Source: OJ L 333, 27.12.2022, p. 80–152

Current language: EN

Article 30 Voluntary notification of relevant information


Summary What does Article 30 of the NIS 2 directive say?

This article sits alongside the mandatory reporting framework established under Article 23, creating a parallel voluntary notification channel.

It opens up the ability for both in-scope and out-of-scope entities to report incidents, cyber threats, and near misses to CSIRTs or competent authorities on a voluntary basis.

Importantly, the article includes a protection for those who choose to report voluntarily, ensuring they do not take on any additional obligations simply by virtue of having reported.

Important points:

  • Essential and important entities, as well as any other entities regardless of whether they fall within the scope of this Directive, can voluntarily notify CSIRTs or competent authorities of incidents, cyber threats, and near misses.
  • Member States may prioritise the processing of mandatory notifications over voluntary ones.
  • Voluntary reporting shall not result in any additional obligations being imposed on the notifying entity that would not have applied had it not submitted the notification.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Member States shall ensure that, in addition to the notification obligation provided for in Article 23, notifications can be submitted to the CSIRTs or, where applicable, the competent authorities, on a voluntary basis, by:

      1. essential and important entities with regard to incidents, cyber threats and near misses;

      2. entities other than those referred to in point (a), regardless of whether they fall within the scope of this Directive, with regard to significant incidents, cyber threats and near misses.

    1. Member States shall process the notifications referred to in paragraph 1 of this Article in accordance with the procedure laid down in Article 23. Member States may prioritise the processing of mandatory notifications over voluntary notifications.

    2. Where necessary, the CSIRTs and, where applicable, the competent authorities shall provide the single points of contact with the information about notifications received pursuant to this Article, while ensuring the confidentiality and appropriate protection of the information provided by the notifying entity. Without prejudice to the prevention, investigation, detection and prosecution of criminal offences, voluntary reporting shall not result in the imposition of any additional obligations upon the notifying entity to which it would not have been subject had it not submitted the notification.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod