# Support for NIS2 incident work.

AtlasEye keeps detection, the incident timeline and the reporting evidence in the same console, so your team can meet its NIS2 deadlines with less manual assembly.

> **A tool, not a certification.** AtlasEye helps organise NIS2-related work. It does not certify compliance or guarantee that your organisation meets its legal obligations; that assessment stays with you and your advisers.

## Article 23 reporting deadlines

Each significant incident carries the three reporting milestones, so the team sees what is due and when.

- **24 h — Early warning**: The first milestone on each incident's timeline.
- **72 h — Incident notification**: The second milestone, tracked on the same timeline.
- **30 days — Final report**: The closing milestone, with a narrative the team can draft from the timeline.

## What the product provides

- **Incident lifecycle with a timeline** (Pro and Enterprise): Open, update and close incidents with every action recorded in order.
- **CSIRT export** (Pro and Enterprise): JSON/XML export for the CSIRTs of the 27 EU member states, and sending by e-mail to the CSIRT.
- **Incident narrative drafted by AI** (Pro and Enterprise): Uses the model provider you configure. The draft is a starting point for your team to review.
- **Tamper-evident audit log** (Pro and Enterprise): A hash-chained record of actions with a "Verify chain" check, full-text search and CSV export.
- **Article 21(2) control assessment** (Enterprise): The page states which inputs are measured on your installation and which are properties of the product.
- **SOC 2 / ISO 27001 evidence map** (Enterprise): Maps product evidence to control areas. It is an evidence aid, not an attestation.
- **Account lockout and sign-in alerts**: Lockout after repeated failed sign-ins, brute-force alerts and unlock by an administrator.
- **NIS2 criticality in IPAM**: Record the NIS2 criticality of IP addresses and ranges alongside subnet discovery.

## From signal to report

1. Syslog, security detection and device alerts raise the signal.
2. The team opens an incident; the Article 23 milestones appear on its timeline.
3. Actions and evidence accumulate on the timeline and in the audit log.
4. The export for the relevant CSIRT is generated and reviewed before it is sent.

---
Canonical page: https://atlaseye.eu/nis2
Product facts verified against AtlasEye 1.2.341 on 2026-09-30.
Request free trial: https://atlaseye.eu/trial
