# NIS2 in healthcare: what IT teams must instrument

> NIS2 operational evidence pack for a health IT team: Art. 21 and 23 of Directive (EU) 2022/2555, 24/72/one-month clocks, ANSSI and CERT-FR, and the dual-channel GDPR.

Author: Ala Ben Aicha

Canonical page: https://alabenaicha.me/insights/nis2-healthcare-instrumentation

Updated: 2026-09-19

## Direct answer

NIS2 is not a single certificate. For an essential or important entity, article 23 imposes 24 hours, 72 hours then one month. In France, ANSSI is the point of contact; the Commission still noted in 2025 an incomplete transposition.

## A directive, not the EHDS / MDR / GDPR stack

The page [EU healthcare compliance](https://alabenaicha.me/insights/eu-healthcare-compliance-landscape) cartography **four diets**. **This isolates NIS2** for the team that must instrument detection, escalation and proof. Pinch text: [directive (EU) 2022/2555](https://eur-lex.europa.eu/eli/dir/2022/2555/oj) (NIS 2). Transposition deadline: October 17, 2024; national measures applicable from October 18, 2024.

The sector of **health** appears in Annex I. This does not automatically make any publisher, host or firm **essential entity**. Type of entity, size (thresholds in the annex to Recommendation 2003/361/EC, included in art. 3), specific inclusions and **national transposition law** count. A CISO does not “declare” the status in a README: it is an organizational decision, with legal advice.

## Incident clocks: NIS2 Art. 23 is not GDPR Art. 33

The[section 23](https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32022L2555) ([ELI](https://eur-lex.europa.eu/eli/dir/2022/2555/oj)) imposes, for a **significant incident**, notification to the CSIRT team or the competent authority. The **letters** below are those of art. 23(4); 24 hour / 72 hour / one month clocks remain the default delays of (a), (b) and (d):

| Clock                                           | Deadline (directive)                                                                                    | Recipient (directive)     | Minimal content                                                                                                                                            | What it is not                               |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------- | ------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------- |
| Early warning                                   | **24 hours** after knowledge — Art. 23(4)**(a)**                                                        | CSIRT / authority         | Significant incident; suspected unlawful or malicious act? ; cross-border impact?                                                                          | An internal Jira ticket, a Slack post-mortem |
| Incident notification                           | **72 hours** after knowledge — Art. 23(4)**(b)**                                                        | ditto                     | Update of (a) + initial assessment (severity, impact, IoC if available)                                                                                    | The notification **GDPR**                    |
| Interim report                                  | **On request** of the CSIRT / of the authority — Art. 23(4)**(c)**                                      | ditto                     | Relevant situation updates                                                                                                                                 | A final report “in advance”                  |
| Final report                                    | **One month later (b)** — Art. 23(4)**(d)**                                                             | ditto                     | Detailed description (severity, impact); type of threat or probable root cause; mitigation measures applied and ongoing; cross-border impact if applicable | An ISO 27001 certificate; art. 23(4)(c)      |
| If the incident is **still in progress** to (d) | Progress report **at that moment**, then final report **one month after treatment** — Art. 23(4)**(e)** | ditto                     | (e) does not merge with (c): (c) is a request for authority; (e) is the “always open to (d)” case                                                          | A silence “we’ll see on Monday”              |
| **GDPR Art. 33**                                | **72 hours** (lane **distinct**)                                                                        | Data Protection Authority | Personal data breach at risk                                                                                                                               | An NIS2 substitute                           |

(c) is not the one-month report. (d) is the final report, **one month after notification (b)**, not a month after acquaintance. (e) is not “on request if it lasts”: if the incident is still open at the time of (d), you file a progress report *instead of the final (d)* at this deadline, then a final one in the month following the treatment.

The two 72 hours can coincide on the calendar and **differ on the recipient and the content**. In France, the NIS2 route targets the CSIRT / designated authority; the GDPR route targets the CNIL. A single “we had an incident” email doesn’t satisfy either of us.

Trusted service providers: **derogation from point (b)** of art. 23(4) — notification **24 hours** (not 72 hours) for the significant incident which impacts the trust service. Do not copy this exemption onto a hospital DPI.

## France: ANSSI, CERT-FR, and what the Commission actually wrote

The [Commission page “NIS2 implementation in France”](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive-france) (updated July 7, 2025) indicates:

* **May 7, 2025** : reasoned opinion for **failure to notify complete transposition**.
* Single point of contact: **ANSSI** (`nis@ssi.gouv.fr`).
* National CSIRT: **CERT-FR** (contact 24/7).

I am not inventing the name of a “definitive” French law here. As long as the Commission publishes a reasoned opinion for incomplete transposition, a slide “we are transposed, therefore we are compliant” is a risk, not proof. Read the national text *in force on D-Day* with your counsel, and keep the Commission URL in the evidence file along with its date of consultation.

## Art. 21: ten families of measurements, one audit trail per family

Article 21(2) lists measures **proportionate** (not a miracle product):

| Letter | Family Art. 21(2)                                    | Engineering proof (example)                                   |
| ------ | ---------------------------------------------------- | ------------------------------------------------------------- |
| (a)    | Risk analysis and IS security policies               | Versioned risk register, named owner                          |
| (b)    | Incident management                                  | Runbook 24/72/1 month + dated exercise                        |
| (c)    | Continuity, backup, recovery, crisis                 | Restoration exercise with measured RTO/RPO — not a PDF policy |
| (d)    | Supply Chain Security                                | Supplier inventory + clauses + tipping test                   |
| (e)    | Acquisition/development/maintenance, vulnerabilities | SDLC, CVE management, documented patch window                 |
| (f)    | Effectiveness assessment                             | Audit / intrusion test **planned**, not a marketing badge     |
| (g)    | Cyber hygiene and training                           | Proof of training of the management body (Art. 20)            |
| (h)    | Cryptography                                         | TLS / keys / HSM inventory, not “we have HTTPS”               |
| (i)    | HR, access control, assets                           | Dated access review, minimal CMDB                             |
| (j)    | MFA, secure communications                           | MFA on EHR Admin **and** on the incident climbing path        |

Article 20 charges the**management body**. A single CISO who “signs NIS2” in Confluence is not Art. 20.

## Integration exercise (without real data)

In a test environment, cut **a** downstream system (HL7 queue, FHIR API, or Mirth destination). Time: detection, classification “significant?” », 24-hour alert (draft to the internal box, not to CERT-FR), queue growth, recovery, reconciliation. The hole this exercise reveals — absent owner, no clock, no IoC — is the backlog item. Do not report a fictitious incident to the authority.

The English version, without ANSSI as if it were valid for all Member States, is [NIS2 for healthcare IT teams](https://alabenaicha.me/insights/nis2-healthcare-it-teams).

## What this page is not

It is not an essential entity qualification, not an ANSSI opinion, not a substitute for legal advice, not an ISO audit, not clinical advice. I do not notify for you. The [health data architecture under GDPR](https://alabenaicha.me/insights/gdpr-compliant-healthcare-data-architecture) remains a construction site **separate**.

If you need to instrument logs, files and toggles around care interfaces, it's [interoperability in digital health](https://alabenaicha.me/services/digital-health-interoperability). For a bounded spike, use the [contact with project intention](https://alabenaicha.me/contact?intent=project).
