Skip to content

Evidence request lists

EU Cyber Solidarity Act (Regulation (EU) 2025/38)

Evidence request list. 18 controls, 17 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

CSA - Cybersecurity Emergency Mechanism (Ch III)

CSA-Art.10_11
Establishment of the Cybersecurity Emergency Mechanism and types of action (Articles 10-11)

Article 10 establishes the Cybersecurity Emergency Mechanism. Article 11 lists the types of action the Mechanism supports: (a) coordinated preparedness testing of essential and important entities under NIS2 in highly critical sectors (energy, finance, health, water, transport, digital infrastructure); (b) preparedness actions including capacity-building and exercises; (c) Union financial support to deploy incident response from the EU Cybersecurity Reserve; (d) mutual assistance between Member States; (e) support to DEP-associated third countries.

Artefacts an auditor will ask for
  • Mechanism-readiness documentation for the entity (where the entity is an essential/important entity under NIS2 within scope of preparedness testing)
  • Mutual-assistance arrangements via the entity's national competent authority
Where this commonly fails
  • Essential entity under NIS2 with no engagement on Article 11(a) coordinated preparedness testing
CSA-Art.12_13
Coordinated preparedness testing and other preparedness actions (Articles 12-13)

Article 12 establishes Union-coordinated preparedness testing of essential and important entities under NIS2 in highly critical sectors, with the Commission and ENISA setting the methodology, the Member States selecting tested entities, and the entity bound to cooperate. The testing covers technical, organisational and incident-response capabilities. Article 13 covers other preparedness actions: capacity-building events, exercises (in coordination with EU-CyCLONe and the CSIRTs network), threat-information dissemination, dissemination of best practices.

Artefacts an auditor will ask for
  • Participation records in Article 12 coordinated preparedness testing
  • Records of EU-CyCLONe / CSIRTs-network exercises the entity participated in
Where this commonly fails
  • Refusal to participate in Article 12 coordinated preparedness testing where designated
CSA-Art.14_15_16_17
EU Cybersecurity Reserve and trusted providers (Articles 14-17)

Article 14 establishes the EU Cybersecurity Reserve: a Union-managed pool of incident-response services provided by certified trusted managed security service providers (MSSPs) available to Member States (Article 15 request mechanism), Union institutions and DEP-associated third countries. Article 16 governs implementation. Article 17 sets the requirements for trusted MSSPs: certification under (EU) 2019/881, security clearances, geographic presence requirements, supply-chain controls, contractual commitments to make services available within agreed response times.

Artefacts an auditor will ask for
  • Trusted-MSSP certification + clearance records where the entity is a provider in the Reserve
  • Procurement-framework participation evidence
  • Article 15 request-handling procedure where the entity is a Member State / Union institution potential beneficiary
Where this commonly fails
  • MSSP supplying Reserve services without the Article 17 certification + clearance evidence
  • Procurement of incident-response services that bypasses the Reserve framework
CSA-Art.18
Actions supporting mutual assistance (Article 18)

Article 18 enables Union funding for mutual-assistance actions between Member States in case of cybersecurity emergencies, including dispatching technical experts, sharing of detection / response tools, and joint operational coordination. The Commission and ENISA coordinate.

Artefacts an auditor will ask for
  • Records of any Article 18 mutual-assistance actions the entity participated in (provider or beneficiary)
CSA-Art.19_20
Support to DEP-associated third countries and coordination with Union crisis-management mechanisms (Articles 19-20)

Article 19 extends Reserve and Emergency Mechanism support to Digital Europe Programme-associated third countries (EFTA + accession-track countries that have signed DEP association agreements). Article 20 coordinates the Mechanism with Union crisis-management mechanisms (Integrated Political Crisis Response, EU Civil Protection Mechanism, EU-CyCLONe).

Artefacts an auditor will ask for
  • Records of any Article 19 third-country support actions
  • Records of any IPCR / EU-CyCLONe / CPM cross-mechanism activations involving the entity

CSA - European Cybersecurity Alert System (Ch II)

CSA-Art.3
Establishment of the European Cybersecurity Alert System (Article 3)

Article 3 establishes the European Cybersecurity Alert System: a pan-EU interconnected network of National Cyber Hubs (Article 4) and Cross-Border Cyber Hubs (Article 5) operating as advanced security operations centres for detection of significant cyber threats and incidents and for sharing of cyber threat intelligence among Member States and with Union institutions, bodies, offices and agencies.

Artefacts an auditor will ask for
  • Documented participation by the entity in the relevant National Cyber Hub / Cross-Border Cyber Hub
  • Information-sharing channels (interfaces / APIs / sensors) to/from the entity into the Alert System
Where this commonly fails
  • Entity operating critical-sector cybersecurity monitoring without engagement with the relevant National Cyber Hub
CSA-Art.4
National Cyber Hubs (Article 4)

Article 4 requires each Member State to designate one National Cyber Hub. The Hub: (a) collects, aggregates and analyses cyber-threat intelligence relevant to its Member State; (b) shares cyber-threat intelligence with the Cross-Border Cyber Hubs of which it is a member and with the CSIRTs network; (c) supports a Member-State-wide situational-awareness picture; (d) makes use of advanced detection tools, including AI-based detection. National Cyber Hubs are designated by the Member State and notified to the Commission and ENISA.

Artefacts an auditor will ask for
  • Records of engagement with the relevant National Cyber Hub (sensor deployment, threat-intelligence sharing, detection-tool integration)
Where this commonly fails
  • Member-State-level threat-intelligence efforts that do not feed into the designated National Cyber Hub
CSA-Art.5
Cross-Border Cyber Hubs (Article 5)

Article 5 enables Member States to form Cross-Border Cyber Hubs: consortia of at least three Member States cooperating to pool data, advanced detection capabilities, threat-intelligence analytics and skills. Hosting Member States are selected through Commission calls and benefit from Union co-funding under the Digital Europe Programme. Cross-Border Cyber Hubs share cyber-threat intelligence with the participating National Cyber Hubs and with the Alert System.

Artefacts an auditor will ask for
  • Records of the entity's participation in a Cross-Border Cyber Hub (host, contributor, beneficiary)
  • Cross-border data-sharing agreements and processing-purpose documentation
Where this commonly fails
  • Cross-border threat-intelligence sharing without an Article 5 governance basis
CSA-Art.6_7
Information sharing within and between Cyber Hubs and Union-level networks (Articles 6-7)

Article 6 sets the rules for cooperation and information sharing within and between Cross-Border Cyber Hubs (use cases, formats, taxonomies, classification). Article 7 sets the rules for cooperation and information sharing between the Cyber Hubs and Union-level networks (CSIRTs network, EU-CyCLONe, ENISA, the Commission, relevant Union agencies including Europol).

Artefacts an auditor will ask for
  • Information-sharing playbook (channels, formats, classification, TLP)
  • TLP (Traffic Light Protocol) handling procedures for inbound and outbound intelligence
Where this commonly fails
  • Information shared between Cyber Hubs without classification / TLP labelling
  • Sharing with Union-level networks not coordinated through the National Cyber Hub
CSA-Art.8
Security of the Alert System (Article 8)

Article 8 imposes security obligations on the National Cyber Hubs and Cross-Border Cyber Hubs as integral parts of the Alert System: technical and organisational measures to ensure confidentiality, integrity and availability of the Hub infrastructure and the data it processes; restricted access to authorised personnel; secure-by-design and secure-by-default architecture; alignment with the Cybersecurity Act certification schemes where applicable; regular audits.

Artefacts an auditor will ask for
  • Security baseline aligned with the EUCC certification scheme (or other applicable Cybersecurity Act schemes)
  • Audit records of the entity's Hub-component infrastructure
  • Personnel-access controls and clearances
Where this commonly fails
  • Hub infrastructure not certified against an applicable EU cybersecurity certification scheme
  • Personnel access without documented clearances
CSA-Art.9
Funding of the European Cybersecurity Alert System (Article 9)

Article 9 sets the funding regime: the Union may contribute to the procurement and operation of the National Cyber Hubs and Cross-Border Cyber Hubs through the Digital Europe Programme (amended by Article 22 of the CSA to incorporate the Cyber Solidarity Specific Objective). Member States contribute matching funding per the relevant work programme.

