NIS 2 Response Controls (RS): Signaling and Investigation Operating Model

The NIS 2 Response (RS) domain requires structured incident response through signaling, investigation, and iterative decision loops. Practical guide to escalation, evidence integrity, and notification handoff.

February 05, 2026 3 min read

A hand filling in a printed form to classify an incident Made with AI
Contents
  1. Key takeaways
  2. Signaling and investigation sequence
  3. Minimum evidence set for RS signaling/investigation
  4. 90-day execution checklist
  5. FAQ
  6. Related reading
  7. Official sources

Within the NIS baseline framework, the Response domain (RS) requires entities to execute incident response through structured sub-phases, including signaling and investigation. Operationally, this means teams must classify events, escalate appropriately, preserve evidence, and maintain a consistent flow toward decision and notification points.

Sources: ACN incident management guidance, ACN baseline obligations determination

Key takeaways

  • Response should be run through documented phases, not ad hoc actions.
  • Signaling and investigation are iterative and may loop as new evidence emerges.
  • Roles and contacts for escalation and external interfaces must be pre-assigned.
  • Investigation quality depends on evidence integrity, event correlation, and timeline reconstruction.

Sources: ACN incident management guidance

Signaling and investigation sequence

1. Event signaling and escalation

Teams should signal relevant events rapidly through predefined channels, with clear thresholds for escalation and decision ownership.

2. Initial response coordination (RS.MA)

The incident-response plan should activate procedures, responsibilities, and communication flows for management, technical teams, and external stakeholders.

3. Investigation workflow

Investigation should collect forensic evidence, correlate logs and artifacts, and build an evolving timeline of attacker actions and service impact.

4. Iterative decision loop

As investigation findings evolve, teams may return to signaling/escalation steps, refine incident qualification, and update response priorities.

5. Preparation for notification and containment handoff

Signaling and investigation outputs should be structured so they can support notification obligations and downstream containment/eradication actions.

Sources: ACN incident management guidance, ACN baseline obligations determination

Minimum evidence set for RS signaling/investigation

RS area Practical objective Typical evidence
Signaling governanceFast and repeatable event escalationSignaling SOP, escalation matrix, contact list
Response activationCoordinated incident-response executionIncident playbook, activation records
Investigation integrityReliable technical and forensic analysisEvidence log, chain-of-custody records, analysis notes
Timeline reconstructionCoherent sequence of incident evolutionEvent timeline, correlated log artifacts
Decision traceabilityDocumented response decisions and updatesDecision register, incident status reports

Sources: ACN incident management guidance

90-day execution checklist

  1. Validate signaling thresholds and escalation ownership across cyber, operations, and legal teams.
  2. Test response-plan activation in a scenario with partial information and evolving evidence.
  3. Standardize investigation templates for evidence capture, correlation, and timeline building.
  4. Define criteria for when signaling returns to deeper investigation before new response actions.
  5. Ensure incident records can support both governance review and external reporting when required.

FAQ

Are signaling and investigation linear steps?

No. Guidance indicates response sub-phases can be iterative as new evidence changes incident understanding. Source: ACN incident management guidance

What is the minimum requirement for investigation evidence?

At minimum, organizations should preserve and document relevant evidence, correlation logic, and timeline updates supporting response decisions. Source: ACN incident management guidance

How does this phase connect to notification?

Signaling and investigation provide the factual basis used to determine whether notification obligations apply and what information is reported. Sources: ACN incident management guidance, ACN baseline obligations determination

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 06, 2026

NIS 2 Response Controls (RS): Containment and Eradication in Incident Handling

Containment and eradication are iterative response steps that limit damage and remove attacker persistence. Practical guide to strategy selection, ev…

February 04, 2026

NIS 2 Detection Controls (DE): Event Monitoring and Adversarial Signal Handling

The NIS 2 Detection (DE) domain requires monitoring networks, services, and endpoints to identify adverse events early. Practical guide to log readin…

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…