NIS2
NIS2 incident reporting: the 24-hour, 72-hour and one-month deadlines
Updated September 26, 2026
Article 23 of NIS2 sets a strict reporting timeline for significant incidents. The clock starts when you become aware of the incident, not when you finish investigating it.
What is a significant incident?
An incident is significant if it has caused or can cause severe operational disruption of your services or financial loss for your organisation, or if it has affected or can affect other people or organisations by causing considerable material or non-material damage (Art. 23(3)).
For digital infrastructure and managed service providers, Implementing Regulation (EU) 2024/2690 adds concrete thresholds, for example direct financial loss above €500,000 or 5% of annual turnover, whichever is lower.
The timeline
- Within 24 hours: an early warning, saying whether the incident is suspected to be malicious and whether it could have cross-border impact.
- Within 72 hours: an incident notification with an initial assessment, severity and impact, and indicators of compromise where available.
- On request: intermediate reports.
- Within one month of the notification: a final report with a detailed description, the root cause, the mitigation measures and any cross-border impact.
Why most organisations miss the first deadline
Twenty-four hours is not enough time to find out who decides whether an incident is significant, where the reporting form is, and who is authorised to send it. Those decisions must be made in advance.
- Name who decides significance and who submits, with deputies.
- Keep the authority's reporting channel and a contact sheet on paper, in case email is compromised.
- Agree an out-of-band communication channel for the response team.
- Make suppliers who host or run your systems notify you quickly, in the contract.
- Rehearse once a year with a tabletop exercise.
Personal data too?
If the incident also involves personal data, the GDPR requires a separate notification to the data protection authority within 72 hours (Art. 33 GDPR). Plan for both.
Our NIS2 kit includes an incident response and reporting procedure with the significance test, report templates for each deadline and a tabletop scenario.
Where does your company stand on NIS2?
Free assessment, about 10 minutes, score for every area of the law.
Start the free assessmentThis guide is general information, not legal advice.