mandatory statutory timelines (such as the initial 24-hour early warning and 72-hour incident notification rules). Additionally, the control requires that contractually mandated notifications to clients, suppliers, and other external stakeholders are executed systematically, ensuring transparent communication and minimizing financial or reputational damage.

note

Applicability Note: This control is fully applicable to the anDREa platform and establishes the mandatory regulatory interface between our internal operations and external regulatory oversight bodies.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement incorporates statutory reporting directly into our ISO/IEC 27001-based ISMS, linking technical impact analysis to our external compliance workflows.

We have expanded our incident response procedures with a dedicated NIS 2 Significant Incident Reporting module. This module provides clear, objective criteria to determine if an incident reaches the regulatory threshold of "significant" (such as severe operational disruption, substantial financial impact, or material downstream damage to our clients). Ultimate accountability for executing these external declarations is assigned directly to the Director. Furthermore, this workflow runs alongside our existing GDPR data breach reporting protocols, ensuring that both data privacy and critical infrastructure notification paths are executed simultaneously and without friction.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.05.26 - Response to information security incidentsControls the execution of communication routing, notification templates, and formal external reports during a breach.
ISO/IEC 27001A.05.31 - Legal, statutory, regulatory and contractual requirementsMandates a complete register of all external legal and contractual requirements to ensure organizational compliance.
Incident FrameworkNIS 2 Significant Incident Reporting ProtocolThe formal procedure defining significance thresholds, regulatory contact matrices, and mandatory statutory timelines (24h / 72h).
Continuity GovernanceDisaster Recovery PlanDirect operational guidelines defining secure, out-of-band communication channels for notifying external stakeholders outside of business hours.
Privacy OperationsData Breach ProcedureDedicated regulatory workflow specifically governing GDPR-mandated notifications to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected data subjects.

Audit Summary

  • Compliance Status: Fully Compliant
  • Gaps Identified: None. Clear threshold definitions, operational communication protocols, and regulatory notification workflows are fully operationalized and bound to executive authority.