Glossary · Term

Single Point of Contact (SPOC) explained

The single point of contact is the national body that handles cross-border exchange between authorities and Member States under NIS2. One per country.

At a glance
Meaning
National coordination body
Task
Exchange between authorities and Member States
Level
One per Member State
In each country
Differs by Member State
Updated
June 2026
Editorial team
Compliance Compass

What is a SPOC?

Under NIS2, every EU Member State designates a Single Point of Contact (SPOC). This central body coordinates cross-border exchange and makes sure that information about incidents reaches the right bodies in other countries and at EU level. The single point of contact is therefore a pure coordination and liaison role – unlike the competent authority, which is responsible for supervision and enforcement, and unlike the CSIRT, which handles incidents operationally.

Why the SPOC exists

Cyberattacks do not stop at borders. The single point of contact makes sure that information flows smoothly between the Member States and EU bodies – a central building block of European cooperation. Without a clearly named contact, authorities would first have to work out whom to approach in the neighbouring country in a crisis; the SPOC shortens that path to one known address.

The SPOC in the NIS2 structure

The single point of contact works together with the competent authority, with the CSIRTs and with ENISA in the wider European network. Which institution holds the role differs from Member State to Member State – some combine it with the competent authority and the national CSIRT in one body, others keep the functions apart. The National cybersecurity authorities page gives examples. In every Member State the single point of contact has been part of the national cybersecurity architecture since NIS2 became applicable on 18 October 2024.

Relevance for organisations

Organisations usually have no direct dealings with the single point of contact – their notifications go through the national channels described under Registration portals. The SPOC makes sure that this information reaches the places where it is needed.

An incident across the EU

Imagine a cloud provider established in one Member State suffering an attack that also affects customers in two other countries. The company reports the incident once, through the national channel of the country where it is established. Its single point of contact then informs its counterparts in the affected countries through the authorities network, so that supervisors there can react – without the company having to report separately in every country.

Further reading: European Commission – NIS2 Directive

Frequently asked questions

What is a single point of contact?

The single point of contact (SPOC) is the central national coordination body that every EU Member State designates under NIS2. It secures the cross-border exchange between the authorities of the Member States and EU bodies such as ENISA. It is a pure coordination and liaison role, unlike the competent authority, which is responsible for supervision and enforcement, and unlike the CSIRT, which handles incidents operationally.

Which body acts as the SPOC in a Member State?

That is decided in national law and differs from country to country. Some Member States place the role with the same institution that acts as competent authority and as national CSIRT, others give it to a separate ministry or agency. Whatever the arrangement, the single point of contact works with the CSIRTs and with ENISA and has been part of the national cybersecurity architecture since NIS2 became applicable on 18 October 2024.

Do organisations deal with the SPOC directly?

Usually not: notifications from entities in scope go through the national registration and reporting channel, not through the single point of contact. The SPOC works in the background and makes sure that relevant information about an incident reaches the right bodies in other Member States. That is why an organisation does not have to report a cross-border incident separately in every country affected, but only once through its national channel.

EU framework

Connected across borders

Compliance Compass makes sure your notifications take the right route to the authorities.