See what a professional incident evidence pack looks like
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
CasePack helps MSPs organize the evidence, timeline, milestones, reports, and audit history needed to support NIS2-style incident reporting preparation across client workspaces.
CasePack is not legal advice and does not submit reports to regulators on your behalf. It helps your team structure the operational record behind incident reporting.
NIS2 increases the pressure on covered organizations and their service providers to respond quickly, document clearly, and show an accountable incident process.
For MSPs, this creates a practical challenge: clients may expect help not only with containment and remediation, but also with evidence gathering, incident timelines, initial assessments, communication notes, and final documentation.
The operational question becomes:
Can your team produce a clear incident record quickly enough, consistently enough, and with enough supporting evidence?
NIS2 incident reporting is commonly discussed around a staged reporting workflow:
| Stage | Typical timing | Operational need |
|---|---|---|
| Early warning | 24 hours | Show that the incident is recognized, triaged, and being handled |
| Incident notification | 72 hours | Provide a fuller status update, initial assessment, severity, impact, and available indicators |
| Final report | Around one month | Document incident details, root cause/threat type, mitigation measures, impact, and closure information |
CasePack's NIS2 milestone tracking is opt-in per incident. When enabled, CasePack creates milestone cards for Early Warning, Full Notification, and Final Report, helping teams track deadlines and completion notes.
CasePack gives your MSP a structured place to collect and prepare:
Open or ingest the incident
Create the incident manually or receive it from a PSA/ticketing workflow through a webhook.
Capture first facts
Document title, severity, initial description, affected users, and suspected impact.
Enable NIS2 milestone tracking where relevant
Use the incident action menu to enable NIS2 reporting for incidents that require it.
Add evidence early
Upload screenshots, logs, PDFs, IOCs, ticket exports, analyst notes, and other files as soon as they are collected.
Build the response timeline
Record containment, eradication, recovery, decisions, notes, and status updates.
Generate stage-appropriate reports
Use the Initial Triage, Executive / Client Summary, Final Evidence Pack, or NIS2 Incident Notification templates.
Export the evidence pack
Generate a PDF or ZIP package for review, client communication, audit preparation, or internal closure.
MSPs can use a repeatable incident evidence workflow to:
Capture initial facts, suspected cause, affected systems, active containment, and communication notes.
Update impact, severity, available indicators, response actions, and next steps.
Close with root cause, mitigation, lessons learned, evidence index, timeline, and audit history.
CasePack gives your team the structure to collect evidence, track milestones, generate reports, and export a clean incident package for client and internal review.
EU/ENISA public guidance describes NIS2 reporting as a 24-hour early warning and 72-hour incident notification workflow, with final reporting commonly described around one month after notification. Always confirm your obligations with the applicable national authority.
Reference: ENISA — Threats and incidents (https://www.enisa.europa.eu/topics/state-of-cybersecurity-in-the-eu/threats-and-incidents).
Request a sample CasePack evidence pack or book a 20-minute workflow review to see how CasePack fits next to your PSA, SIEM, EDR, or existing incident process.
CasePack is not legal advice and does not submit reports to regulators on your behalf. Always confirm reporting obligations with qualified legal/compliance counsel and the applicable national authority.