NIS 2 Significant Incident IS-2: Integrity Loss Affecting Digital Data

IS-2 in the ACN baseline model covers integrity loss affecting digital data under entity ownership or control. Practical guide to qualification, evidence capture, and escalation workflow.

February 12, 2026 2 min read

A hand filling in a printed form to classify an incident Made with AI
Contents
  1. Key takeaways
  2. IS-2 qualification model
  3. Operational handling steps for IS-2
  4. 90-day implementation checklist
  5. FAQ
  6. Related reading
  7. Official sources

In the ACN baseline typology, IS-2 addresses incidents where the entity has evidence of integrity loss involving digital data under its ownership or control. Operationally, teams should confirm unauthorized data alteration, assess external impact, and activate escalation/notification decision flow.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Key takeaways

  • IS-2 is tied to integrity-loss compromise patterns.
  • Qualification requires evidence of incident occurrence.
  • The compromise object is digital data owned/controlled by the entity.
  • Official typology mapping (condition, compromise, object) should drive decision consistency.

Sources: ACN baseline reading guide

IS-2 qualification model

1. Condition

The entity has evidence that a relevant incident occurred.

2. Compromise pattern

The compromise corresponds to integrity loss, including unauthorized modification with external impact as described by official guidance.

3. Object of compromise

The impacted object is digital data within the entity ownership/control perimeter.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Operational handling steps for IS-2

Step Control question Expected output
Evidence captureDo we have objective evidence of unauthorized data modification?Timestamped evidence record
Data-impact scopeWhich data sets and dependent processes are affected?Integrity-impact scope statement
Escalation decisionDoes the case meet significant-incident criteria?Escalation decision log
Notification readinessIs incident information structured for authority workflow?Structured incident brief

Sources: ACN baseline reading guide

90-day implementation checklist

  1. Add IS-2 decision criteria into triage and investigation templates.
  2. Standardize evidence collection for integrity-modification events.
  3. Define workflow for mapping impacted data and downstream process effects.
  4. Run incident drills focused on integrity compromise with external impact.
  5. Keep traceable linkage between IS-2 qualification and escalation outcomes.

FAQ

Is any data inconsistency automatically IS-2?

No. Qualification depends on official typology criteria and documented incident evidence. Source: ACN baseline reading guide

What is the relevant incident trigger point?

The trigger is tied to when the entity acquires evidence of the significant incident, as defined in official guidance. Source: ACN baseline reading guide For these steps we offer a NIS 2 incident notification service.

Which data perimeter is considered for IS-2?

Digital data owned by the entity or data over which it exercises control, according to baseline definitions. Source: ACN baseline reading guide

Related guides in this series

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 13, 2026

NIS 2 Significant Incident IS-3: Violation of Expected Service Levels

IS-3 in the ACN baseline model covers service-level violation incidents affecting entity services and activities. Practical guide to qualification, s…

February 11, 2026

NIS 2 Significant Incident IS-1: Confidentiality Loss Affecting Digital Data

IS-1 in the ACN baseline model covers confidentiality loss affecting digital data under entity ownership or control. Practical guide to qualification…

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…