Glossary · Term

Incident response plan (IRP) explained

An incident response plan (IRP) is an incident plan with clear roles, procedures and decisions for the emergency.

At a glance
Meaning
Incident plan for the emergency
Contents
Roles, procedures, escalation, communication
Benefit
The ability to act under stress
Related
Incident response, BCP
Updated
June 2026
Editorial team
Compliance Compass

What is an incident response plan?

The Incident response plan (IRP) is the written document that sets out in advance who does what in an emergency: who decides, who communicates, when things escalate and when the authority is notified. It is the central tool that translates the abstract capability of Incident response into concrete instructions the team can pick up and follow. That keeps you able to act under the stress of an incident, because nobody has to work out first who is responsible or which deadline applies.

What belongs in it

Practise, do not just write

A plan in a drawer helps little. Only regular exercises such as tabletop scenarios expose gaps, make the team sure-footed and check whether contact details and assumptions still hold. After every real incident and every exercise the IRP is revised – it is a living document, not a one-off compliance product. It is closely interlocked with the Business Continuity Plan, which governs keeping the business running.

The IRP and NIS2

In an emergency every minute counts – not least because of the reporting deadlines. A rehearsed IRP makes sure that incident response runs quickly and in an orderly way and that the deadlines towards the national CSIRT and the competent authority are met. Article 34 sets minimum ceilings for fines of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts. In practice: when patient records become unreachable overnight at a hospital operator, the team reaches straight for the IRP checklist: the call chain stored there activates the management and the head of IT, the pre-drafted notification template speeds up the 24-hour early warning, and the escalation matrix settles at once who decides on shutting systems down.

Further reading: ISO 22301 – Business Continuity Management Systems (ISO)

Frequently asked questions

What is an incident response plan?

An incident response plan (IRP) is the written incident document that sets out in advance who does what in an emergency: roles and the people responsible, escalation and communication paths, and concrete procedures and decisions. It also ties in the NIS2 reporting deadlines of 24 hours, 72 hours and one month, and it translates the abstract capability of incident response into instructions the team can pick up and follow.

Why do you need an incident response plan?

An incident response plan (IRP) keeps action orderly and fast under the stress of a security incident, because nobody has to work out first who is responsible or which deadline applies. That is how the NIS2 reporting deadlines towards the national CSIRT or the competent authority are met. Article 34 sets minimum ceilings for fines: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

How do you keep an incident response plan effective?

An incident response plan (IRP) only stays effective through regular exercises such as tabletop scenarios, which expose gaps, test contact details and assumptions and drill the team. On top of that comes continuous updating after every real incident, whenever staff change and whenever systems or responsibilities change. The IRP is therefore a living document, not a one-off compliance product in a drawer.

Preparation

Sure-footed when it matters

Compliance Compass helps you set out roles, procedures and reporting paths – and keep them ready for the emergency.