NIS2 guideNIS2 evidence

NIS2 incident evidence should tell the story without relying on memory.

After an incident, the team needs to explain what happened, what was affected, who acted, what evidence existed, what decisions were made, and what changed. That record is much easier to build when evidence is captured during the response, not weeks later.

IncidentAIUpdated August 2026
Key points

What to remember before you act.

  • Evidence should support decisions, not overwhelm the record.
  • Capture detection time, impact, actions, and owner decisions while the incident is active.
  • Keep supplier and customer communications connected to the incident record.
  • Preserve logs and alerts according to policy and legal requirements.
  • IncidentAI can help organize evidence links, summaries, and RCA drafts.

Evidence to capture during the incident

  • Original alert, user report, vendor notice, or customer message.
  • Time detected, time reported, and detection source.
  • Affected assets, users, services, suppliers, or customers.
  • Indicators observed, including domains, IPs, hashes, accounts, devices, or log patterns where relevant.
  • Screenshots or configuration exports where appropriate and safe.
  • Actions taken, including containment, access changes, rollback, blocking, or recovery.
  • Decision notes showing who approved important actions and why.

Evidence to capture after containment

  • Validated service recovery or restoration evidence.
  • Final impact assessment and affected population where known.
  • Root cause and contributing factors.
  • Supplier RCA or customer-facing statements where applicable.
  • Reporting and notification decisions.
  • Corrective actions with owners and due dates.
  • Post-incident review notes and management follow-up.

What good incident evidence looks like

QualityPractical meaning
TraceableA reviewer can see where the information came from.
Time-boundImportant events have dates and times.
OwnedEach action or decision has an accountable person or role.
RelevantThe evidence supports impact, cause, action, or decision.
ReviewableA manager, auditor, customer, or adviser can understand the record without reading every chat message.
ProtectedSensitive evidence is stored with appropriate access control and retention.

Avoid evidence chaos

Evidence chaos happens when logs are in one tool, screenshots are in chat, decisions are in email, supplier updates are in a shared drive, and the RCA is written from memory. That makes reporting and review harder than the incident itself.

A better approach is to keep the incident ticket as the index. It does not need to store every artifact directly, but it should point to where each artifact lives and why it matters.

Where IncidentAI helps

IncidentAI can help keep incident evidence organized by linking context to the ticket, summarizing thread updates, maintaining a timeline, highlighting missing information, and preparing RCA notes for review.

Evidence still needs human validation. AI can organize and summarize, but people decide what is accurate, sensitive, reportable, and appropriate to retain.

Quick FAQ

What evidence should be kept for a NIS2 incident?

Keep detection details, timelines, affected assets, impact assessment, logs, alerts, actions, decisions, communications, RCA, corrective actions, owners, and review notes.

Should all evidence be attached to the ticket?

Not always. The ticket should at least index the evidence and link to controlled storage where sensitive artifacts are retained.

Why is a decision log important?

A decision log explains what the team knew, who approved actions, and why choices were made when facts were still developing.

Can AI validate incident evidence?

AI can help organize and summarize evidence, but accountable humans should validate accuracy, relevance, sensitivity, and reporting implications.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

IncidentAI

Keep incident evidence connected to the work.

IncidentAI helps teams maintain timelines, evidence links, summaries, decisions, and RCA drafts in a cleaner incident record.