NIS2 guide
NIS2 incident reporting in three stages
Essential and important entities must report significant incidents in fixed stages. The first deadline is 24 hours. If you work out the process only when an incident happens, you will almost certainly miss it.
Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law
When an incident is significant
Article 23 NIS2 does not cover every security incident, only significant ones. Under Article 23(3), an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
The key words are “capable of”. You do not have to wait until damage occurs. An attack that could have stopped your production is significant even if you contain it in time, as long as the risk was real. A phishing attempt that was blocked without consequences is not.
For certain digital providers, Implementing Regulation (EU) 2024/2690 sets concrete thresholds. Among other things, an incident is significant if it causes or is capable of causing direct financial loss above €500,000 or 5% of annual turnover, whichever is lower, if it leads to the exfiltration of trade secrets, or if it causes or could cause the death of a person (Art. 3 of the regulation). Further criteria apply to each type of provider. Other sectors can use these thresholds as a guide, but national authorities may set their own.
| Incident | Why it can be significant |
|---|---|
| Ransomware encrypts the ERP server | Orders, warehouse and shipping stop. That is a severe operational disruption, often with data exfiltration. |
| The managing director’s mailbox is compromised | Attackers read confidential correspondence and can redirect payments. Financial loss and damage to business partners are possible. |
| A DDoS attack takes the customer portal offline for hours | Customers cannot order or access their data. The service is disrupted for its recipients. |
| Your cloud provider goes down after an attack | The incident is at the provider, but the disruption is in your business. Your own reporting duty may still be triggered. |
The reporting stages as a timeline
The deadlines run from the moment you become aware of the significant incident. This is not a licence to delay the assessment. If alerts sit unread for days, it will be hard to claim late awareness.
Early warning: within 24 hours
Without undue delay and in any event within 24 hours of becoming aware (Art. 23(4)(a)). It states whether the incident is suspected of being caused by unlawful or malicious acts and whether it could have a cross-border impact. Short and on time is better than complete and late.
Incident notification: within 72 hours
Within 72 hours of becoming aware (Art. 23(4)(b)). It updates the early warning and gives an initial assessment of the incident, including its severity and impact, and indicators of compromise where available. Trust service providers must send this notification within 24 hours for incidents affecting their trust services.
Intermediate report: on request
The CSIRT or competent authority may request an intermediate report on relevant status updates (Art. 23(4)(c)).
Final report: within one month
No later than one month after the incident notification (Art. 23(4)(d)). It contains a detailed description of the incident, the type of threat or root cause that likely triggered it, the mitigation measures applied and ongoing, and any cross-border impact.
Progress report for ongoing incidents
If the incident is still ongoing when the final report is due, you submit a progress report instead, and the final report within one month of handling the incident (Art. 23(4)(e)).
Who receives the reports
Reports go to the national CSIRT or, where applicable, the competent authority (Art. 23(1)). Who that is, and which portal or form to use, depends on your Member State. In some countries one central body receives all reports; in others it depends on the sector. Some national laws also set reporting to several bodies at once. The transposition overview names the authorities of the countries with a national law, and our country versions describe the reporting channel.
The CSIRT must respond within 24 hours of receiving the early warning, with initial feedback and, on request, guidance on mitigation (Art. 23(5)). Where several Member States are affected, the authority informs the others and ENISA.
Informing recipients of your services
Where appropriate, you must inform recipients of your services without undue delay of significant incidents that are likely to adversely affect the provision of those services (Art. 23(1)). If a significant cyber threat could affect them, you also tell them about measures or remedies they can take, and where appropriate about the threat itself (Art. 23(2)).
In practice: keep text modules for a customer notice ready, decide who approves it, and agree the distribution list in advance.
Preparing the reporting chain
The 24-hour deadline can only be met if the process exists before the incident. An incident on a Friday evening is normal, not an exception. Settle and write down these points:
- Roles: who assesses whether an incident is significant, who decides on reporting, who submits the report. The decision belongs to management or a named delegate.
- Deputies: at least one deputy for each role, including weekends and holidays.
- Portal access: at least two people with working access to the national reporting channel, tested in advance.
- Templates: one each for the early warning, the incident notification and the final report, plus templates for the GDPR notification and the customer notice.
- Criteria: a short list of thresholds for downtime, customers affected and loss that make an incident significant.
- Offline contacts: phone numbers of the crisis team, IT providers, data protection officer, insurer and legal advisers on paper and on a device outside the company IT.
- Suppliers: contracts that oblige IT and cloud providers to report incidents to you without delay.
- Exercise: a yearly tabletop exercise that runs through to a test report.
The NIS2 scoring checks these points in the area “Registration and incident reporting”. Incident handling itself is one of the ten measures under Article 21(2)(b).
Frequently asked questions
When does the 24-hour deadline start?
When your organisation becomes aware of the significant incident (Art. 23(4)(a)). The time of the attack itself is not decisive.
Do I have to report an attack that was stopped?
Yes, if it was capable of causing severe operational disruption or financial loss. The definition in Article 23(3) covers possible consequences.
Does the NIS2 report replace the GDPR notification?
No. If personal data is affected, you also notify the data protection authority under Article 33 GDPR within 72 hours.
Where do I send the report?
To the national CSIRT or competent authority of your Member State (Art. 23(1)). The channel is set by national law; see our transposition overview and country versions.