NIS 2 Significant Incident IS-3: Violation of Expected Service Levels

IS-3 in the ACN baseline model covers service-level violation incidents affecting entity services and activities. Practical guide to qualification, service-impact mapping, and escalation workflow.

February 13, 2026 2 min read

A hand filling in a printed form to classify an incident Made with AI
Contents
  1. Key takeaways
  2. IS-3 qualification model
  3. Operational handling steps for IS-3
  4. 90-day implementation checklist
  5. FAQ
  6. Related reading
  7. Official sources

In the ACN baseline model, IS-3 covers incidents where the entity has evidence of expected service-level violation. Unlike IS-1 and IS-2, the affected object in IS-3 is the entity’s services or activities, not digital data as a primary object.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Key takeaways

  • IS-3 addresses service-impact scenarios based on expected service levels.
  • Qualification starts from evidence of incident occurrence.
  • Compromise is linked to service-level violation against defined expectations.
  • The affected object is service/activity continuity and performance.

Sources: ACN baseline reading guide

IS-3 qualification model

1. Condition

The organization has evidence that a relevant incident occurred.

2. Compromise pattern

The compromise corresponds to violation of expected service levels defined by the entity’s baseline model.

3. Object of compromise

The compromised object is the services and/or activities provided by the NIS entity.

Sources: ACN baseline reading guide, ACN baseline obligations determination

Operational handling steps for IS-3

Step Control question Expected output
Evidence checkpointDo we have objective evidence of service-level breach?Timestamped evidence log
Service impact mappingWhich services/activities are below expected levels?Service-impact statement
Escalation decisionDoes this meet significant-incident criteria?Escalation and ownership decision
Notification readinessAre impact facts and timeline structured for reporting?Structured incident brief

Sources: ACN baseline reading guide

90-day implementation checklist

  1. Define and maintain expected service-level references used for IS-3 qualification.
  2. Align monitoring and triage workflows to capture service-level breach evidence.
  3. Standardize impact analysis templates for service/activity degradation.
  4. Run crisis simulations focused on service-level violation scenarios.
  5. Keep traceable records linking IS-3 qualification to escalation outcomes.

FAQ

Is every service disruption automatically IS-3?

No. Qualification depends on official IS-3 typology criteria and documented incident evidence. Source: ACN baseline reading guide

What is the key differentiator from IS-1/IS-2?

IS-3 centers on service/activity impact and expected service-level violation, while IS-1/IS-2 primarily concern data compromise patterns. Source: ACN baseline reading guide

When does timing start for related obligations?

Timing references are tied to the point when the entity has evidence of the significant incident, as defined in official guidance. Source: ACN baseline reading guide For these steps we offer a NIS 2 incident notification service.

Related guides in this series

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 12, 2026

NIS 2 Significant Incident IS-2: Integrity Loss Affecting Digital Data

IS-2 in the ACN baseline model covers integrity loss affecting digital data under entity ownership or control. Practical guide to qualification, evid…

February 11, 2026

NIS 2 Significant Incident IS-1: Confidentiality Loss Affecting Digital Data

IS-1 in the ACN baseline model covers confidentiality loss affecting digital data under entity ownership or control. Practical guide to qualification…

February 18, 2026

NIS 2 Point of Contact and CSIRT Contact Role: Accountability and Operating Duties

NIS 2 implementation guidance distinguishes the legal Point of Contact from the operational CSIRT contact role. Practical guide to role formalization…