What are the NIS2 reporting deadlines for a significant incident?
Question as asked: What are the NIS2 reporting deadlines for a significant incident?
Under Article 23 of Directive (EU) 2022/2555 (NIS2), all reporting deadlines run in clock hours/days from the moment the entity becomes aware of a significant incident — there is no business-hours, weekday-only, or weekend extension in the Directive itself.
"Significant incident" threshold (Art. 23(3)): an incident that (a) has caused or can cause severe operational disruption or financial loss for the entity, or (b) has affected or can affect other persons through considerable material or non-material damage. For the digital-infrastructure/provider entity types covered by Commission Implementing Regulation (EU) 2024/2690 (DNS, TLD registries, cloud, data centre, CDN, MSP, MSSP, online marketplaces/search engines/social networks, trust service providers), that Regulation's Art. 3(1)(a)–(e) sets exhaustive quantitative/qualitative criteria (e.g. financial loss over EUR 500,000 or 5% of turnover, whichever is lower) plus entity-specific thresholds in Arts. 5–14.
Reporting stages (Art. 23(4)):
| Deadline (from awareness) | Report | Required content |
|---|---|---|
| ≤ 24 hours | Early warning | Whether the incident is suspected to be caused by unlawful/malicious action; whether it could have cross-border impact |
| ≤ 72 hours (≤ 24 hours for trust service providers, re incidents affecting their trust services) | Incident notification | Updates the early warning; initial assessment of severity/impact; indicators of compromise where available |
| On the CSIRT's/authority's request | Intermediate report | Relevant status updates while handling continues |
| ≤ 1 month after the incident notification | Final report | Detailed description including severity and impact; type of threat/root cause; mitigation measures applied/ongoing; cross-border impact |
| If handling is still ongoing at the 1-month mark | Progress report at that point, then a final report | Same fields, once resolved |
All reports go to the CSIRT or competent authority via the Member State's single entry point (national transposing law designates the recipient). The CSIRT/authority must give initial feedback on the early warning, where possible within 24 hours, and guidance on request (Art. 23(5)).
Separately, the entity must notify service recipients, where appropriate, of significant incidents likely to affect delivery of the service, without undue delay (Art. 23(1)), and must inform recipients potentially affected by a significant cyber threat of protective measures and, where appropriate, the threat itself (Art. 23(2)).
Note on entity type: whether the quantitative 2024/2690 thresholds or the general Art. 23(3) judgment test applies depends on which Annex I/II category and Art. 6 definition the entity meets — ask again with the entity type for a threshold-specific answer.
If personal data is also involved, GDPR Art. 33/34 breach notification runs on its own separate 72-hour clock to the data protection authority — it does not replace the NIS2 timeline.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)