The levels at a glance
- EU baseline: The NIS2 Directive (EU) 2022/2555 anchors detection as part of incident handling. Implementing Regulation (EU) 2024/2690 makes monitoring and logging concretely mandatory for digital services.
- Financial sector: DORA (EU) 2022/2554 has an explicit detection obligation (Art. 10) with automatic alerting and hard deadlines.
- Product and resilience level: The Cyber Resilience Act and the CER Directive add product and operator duties.
- National additional regimes: Germany (SzA), France (LPM), Italy (Perimetro), Spain (ENS) and Belgium (CyFun) go beyond the EU baseline.
- Standards: ISO/IEC 27001:2022 as the certifiable anchor, ISO/IEC 27039 specifically for attack detection systems, ISO/IEC 27035-3 for operations, IEC 62443-3-3 for OT, NIST CSF 2.0 as the common language.
National regimes and reporting deadlines
Deadlines are the strongest driver for automation. Only Germany has a named obligation for attack detection systems.
| Framework | Specifics for attack detection | Deadlines |
|---|---|---|
| NIS2 (EU) | Detection as part of incident handling, baseline | 24h / 72h / 1M |
| DORA (EU) | Explicit detection obligation for the financial sector | 4h / 24h / 72h |
| Deutschland | Named SzA obligation (Sec. 31 BSIG), separate detailed document | 24h / 72h |
| Frankreich | Qualified probes and PDIS SOC duty (LPM/SAIV) | ANSSI |
| Italien | Perimetro with very short reporting deadlines | 1h / 6h |
| Spanien | ENS with concrete monitoring controls (op.mon) | NIS2 |
| Belgien | CyberFundamentals (certifiable) with DETECT function | NIS2 |
Which ISO standard fits?
- ISO/IEC 27001:2022 – the only certifiable framework, a recognized proof for NIS2/critical infrastructure. Core controls: A.8.16 monitoring, A.8.15 logging, A.5.7 threat intelligence, A.5.24–A.5.28 incident management.
- ISO/IEC 27039 – the only standard specifically for intrusion detection and prevention systems (IDPS): selection, deployment, operation, including automated response.
- ISO/IEC 27035-3 – operational detection and response (SOC/CSIRT).
- IEC 62443-3-3 – continuous monitoring for OT-heavy environments.
See conformance in detail
The core catalogue with coverage and maturity, and the full references per standard.