Artefacts an auditor will ask for
  • Records of any Union co-funding received for Hub activities the entity participates in (DEP grant agreements, reporting obligations under the grant)

CSA - European Cybersecurity Incident Review Mechanism (Ch IV)

CSA-Art.21
European Cybersecurity Incident Review Mechanism (Article 21)

Article 21 establishes the European Cybersecurity Incident Review Mechanism: ENISA, at the request of the Commission, EU-CyCLONe or the NIS Cooperation Group, reviews significant or large-scale cybersecurity incidents with the purpose of identifying lessons learned and recommendations for future incidents. ENISA produces a public lessons-learned report; sensitive details are protected per Article 8 confidentiality safeguards.

Artefacts an auditor will ask for
  • Internal incident-review file ready for ENISA Article 21 review (incident timeline, root-cause analysis, mitigations applied, lessons identified)
  • Cooperation procedure to provide ENISA with redacted / sanitised incident details on request
Where this commonly fails
  • No internal lessons-learned process despite significant cybersecurity incidents
  • Refusal to engage with ENISA Article 21 review without an Article 8 confidentiality basis

CSA - Final Provisions (Ch V)

CSA-Art.22
Amendments to Regulation (EU) 2021/694 (Article 22)

Article 22 amends the Digital Europe Programme Regulation (EU) 2021/694 to add a new Specific Objective 6 covering cyber solidarity (financing the Alert System, the Emergency Mechanism and the Reserve). Annex II of the DEP Regulation is amended to add the corresponding indicators.

Artefacts an auditor will ask for
  • Tracking of DEP work-programme calls relevant to the entity's CSA-pillar participation
CSA-Art.23_24
Exercise of the delegation and committee procedure (Articles 23-24)

Article 23 governs the exercise of the delegation of power to amend technical annexes and procedural details. Article 24 establishes the committee procedure (Cyber Solidarity Committee, composed of Member State representatives, chaired by the Commission).

CSA-Art.25
Evaluation and review (Article 25)

Article 25 requires the Commission to evaluate the Regulation by 5 February 2027 (initial early assessment focused on Hub deployment and Reserve operationalisation), and to carry out a comprehensive evaluation every four years thereafter. The evaluation considers cyber-threat-landscape evolution, Reserve utilisation, Member-State capability gains, and the case for scope or budget adjustments.

Artefacts an auditor will ask for
  • Tracking of the Commission's Article 25 evaluation reports relevant to the entity's CSA participation
CSA-Art.26
Entry into force (Article 26)

Article 26 provides that the Regulation entered into force on the twentieth day following its publication in the Official Journal (5 February 2025) and applies from the day of entry into force, with certain implementing acts adopted progressively.

Artefacts an auditor will ask for
  • Compliance calendar reflecting 5 February 2025 entry into force and any progressive implementing-act milestones

CSA - General Provisions (Ch I)

CSA-Art.1
Subject matter and objectives (Article 1)

Article 1 sets the subject matter and objectives: strengthen solidarity and capacities in the Union to detect, prepare for and respond to cybersecurity threats and incidents, supporting Union and Member State preparedness, response and recovery. Article 1(2) establishes the three operational pillars (Alert System, Emergency Mechanism, Incident Review Mechanism).

Artefacts an auditor will ask for
  • Internal mapping of the entity's cybersecurity functions to the three CSA pillars (where the entity operates as a National Cyber Hub member, hosts an SOC participating in a Cross-Border Cyber Hub, contributes to the EU Cybersecurity Reserve as a trusted provider, or is an NIS2-scope essential/important entity)
Where this commonly fails
  • Treating the CSA as ENISA-only legislation - it imposes operational involvement on Member State SOCs and on the EU Cybersecurity Reserve trusted providers
CSA-Art.2
Definitions (Article 2)

Article 2 supplies definitions, in alignment with the NIS2 Directive ((EU) 2022/2555) and the Cybersecurity Act ((EU) 2019/881): 'cybersecurity threat', 'significant cybersecurity incident', 'large-scale cybersecurity incident', 'National Cyber Hub', 'Cross-Border Cyber Hub', 'cyber threat intelligence', 'EU Cybersecurity Reserve', 'trusted managed security service provider', and 'national competent authority' (the Member State authority for the CSA, normally aligned with the NIS2 single point of contact).

Artefacts an auditor will ask for
  • Definitions glossary aligning the entity's internal terminology to Article 2 and to NIS2 / Cybersecurity Act baseline definitions
  • Internal classification of incidents against the Article 2 thresholds (significant vs large-scale)
Where this commonly fails
  • Internal incident-severity classification that drifts from the CSA / NIS2 thresholds
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.