Compliance Colleague · Answers · NIS2

What are the NIS2 reporting deadlines for a significant incident?

Standard: NIS2 · Answered by Compliance Colleague on September 30, 2026

Question as asked: What are the NIS2 reporting deadlines for a significant incident?

Under Article 23 of Directive (EU) 2022/2555 (NIS2), all reporting deadlines run in clock hours/days from the moment the entity becomes aware of a significant incident — there is no business-hours, weekday-only, or weekend extension in the Directive itself.

"Significant incident" threshold (Art. 23(3)): an incident that (a) has caused or can cause severe operational disruption or financial loss for the entity, or (b) has affected or can affect other persons through considerable material or non-material damage. For the digital-infrastructure/provider entity types covered by Commission Implementing Regulation (EU) 2024/2690 (DNS, TLD registries, cloud, data centre, CDN, MSP, MSSP, online marketplaces/search engines/social networks, trust service providers), that Regulation's Art. 3(1)(a)–(e) sets exhaustive quantitative/qualitative criteria (e.g. financial loss over EUR 500,000 or 5% of turnover, whichever is lower) plus entity-specific thresholds in Arts. 5–14.

Reporting stages (Art. 23(4)):

Deadline (from awareness)ReportRequired content
≤ 24 hoursEarly warningWhether the incident is suspected to be caused by unlawful/malicious action; whether it could have cross-border impact
≤ 72 hours (≤ 24 hours for trust service providers, re incidents affecting their trust services)Incident notificationUpdates the early warning; initial assessment of severity/impact; indicators of compromise where available
On the CSIRT's/authority's requestIntermediate reportRelevant status updates while handling continues
≤ 1 month after the incident notificationFinal reportDetailed description including severity and impact; type of threat/root cause; mitigation measures applied/ongoing; cross-border impact
If handling is still ongoing at the 1-month markProgress report at that point, then a final reportSame fields, once resolved

All reports go to the CSIRT or competent authority via the Member State's single entry point (national transposing law designates the recipient). The CSIRT/authority must give initial feedback on the early warning, where possible within 24 hours, and guidance on request (Art. 23(5)).

Separately, the entity must notify service recipients, where appropriate, of significant incidents likely to affect delivery of the service, without undue delay (Art. 23(1)), and must inform recipients potentially affected by a significant cyber threat of protective measures and, where appropriate, the threat itself (Art. 23(2)).

Note on entity type: whether the quantitative 2024/2690 thresholds or the general Art. 23(3) judgment test applies depends on which Annex I/II category and Art. 6 definition the entity meets — ask again with the entity type for a threshold-specific answer.

If personal data is also involved, GDPR Art. 33/34 breach notification runs on its own separate 72-hour clock to the data protection authority — it does not replace the NIS2 timeline.

Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.

This is one answer from Compliance Colleague, which answers questions like this against 30+ security, privacy and AI governance standards, with the clause cited, and reviews your policies against them. Ask your own question free, no card required →

More answers