Countermove

Insights

NIS2 and incident response testing: what does the directive require?

NIS2 requirements for testing incident response, in brief: what the directive says about incident handling, business continuity, crisis management and assessing whether your measures work - and how a tabletop exercise can document the work.

Published

NIS2 is not only about firewalls and patching. The directive also expects you to be able to handle an incident when it happens, to keep the business running, and to have a set way of assessing whether your measures actually work. This page goes through what the directive says about exactly that, and where a tabletop exercise can fit in.

This is a practical introduction, not legal advice. What applies to you specifically is something to settle with your own adviser or your authority. The references point to the official text of the directive on EUR-Lex.

Who is covered?

NIS2, Directive (EU) 2022/2555, sets requirements for what it calls essential and important entities. In Denmark it has been implemented by the Danish NIS 2 Act, Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (lov nr. 434 af 6. maj 2025), which came into force on 1 July 2025. Whether your organisation is covered is for you to establish from the directive and the act; the rest of this page assumes it is.

What the directive requires

Under Article 21(1), entities must take "appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems" and "to prevent or minimise the impact of incidents on recipients of their services and on other services". Article 21(2) says the measures "shall be based on an all-hazards approach" and "shall include at least" a list of items. Four of them are directly about readiness:

  • (b) "incident handling";
  • (c) "business continuity, such as backup management and disaster recovery, and crisis management";
  • (f) "policies and procedures to assess the effectiveness of cybersecurity risk-management measures";
  • (g) "basic cyber hygiene practices and cybersecurity training".

Point (f) is the one most often overlooked. Having a plan is not enough; you also need a set way of assessing whether it and your other measures work. Point (f) speaks of policies and procedures for that assessment, not of any particular kind of test, and the words "tabletop exercise" do not appear in the directive.

Management is not off the hook either. Under Article 20(1), management bodies must "approve the cybersecurity risk-management measures", "oversee its implementation" and "can be held liable for infringements". Read more about cyber exercises for management.

When it goes wrong: the reporting deadlines

Article 23(4) sets out a sequence for a significant incident:

  1. An early warning "without undue delay and in any event within 24 hours" of becoming aware of it.
  2. An incident notification without undue delay and in any event within 72 hours of becoming aware of it.
  3. An intermediate report, on request.
  4. A final report "not later than one month after" the incident notification.

24 hours goes quickly when the incident starts on a Friday night. Meeting the deadline depends on someone spotting the incident, judging whether it is significant, and knowing who writes and sends the notification. Those are roles and decisions, not technology, and they can be practised.

How do you check that the measures work?

In practice it comes down to a regular rhythm of testing and following up. Typical elements are:

  • Backup restore tests: can you actually restore a critical system, and how long does it take?
  • Technical tests such as penetration tests and vulnerability scans, which show whether your defences hold.
  • Reviews of plans and contact lists: are the names, phone numbers and deputies up to date?
  • Exercises in which the people responsible work through an incident and test roles, escalation and decisions.
  • Follow-up: findings become actions with an owner and a deadline, and the next test shows whether they worked.

None of these covers everything on its own. A restore test shows that the backup works technically, but not whether anyone makes the decision to restore in time. An exercise shows the opposite. What ties them together is that the results are written down and followed up.

Where a tabletop exercise fits in

A tabletop exercise is one way to practise incident handling and crisis management. The people who would actually be dealing with the incident work through a realistic scenario round by round, usually in 2–3 hours and without touching a single system. In an incident response exercise, the scenario runs from the first alert through triage, escalation, containment, evidence preservation and regulatory notification to recovery, so the team has to handle the notification under pressure. A disaster recovery exercise tests your recovery plan through declaration, stabilisation, recovery, validation and the return to normal operations. For the participants, the exercise is also training in handling a real incident.

In a NIS2 context, what matters most is the documentation. With Countermove, an exercise ends in a written report, reviewed before it reaches you and usually delivered within five working days. It contains:

  • key takeaways and prioritised actions, each rated high, medium or low
  • a readiness scorecard scored by a transparent, weighted method
  • an assessment of your own plan, both as a document and of how closely the team followed it
  • a round-by-round record: every situation, every decision, and how it was judged.

The report is dated and concrete, and it can form part of the material you use to assess whether your measures work. Because the method and the scorecard stay the same each time, you can show progress from one exercise to the next instead of starting from scratch.

What an exercise does not do

NIS2 does not require a tabletop exercise, and one exercise does not make you compliant. Nor does it prove that a restore works technically. What it shows is whether you know what to do, who does it, and whether the plan holds up when decisions have to be made quickly. Whether it is sufficient, together with your other testing, is for you and your authority to judge, not for this page.

Try a round

On the front page you can try a round, a heavily simplified taste of how an exercise runs. Read more about Countermove's incident response and disaster recovery tabletop exercises.

Want to see how your team would handle it?

We'll gladly show you an exercise and work out whether it fits.

Book a demo