Skip to Content

Overview

The European landscape of attack detection

What applies where, and why automation becomes mandatory.

Requirements for automated attack detection in Europe are outcome-oriented, not product-specific. Almost all frameworks demand the same capabilities, only at different levels and with very different deadlines.

The levels at a glance

  • EU baseline: The NIS2 Directive (EU) 2022/2555 anchors detection as part of incident handling. Implementing Regulation (EU) 2024/2690 makes monitoring and logging concretely mandatory for digital services.
  • Financial sector: DORA (EU) 2022/2554 has an explicit detection obligation (Art. 10) with automatic alerting and hard deadlines.
  • Product and resilience level: The Cyber Resilience Act and the CER Directive add product and operator duties.
  • National additional regimes: Germany (SzA), France (LPM), Italy (Perimetro), Spain (ENS) and Belgium (CyFun) go beyond the EU baseline.
  • Standards: ISO/IEC 27001:2022 as the certifiable anchor, ISO/IEC 27039 specifically for attack detection systems, ISO/IEC 27035-3 for operations, IEC 62443-3-3 for OT, NIST CSF 2.0 as the common language.

National regimes and reporting deadlines

Deadlines are the strongest driver for automation. Only Germany has a named obligation for attack detection systems.

FrameworkSpecifics for attack detectionDeadlines
NIS2 (EU)Detection as part of incident handling, baseline24h / 72h / 1M
DORA (EU)Explicit detection obligation for the financial sector4h / 24h / 72h
DeutschlandNamed SzA obligation (Sec. 31 BSIG), separate detailed document24h / 72h
FrankreichQualified probes and PDIS SOC duty (LPM/SAIV)ANSSI
ItalienPerimetro with very short reporting deadlines1h / 6h
SpanienENS with concrete monitoring controls (op.mon)NIS2
BelgienCyberFundamentals (certifiable) with DETECT functionNIS2

Which ISO standard fits?

  • ISO/IEC 27001:2022 – the only certifiable framework, a recognized proof for NIS2/critical infrastructure. Core controls: A.8.16 monitoring, A.8.15 logging, A.5.7 threat intelligence, A.5.24–A.5.28 incident management.
  • ISO/IEC 27039 – the only standard specifically for intrusion detection and prevention systems (IDPS): selection, deployment, operation, including automated response.
  • ISO/IEC 27035-3 – operational detection and response (SOC/CSIRT).
  • IEC 62443-3-3 – continuous monitoring for OT-heavy environments.

See conformance in detail

The core catalogue with coverage and maturity, and the full references per standard.