- Meaning
- Incident plan for the emergency
- Contents
- Roles, procedures, escalation, communication
- Benefit
- The ability to act under stress
- Related
- Incident response, BCP
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is an incident response plan?
The Incident response plan (IRP) is the written document that sets out in advance who does what in an emergency: who decides, who communicates, when things escalate and when the authority is notified. It is the central tool that translates the abstract capability of Incident response into concrete instructions the team can pick up and follow. That keeps you able to act under the stress of an incident, because nobody has to work out first who is responsible or which deadline applies.
What belongs in it
- Roles and the people responsible, including named deputies and contact details
- Detection, classification and escalation paths according to severity
- Communication plan (internal, the competent authority, and where relevant customers and the public)
- A concrete reference to the NIS2reporting deadlines (24 hours / 72 hours / one month)
- Checklists for containment, evidence preservation and Recovery
Practise, do not just write
A plan in a drawer helps little. Only regular exercises such as tabletop scenarios expose gaps, make the team sure-footed and check whether contact details and assumptions still hold. After every real incident and every exercise the IRP is revised – it is a living document, not a one-off compliance product. It is closely interlocked with the Business Continuity Plan, which governs keeping the business running.
The IRP and NIS2
In an emergency every minute counts – not least because of the reporting deadlines. A rehearsed IRP makes sure that incident response runs quickly and in an orderly way and that the deadlines towards the national CSIRT and the competent authority are met. Article 34 sets minimum ceilings for fines of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts. In practice: when patient records become unreachable overnight at a hospital operator, the team reaches straight for the IRP checklist: the call chain stored there activates the management and the head of IT, the pre-drafted notification template speeds up the 24-hour early warning, and the escalation matrix settles at once who decides on shutting systems down.
Further reading: ISO 22301 – Business Continuity Management Systems (ISO)
Frequently asked questions
What is an incident response plan?
An incident response plan (IRP) is the written incident document that sets out in advance who does what in an emergency: roles and the people responsible, escalation and communication paths, and concrete procedures and decisions. It also ties in the NIS2 reporting deadlines of 24 hours, 72 hours and one month, and it translates the abstract capability of incident response into instructions the team can pick up and follow.
Why do you need an incident response plan?
An incident response plan (IRP) keeps action orderly and fast under the stress of a security incident, because nobody has to work out first who is responsible or which deadline applies. That is how the NIS2 reporting deadlines towards the national CSIRT or the competent authority are met. Article 34 sets minimum ceilings for fines: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
How do you keep an incident response plan effective?
An incident response plan (IRP) only stays effective through regular exercises such as tabletop scenarios, which expose gaps, test contact details and assumptions and drill the team. On top of that comes continuous updating after every real incident, whenever staff change and whenever systems or responsibilities change. The IRP is therefore a living document, not a one-off compliance product in a drawer.