Incidents
Vendor incidents: settling reporting paths and decisions before the incident
If a provider only starts looking for the right contact after hours have passed, the contractual reporting obligation is operationally worthless.
8 minute read · Content as of 21.07.2026
A shared situational picture needs fixed minimum information
Affected service, start, impact, data involvement, containment, next steps and expected updates should be transmitted in a structured form. Contacts and fallback channels must be tested regularly.
Internal obligations run in parallel
The organisation assesses its own reporting, information and continuity obligations regardless of whether the provider has completed its investigation. Contracts should allow interim reports and continuous updates.
- 24/7 contacts and authentication
- initial reporting deadline and update frequency
- evidence preservation and cooperation
- post-incident report and corrective actions
Sources used
- Directive (EU) 2022/2555 – NIS2 · EU · 2022
- Best practice recommendations for supplier requirements · UP KRITIS / BSI · Version 4.0, 2023
- Vendor, due diligence and exit patterns · KaitoSec