Integrating NIS2 Requirements into a Collaboration Framework for Security Operations Centers
Abstract
We present an initial work of how Security Operations Centers (SOCs) can align rapid incident response with the compliance demands of the NIS2 Directive. Building on the existing SAPPAN reference architecture for cyber threat intellegence (CTI) exchange and automation, this work identifies gaps in auditability and traceability and takes first steps toward integrating regulatory requirements into SOC collaboration models.
Full text
Integrating NIS2 Requirements into a Collaboration Framework for Security Operations Centers — Avikarsha Mandal1, Lasse Nitz1,2 , Mehdi Akbari Gurabi1,2, 1 Fraunhofer FIT, Sankt Augustin, Germany 2 RWTH Aachen University, Aachen, Germany Problem: Operational Security vs Regulatory Compliance ▪Security operation centers (SOCs) must maintain fast and effective incident detection and response. ▪To defend against evolving cyberattacks, cross-organizational cyber threat intelligence (CTI) sharing essential but constrained by confidentiality, privacy, and data sovereignty. ▪EU regulations (NIS2, GDPR, Cyber Solidarity Act) increase legal pressure and reporting obligations. ▪SOCs increasingly feel strained by regulatory demands that introduce additional administrative workload and legal risks. Background: EU Directive NIS2 ▪NIS2 (Network and Information Security Directive 2, ((EU) 2022/2555)) provides a unified legal framework to uplift and strengthen cybersecurity level across all EU member states. ▪Replaces the original 2016 NIS directive, it applies to more sectors and companies, not only critical infrastructure but also digital services, manufacturing, research, etc. ▪It obliges organizations to maintain documented security and risk-management measures, ensure timely incident reporting, and provide traceability of actions for regulatory accountability. ▪Mediumand small-sized companies have been impacted the most by integrating compliance requirements with technical security measures. Background on SAPPAN ▪EU H2020 833418 research project to improve cyber incident management lifecycle with privacy-preserving collaboration and automation for SOCs. ▪SAPPAN proposed a reference architecture for the exchange of CTI and automation in threat detection and response. ▪However, the SAPPAN architecture lacked the compliancelevel perspective in terms of auditability and traceability now required under NIS2. Figure 1 - SAPPAN collaboration concept aligned with the National Institute of Standards and Technology (NIST) incident response lifecycle. — Table 1 - NIS2 key requirements & mapping NIS2 Requirements Core Regulatory Expectation How SAPPAN + COL Supports It R1: Cybersecurity risk - management (Art. 21) Establish policies, risk assessments, access controls, continuity, vulnerability management; continuously maintain security posture COL tracks implemented measures, maps requirements to technical controls, records evaluation status R2: Timely incident reporting (Art. 23) Detect, classify, and report incidents following formal notification timelines Enables automated structured reporting workflows and timestamped notification evidence R3: CTI sharing (Art. 29 –30) Support information exchange but limit exposure of sensitive or personal data Uses data sanitization and transformation to filter and anonymize CTI before sharing R4: Accountability & Traceability (Art. 20, 32, 33) Maintain logs and decision records to demonstrate compliance and oversight Generates audit logs, captures decision chains, provides traceable evidence for authorities [1] ECSO, White Paper: NIS2 Implementation – Challenges and Priorities, Jan 2025. [2] CORDIS, SAPPAN Project (ID 833418). [3] Nitz et al., On Collaboration and Automation in Threat Detection, Digital Threats, Feb 2025. [4] Directive (EU) 2022/2555 (NIS2), Official Journal of the EU. [5] Akbari Gurabi et al., Playbook-Assisted Incident Response, Digital Threats, Sep 2024. [6] ECSO, NIS2 Transposition Tracker, 2025. Contact — Dr. Avikarsha Mandal Research Group Leader, Data Protection and Sovereignty [email protected] Fraunhofer FIT Schloss Birlinghoven, 53757 Sankt Augustin www.fraunhofer.de Results ▪SAPPAN provides the technical basis for distributed CTI sharing across the incident lifecycle. Introducing the COL enables integration of NIS2-required compliance tasks directly into SOC workflows. ▪The COL coordinates evidence collection, archiving, and traceable documentation for regulatory accountability (R4). ▪Risk management (R1) influence all technical components, with COL tracking implemented measures and evaluation status, while some organizational obligations remain beyond the technical scope. ▪Incident reporting requirements (R2) can be supported automation, case management and recommendation workflows, including notification timing. ▪CTI sharing (R3) such as handling sensitive information is supported through data sanitization and transformation component, though additional national requirements for data formats and filtering may still apply. Figure 2 - SAPPAN reference architecture with Compliance Orientation Layer (COL). — Discussion ▪R2 and R3 can be supported by the existing SAPPAN technical components, while R4 is enabled through the addition of the COL for compliance oversight and traceability. ▪In R1 is partially supported, with COL tracking implemented measures, for full R1 support - integration with external standards and framework (e.g., ISO27001) is required. Objective ▪Enable compliance to be integrated into existing SOC workflows rather than handled separately. ▪Bridge and overlay technical SOC functions, including detection, response, case management, automation, and CTI sharing. ▪Support meeting regulatory requirement while enabling collaborative security operation and automation. ▪Introduce the Compliance Orientation Layer (COL) on top of the SAPPAN architecture. Methodology ▪Conduct a gap analysis of the SAPPAN architecture from the NIS2 compliance perspective. ▪Map identified gaps to technical components in the SAPPAN architecture. ▪Identify key components relevant for NIS2 compliance: ▪automation engine, case management system, recommendation system, data transformation & sanitization module, user dashboard. ▪Based on the relevant NIS2 articles (20-33), we identity 4 key regulatory requirements that the COL-enhanced SAPPAN architecture can technically support and operationalize. Acknowledgments: This work was funded by the Fraunhofer Cluster of Excellence Cognitive Internet Technologies under the project name CyberGuard++.