NIS 2 Incident Typology Model: Condition, Compromise, and Affected Object

ACN baseline guidance classifies significant incidents through condition, compromise, and object of compromise. Practical guide to using the typology model for consistent classification and notification decisions.

February 10, 2026 2 min read

A hand filling in a printed form to classify an incident Made with AI
Contents
  1. Key takeaways
  2. Model components in practice
  3. How to use the model in operations
  4. 90-day implementation checklist
  5. FAQ
  6. Related reading
  7. Official sources

The ACN baseline guidance describes significant-incident typologies through a practical model built on three elements: condition, compromise, and object of compromise. This model helps organizations decide when notification obligations are triggered and how incidents should be classified consistently.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Key takeaways

  • The typology model supports repeatable qualification of significant incidents.
  • The triggering condition is linked to the entity having evidence of the incident.
  • Compromise type and object of compromise determine how the event is framed in notification workflows.
  • Details for each incident code are defined in official baseline documentation.

Sources: ACN baseline reading guide

Model components in practice

1. Condition

The condition is the circumstance that triggers notification obligations. In operational terms, this is tied to the moment the organization acquires evidence of a relevant incident.

2. Compromise

Compromise describes the nature of the security event (for example, loss of confidentiality, loss of integrity, or service-level violation, depending on the applicable typology).

3. Object of compromise

The object identifies what is impacted, such as data or service/network components, according to the incident typology in scope.

Sources: ACN baseline reading guide, ACN baseline obligations determination

How to use the model in operations

Step Operational question Expected output
Evidence checkpointDo we have objective evidence of incident occurrence?Timestamped evidence record
Typology mappingWhich compromise pattern applies?Incident-type classification
Object identificationWhat asset/service/data set is affected?Impact object statement
Decision supportDoes the case meet notification criteria?Escalation and notification decision

Sources: ACN baseline reading guide

90-day implementation checklist

  1. Standardize incident records with explicit fields for condition, compromise, and object.
  2. Align SOC/CSIRT triage to the typology model before escalation decisions.
  3. Define evidence-quality criteria for "incident evidence acquired" checkpoints.
  4. Run simulation drills to test consistent typology assignment across teams.
  5. Maintain a decision log linking typology assessment to notification outcomes.

FAQ

Does the model replace technical investigation?

No. The model structures classification and notification decisions, while technical investigation remains necessary to determine scope and root causes. Source: ACN baseline reading guide

When does the notification clock start?

The timing references are tied to when the organization has evidence of a significant incident, as defined in official documentation. Source: ACN baseline reading guide

Where are code-level details (IS categories) defined?

Details are defined in the official call documentation and ACN baseline annexes. Source: ACN baseline obligations determination

Related guides in this series

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…

February 13, 2026

NIS 2 Significant Incident IS-3: Violation of Expected Service Levels

IS-3 in the ACN baseline model covers service-level violation incidents affecting entity services and activities. Practical guide to qualification, s…

February 12, 2026

NIS 2 Significant Incident IS-2: Integrity Loss Affecting Digital Data

IS-2 in the ACN baseline model covers integrity loss affecting digital data under entity ownership or control. Practical guide to qualification, evid…