Glossary · Term

CSIRT explained

A CSIRT (Computer Security Incident Response Team) is the body that handles and coordinates security incidents under NIS2.

At a glance
Meaning
Computer Security Incident Response Team
Task
Handling and coordinating security incidents
Level
Internal or national (at least one per Member State)
Relation to NIS2
Point of contact for notifications
Updated
June 2026
Editorial team
Compliance Compass

What is a CSIRT?

A CSIRT (Computer Security Incident Response Team) is a specialised team that reacts to security incidents – it analyses them, contains them and coordinates the countermeasures. The term therefore stands for the operational, technical side of incident handling. Larger organisations have their own CSIRTs; at national level a CSIRT is run by the National cybersecurity authorities of each Member State. The CSIRT role is narrower than that of the competent authority: the latter exercises supervision and enforcement, while the CSIRT mainly gives operational support.

What a CSIRT does

National CSIRTs under NIS2

NIS2 strengthens the role of the national CSIRTs: they receive notifications, support affected organisations and promote the exchange of information about threats. Through the CSIRTs network coordinated by ENISA the national teams also work together across borders. Findings from the staggered reporting chain (a 24-hour early warning, a 72-hour incident notification, a final report within one month) thus feed into a Europe-wide situational picture.

Do I need a CSIRT of my own?

Smaller organisations do not need a team of their own, but they do need clearly defined responsibilities and an Incident response plan. An external service provider can take on that role too. What matters is that in an emergency somebody knows who assesses the incident, who contains it and who files the notification with the national CSIRT.

An incident step by step

Example: at a mid-sized machine builder the monitoring triggers overnight because a server is communicating with a suspicious IP address. The in-house IT team has no forensic experience and calls in the external CSIRT it has under contract. That team isolates the system, secures evidence, identifies the exploited vulnerability and supplies the indicators the company uses to draft its 24-hour early warning to the national CSIRT.

Frequently asked questions

What does a CSIRT do?

A CSIRT (Computer Security Incident Response Team) is a specialised team that handles and coordinates security incidents – from receiving and analysing them through containment to recovery and prevention. It also shares warnings and indicators of compromise (IoCs) and stands for the operational, technical side of incident handling. Larger organisations run their own CSIRTs; at national level every Member State designates at least one CSIRT.

What is the role of the CSIRT under NIS2?

NIS2 strengthens the role of the national CSIRTs: they receive incident notifications, support affected organisations and promote the exchange of information about threats. Through the CSIRTs network coordinated by ENISA the national teams work together across borders. Findings from the staggered reporting chain – a 24-hour early warning, a 72-hour incident notification and a final report within one month – thus feed into a Europe-wide situational picture.

Does every organisation need its own CSIRT?

No, smaller organisations do not need a CSIRT of their own, but they do need clearly defined responsibilities and an incident response plan. An external service provider can take on that role too. What matters is that it is settled in advance who assesses the incident, who contains it and who files the notification with the national CSIRT – so that the NIS2 deadline of 24 hours for the early warning can be met reliably.

Further reading: ENISA – European Union Agency for Cybersecurity

Incident response

Coordinated action in an incident

Compliance Compass structures the roles and procedures of incident handling – with or without a CSIRT of your own.