NIS2 incident reporting: 24h early warning, 72h notification, final report
NIS2 sets a multi-stage reporting process for significant incidents, sent to the CSIRT or competent authority. This page explains the deadlines, the content of each report and how to judge whether an incident is significant.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
The reporting timeline step by step
An early warning is due without undue delay and in any event within 24 hours of becoming aware of the significant incident. Where applicable, it indicates whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.
An incident notification follows within 72 hours of becoming aware of the incident. It updates the early warning and gives an initial assessment of severity and impact, plus indicators of compromise where available. The CSIRT or authority can request an intermediate report on relevant status updates.
A final report is due no later than one month after the incident notification. It covers a detailed description, the likely root cause, mitigation measures and any cross-border impact. If the incident is still ongoing, a progress report is submitted at that time and the final report within one month of handling the incident.
When is an incident significant?
Under Article 23(3), an incident is significant if it has caused or is capable of causing severe operational disruption of services or financial loss for the entity, or if it has affected or can affect other persons by causing considerable material or non-material damage.
For DNS, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers, Implementing Regulation (EU) 2024/2690 adds criteria. These include direct financial loss exceeding EUR 500,000 or 5% of total annual turnover of the preceding financial year, whichever is lower, exfiltration of trade secrets, death or considerable damage to a person's health.
Recurring incidents linked by the same apparent root cause count collectively as significant if together they meet the financial loss criterion and occurred at least twice within six months.
Frequently asked questions
Does notifying an incident expose us to more liability?
No. Article 23 states that the mere act of notification shall not subject the notifying entity to increased liability.
What does the CSIRT do after receiving the early warning?
It must respond without undue delay and where possible within 24 hours, with initial feedback and, on request, guidance or operational advice on mitigation. If the incident is suspected to be criminal, it also gives guidance on reporting to law enforcement.
Are trust service providers subject to a different deadline?
Yes. For significant incidents affecting the provision of their trust services, trust service providers must notify within 24 hours of becoming aware of the incident, instead of the 72-hour incident notification.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs β¬0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_β¦"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_β¦"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_β¦" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_β¦with your key. - Full details (responses, errors, JS and Python examples): developer docs.