CSIRT Representative: what’s changing in 2026 and how to manage the role

For all NIS2 entities included in the 2025 list, the designation of the CSIRT Representative was completed on 31 December. In 2026, the focus shifted to ensuring that the role is fully operational within the incident management process. Meanwhile, the framework established by ACN has become more consolidated. For entities entering the NIS2 scope in 2026, the designation must be completed by 31 December 2026, while the notification obligation will apply from 1 January 2027.

The new context introduced by the NIS2 Directive

With the implementation of the NIS2 Directive, cyber incident management requires a structured organisational approach, in which the CSIRT Representative acts as the operational point of contact for managing incident notifications.

During 2026, ACN further consolidated the operational framework through new guidance dedicated to incident management, formally integrating the CSIRT Representative into the cybersecurity organisation of NIS entities.

The role becomes particularly relevant when an event is detected and must be assessed, as the effectiveness of the notification process depends on the Representative’s ability to rapidly access the information produced during the incident analysis.

CSIRT Representative and NIS2 Point of Contact: two distinct roles

The CSIRT Representative is the person appointed to liaise with CSIRT Italia and manage the required notifications. The Point of Contact, on the other hand, manages the broader relationship with ACN in connection with NIS2 compliance requirements.

In smaller organisations, the two roles may be assigned to the same person, provided that the requirements established for the Point of Contact are met. Maintaining a clear distinction between the two functions remains useful for defining how information is managed during an incident and how communications with CSIRT Italia are handled.

Management bodies also retain the responsibilities established under the NIS framework and must receive appropriate information regarding relevant incidents.

Required skills: technical expertise, governance and operational readiness

The CSIRT Representative must combine advanced technical expertise with a strong understanding of the organisation.

Experience in incident response, digital forensics, threat intelligence and SOC management is required, together with knowledge of international standards and frameworks such as:

  • ISO/IEC 27035 for incident management
  • NIST SP 800-61r2 for the incident response lifecycle
  • ISO/IEC 27001:2022 for governance
  • MITRE ATT&CK and D3FEND for the classification of adversarial behaviours

Incident management under NIS2: a defined timeline

NIS2 establishes a three-stage procedure for the notification of significant incidents:

  • Within 24 hours – submission of an early warning to the national CSIRT, including the first available information on the impact.
  • Within 72 hours – submission of a complete incident notification including technical and operational details.
  • Within one month – submission of a final report including root cause analysis, actual impacts and corrective measures.

The CSIRT Representative coordinates this process: receiving and classifying the event, coordinating technical teams, communicating with the CISO, DPO and management, and overseeing containment activities.

The role operates in close coordination with the SOC, whether internal or external, and with telemetry and correlation platforms such as SIEM, SOAR and MISP, ensuring information consistency throughout the entire decision-making chain.

Organisational positioning and governance models

The organisational positioning of the CSIRT Representative depends on the organisation’s structure and its security management model. The role may be assigned to an internal resource or to an external party, provided that the person has sufficient knowledge of the organisational context and can access the information required during an incident.

It is essential to define how the Representative is integrated into incident management: when the role must be activated and how information is provided, so that notifications can be managed while technical activities are still ongoing.

This coordination becomes even more important when security activities are partially managed by external providers, as delays in transferring information may directly affect notification timelines.

The CSIRT Representative within the NIS2 operating model

In 2026, the role of the CSIRT Representative entered a different phase compared with the initial implementation period of NIS2. For many organisations, the designation process has already been completed, and attention is now shifting towards how effectively the role operates during an actual incident.

The Representative’s ability to meet the required timelines depends on the connection with the teams managing the event and on having access to relevant information while the technical investigation is still underway.

For organisations that have already completed the designation process, the key issue in 2026 is therefore the effective integration of the CSIRT Representative into the organisation’s incident management framework.

The quality of this integration directly affects the organisation’s ability to maintain timely communication with CSIRT Italia while it is still assessing the scope and impact of the incident.

Recommended Articles

August 31, 2026

From technical data to strategic decision-making: how Cyber Risk Management will evolve in 2027

In recent years, Cyber Risk Management has undergone a profound transformation, driven by regulatory developments and steadily increasing technological complexity. Together, these forces have expanded organizations’ […]
June 16, 2026

The mouse in the closet metaphor in the cyber ​​world: why it’s important to keep track of all your applications

In many organizations, application risk gets associated mainly with the most visible systems, the ones that support essential processes and therefore stay under the constant attention […]
March 24, 2026

Adopting AI without governing it: the new systemic risk for enterprises

Artificial intelligence is rapidly entering business processes, influencing operational decisions, customer interactions, and business models. However, the discussion often tends to focus on technological aspects, while […]
February 10, 2026

From control to awareness: how Cyber Risk Management is changing

The historical model: control, inventories, assessments For many years, Cyber Risk Management was interpreted as a simple control exercise, limited to specific and infrequent moments in […]
January 23, 2026

5 Cyber ​​Risk Questions Every Company Should Know How to Answer in 2026

In recent years, Cyber Risk has been undergoing continuous transformation in terms of regulations, technologies, and methodological approaches. This transformation is often addressed by building increasingly […]