The classic trap
Essential and important entities tend to believe that operational cooperation within the CSIRTs network is the exclusive business of ILR and CIRCL. That is a mistake: when a major incident hits, ILR mobilises the CSIRTs network and, potentially, Europol via the EU LE ERP protocol. If your internal teams cannot dialogue with these counterparts (STIX/TAXII formats, ENISA taxonomy, TLP levels), cooperation stalls and the qualification of your incident degrades in the regulator's eyes.
What this recital changes for your organisation
The EU legislator signals that operational cooperation will expand beyond national CSIRTs, towards Europol and other Union bodies. In practice, your article 23 NIS 2 incident notifications may be relayed to several counterparts, and your technical evidence (logs, IoCs, memory artefacts) must be exploitable by all of them. Concretely:
- Your IoCs must be exportable as STIX 2.1 or MISP to be ingestible by the CSIRTs network.
- Your incident taxonomy must align with ENISA's Reference Incident Classification Taxonomy.
- Your reports must carry a TLP marking consistent with CIRCL's.
- Your digital chain of custody must be opposable in the event of transfer to Europol (SHA-256 hash, eIDAS qualified timestamp).
How Luxgap automates this risk
Our Luxgap CSIRT Bridge turns your SOC into a native counterpart of the European CSIRTs network. The tool plugs your SIEM (Microsoft Sentinel, Splunk, Wazuh, CrowdStrike Falcon) into a translation layer that converts your alerts in real time into STIX 2.1 / MISP bundles ready to be pushed to CIRCL, and simultaneously prepares a Europol-ready dossier if the incident escalates into organised cybercrime.
- Detects article 23 NIS 2 qualifying incidents the moment they appear in the SIEM and triggers the ILR notification workflow within 24h.
- Automatically converts your internal IoCs into STIX 2.1 bundles with TLP markings, ready to be shared via MISP-CIRCL.
- Aligns each incident with the ENISA RICT taxonomy and proposes the qualification (ransomware, supply-chain, volumetric DDoS, targeted intrusion).
- Generates a pre-filled Europol referral file (EC3 / J-CAT) when cross-border criminality indicators are detected.
- Cryptographically seals every artefact (SHA-256 + eIDAS qualified timestamp) to guarantee chain of custody opposability in case of international transfer.
- Produces a timestamped PDF report reconstructing for ILR the full timeline and the effective cooperation with the CSIRTs network.
Available as an add-on to a Luxgap CISO mandate or as a standalone SaaS brick depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real SIEM feeds, with a free 48h blank audit to measure your current ability to cooperate with the CSIRTs network.