The 24-hour clock, already running.

Incident notifications in the format each authority wants, on the deadlines NIS 2 sets, and a named Article 26 representative registered with ENISA. For digital providers serving the EU from outside it.

What Cyber Resilience is

Three jobs that usually sit in three places.

01

The clock

Early warning in 24 hours, notification in 72, final report in a month. The deadlines are started by the incident, not by whoever remembers, and the drafts are waiting when you get there.

02

The authorities

Which CSIRT and which competent authority, in which member states, for an incident with this footprint — decided from your registration rather than searched for at three in the morning.

03

The representative

A named Article 26 representative, registered with ENISA under Article 27. The part of this you cannot do yourself from outside the EU.

An incident

The worst 72 hours of the year, with the paperwork done.

  1. The clock starts when you log it

    Detection time, not reporting time, is what the deadlines run from — so the first thing recorded is when you knew, and every deadline is derived from that.

  2. The early warning goes out

    Within 24 hours: whether it is suspected to be unlawful or malicious, and whether it could have cross-border impact. Short on purpose, because at that point nobody knows much.

  3. The notification follows

    Within 72 hours: severity, impact, indicators of compromise, and an update on the early warning. Drafted against what you have logged rather than from a blank page.

  4. The final report closes it

    Within a month: the description, the type of threat, the mitigations applied, and the cross-border effect. Filed to every authority that was told about the incident in the first place.

What a closed incident carries
// Incident · NIS 2 Art. 23

Detected    14 Feb 02:11 CET
Early       14 Feb 02:41 (+30 min)
Notified    15 Feb 18:20 (+40 h)
Final       09 Mar (+23 d)

Authorities 3 engaged
            HR CSIRT · lead
            DE BSI · cross-border
            IE NCSC · cross-border

Users       ~14,200 affected
Status      Closed · no enforcement
Three authorities, one account of what happened. The alternative is three accounts that have to agree under scrutiny.
What NIS 2 also asks for

The duties that come before the incident.

Article 21

Risk-management measures

The ten measures Article 21(2) names — policies, incident handling, business continuity, supply-chain security, disclosure, cryptography and the rest — held as a framework you can show rather than assert.

Article 20

Management-body accountability

The governing body approves the measures and can be held personally liable for failing to. That approval, and the training behind it, is recorded.

Article 21(2)(d)

Supply-chain security

The register of the suppliers and service providers whose security is now part of yours, with the assessment behind each relationship.

Articles 26 and 27

Registration

Your entity registered in the member state where the representative sits, and the ENISA registry entry that digital providers specifically must keep current.

Article 26

The entity the directive can reach.

Included in Cyber Resilience

A named representative, registered.

DNS providers, cloud and data-centre services, CDNs, managed service providers and online marketplaces that offer services in the Union without being established there must designate a representative in one of the member states where they operate. We become yours, and we register you where Article 27 requires.

Incident filings are never metered. We will not charge you by the notification during the week you can least afford it.

Learn more about the Article 26 mandate →
MandateNIS 2 Article 26 · signed
RepresentativeWorld Presence j.d.o.o.
RegisteredENISA, under Article 27
CSIRT contactNamed, with an out-of-hours route
Covers1 entity included · more on the slider
FilingsUnlimited · never metered
Pricing

One monthly fee. Digital or essential.

The incident clocks, the risk-management framework and the Article 26 mandate, for one entity, with every filing included. Open Usage to add entities.

Cyber Resilience

NIS 2 representative under Article 26. Unlimited incident filings. We never charge you during your worst 72 hours.

$327/mo

Service fee

Start now

In the fee

  • Named Art. 26(3) representative on record
  • Registration with the competent authority
  • 24 / 72 hour and 30-day incident reporting — unlimited
  • Art. 21 risk-management framework
  • Management-body training (Art. 20)
  • Supply-chain security register
  • Incident post-mortem and final report drafting
  • CSIRT and authority liaison
  • Annual framework review

This is on top of your platform plan, which starts at $0. See every price →

Common questions

What teams ask us first.

Is this the same thing as the NIS 2 representative?

The representative is part of it. Cyber Resilience is the product: the incident clocks, the notifications, the risk-management framework and the Article 26 mandate together. If all you need is the mandate itself, that is the piece described on the NIS 2 Representative page — but it is bought as Cyber Resilience either way.

Are we in scope?

NIS 2 catches more than people expect: cloud computing, data centres, CDNs, DNS, managed services, online marketplaces, search engines and social platforms are all named, and the thresholds are lower than the old directive's. If you sell any of those into the EU without an entity there, assume yes and check.

Do you file on our behalf, or do we?

We file, from what you give us, against the deadline. You keep the facts and the decisions; what you do not keep is the question of which authority, in which format, in which language, by when.

What does an entity mean for pricing?

One legal entity in scope. One is included; each additional entity is priced on top. Incident filings are never counted, however many there are.

What happens if we stop?

The mandate ends on 30 days' notice, and the authority and the ENISA registry are updated. Until it does you stay covered: a designated representative that quietly lapses leaves you in breach.

The clock runs either way.

Thirty minutes to work out which authorities you answer to and what your 24 hours would look like. A named representative on record the moment you sign.