NIS2 Incident Reporting Timeline: Early Warning, Notification and Final Report Deadlines
Under Article 23 of NIS2, once you become aware of a significant incident you must send your CSIRT or competent authority an early warning within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the incident notification. If the incident is still ongoing at that point, you send a progress report instead and the final report within one month of handling the incident. The CSIRT, for its part, must respond to your early warning, where possible within 24 hours. Here is how to turn those rules into an incident-response playbook.
Who must report, and to whom
The obligation applies to essential and important entities under Directive (EU) 2022/2555. For a US company, that typically means an EU subsidiary in an Annex I or II sector, or a cloud, managed-service or other digital provider supervised in the EU. Reports go to the national CSIRT or, where the Member State has chosen so, the competent authority; if you notify the competent authority, it must forward the notification to the CSIRT "upon receipt" (Article 23(1)).
Which country's CSIRT? As a rule, that of the Member State where the entity is established. Certain digital providers (DNS, cloud, data centers, CDNs, managed service and managed security service providers, online marketplaces, search engines, social networks) report in the Member State of their main EU establishment, under Article 26. Build that answer into your playbook in advance; you will not want to research it at hour 20.
Reporting is not only owed to authorities. Where appropriate, you must also notify, without undue delay, "the recipients of their services of significant incidents that are likely to adversely affect the provision of those services" (Article 23(1)), and Article 23(2) requires you to tell recipients potentially affected by a significant cyber threat what measures or remedies they can take.
When does the clock start? "Becoming aware"
All three deadlines run from the moment you become aware of the significant incident, not from the first alert. Recital 31 of Commission Implementing Regulation (EU) 2024/2690 explains the logic: after detecting a suspicious event, or being told about one by a customer, a third party or the media, the entity should assess it "in a timely manner". It is regarded as aware "when, after such initial assessment, that entity has a reasonable degree of certainty that a significant incident has occurred."
That does not license slow triage. An incident is significant under Article 23(3) of the directive if it "has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned" or has affected or is capable of affecting others "by causing considerable material or non-material damage." The words "capable of" mean you do not need to wait for the damage to happen. For DNS, cloud, data center, CDN, managed service, online platform and trust service providers, the 2024 Implementing Regulation adds quantified criteria, such as direct financial loss above EUR 500,000 or 5% of annual turnover, whichever is lower.
Document the awareness moment
Because the deadlines hinge on awareness, log the time and the reasoning of your initial assessment. Supervisors can later ask for "evidence of implementation of cybersecurity policies" (Article 32(2)(g)), and a failure to notify significant incidents is listed as a serious infringement in Article 32(7).
The three-stage timeline at a glance
NIS2 Article 23(4) reporting stages
| Stage | Deadline | Required content |
|---|---|---|
| Early warning | Without undue delay and in any event within 24 hours of becoming aware | Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, or could have a cross-border impact |
| Incident notification | Without undue delay and in any event within 72 hours of becoming aware | Updates to the early warning; initial assessment including severity and impact; indicators of compromise, where available |
| Intermediate report | Only on request of the CSIRT or competent authority | Relevant status updates |
| Final report | Not later than one month after submitting the incident notification | Detailed description, including severity and impact; type of threat or likely root cause; applied and ongoing mitigation measures; cross-border impact, where applicable |
| Progress report (if still ongoing) | At the time the final report would be due | Status at that time; the final report then follows within one month of handling the incident |
Worked example. Your EU subsidiary's SOC reaches a reasonable degree of certainty that a ransomware event is significant on Monday at 10:00 a.m. local time. The early warning is due by Tuesday 10:00 a.m. (+24 hours) and the incident notification by Thursday 10:00 a.m. (+72 hours). If you file the notification on Wednesday, the one-month final-report deadline runs from that Wednesday submission, not from Monday. These are outer limits: the text says "without undue delay and in any event within" each period.
One exception: a trust service provider must send the incident notification for significant incidents affecting its trust services within 24 hours, not 72 (Article 23(4), second subparagraph).
What to put in each report
Early warning: short on purpose
Recital 102 of NIS2 says the early warning "should only include the information necessary" to make the CSIRT aware of the incident and allow you to seek assistance. It also says Member States should ensure reporting does not divert resources from incident handling. In practice: entity identity and contact, what is affected, whether malicious action is suspected, whether other EU countries could be affected, and whether you want help.
Incident notification: the first real assessment
At 72 hours you update the early warning and give an initial assessment of severity and impact, plus indicators of compromise where you have them. The Commission's 2023 guidelines on Article 4 restate these elements, which is helpful if you report under several regimes.
Final report: root cause and remediation
- a detailed description of the incident, including its severity and impact;
- the type of threat or root cause that likely triggered it;
- mitigation measures applied and ongoing;
- where applicable, the cross-border impact.
Article 23(1) adds a general requirement across all stages: report "any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident." Exact forms and portals are national; Article 23(11) lets the Commission specify the type of information, format and procedure by implementing act.
Does the CSIRT have to answer?
Yes. Article 23(5) requires the CSIRT or competent authority to respond "without undue delay and where possible within 24 hours of receiving the early warning", with initial feedback and, if you ask, "guidance or operational advice on the implementation of possible mitigation measures." The CSIRT must provide additional technical support on request, and if the incident is suspected to be criminal, guidance on reporting it to law enforcement.
Two further reassurances in the text: "The mere act of notification shall not subject the notifying entity to increased liability" (Article 23(1)), and the authority may inform the public, or require you to, only "after consulting the entity concerned" (Article 23(7)). If the incident touches two or more Member States, the CSIRT, authority or single point of contact informs the others and ENISA (Article 23(6)).
Building the playbook: a checklist
- Map jurisdictions. For each EU entity, record the competent CSIRT or authority and its reporting channel.
- Define significance criteria in advance. The 2024 Implementing Regulation (Annex, point 3.4.2) requires in-scope digital providers to assess events "based on predefined criteria laid down in advance" and to check for recurring incidents quarterly.
- Pre-draft templates for the early warning, notification and final report, with the fields listed above.
- Assign roles and escalation. Point 3.1.2 of the same Annex requires communication plans "including for escalation and reporting" and documents such as escalation charts and contact lists.
- Track the awareness timestamp and compute the 24h and 72h deadlines automatically.
- Plan customer notices for incidents likely to affect service recipients.
- Test it. ENISA's June 2025 technical implementation guidance suggests testing incident response procedures at least annually, including scenarios such as ransomware, phishing, data breach and DoS.
The incident may also be a personal data breach. NIS2 Article 35 requires the NIS2 authority to inform the data protection authority in that case, and prevents a double NIS2 fine for the same conduct already fined under the GDPR. GDPR's own notification rules are not covered by the NIS2 knowledge base, so check them separately.
Put the NIS2 reporting rules in your responders' hands
Ask the NIS2 knowledge base questions like "After we first notice a significant incident, exactly how much time do we have for the early warning, the incident notification and the final report?" and get answers citing Article 23.
Deadlines and portals are set in national transposing laws, and transposition is not complete in every Member State: as of the Commission's tracker consulted on 2 October 2026, four Member States had been referred to the Court of Justice on 8 July 2026 for failing to notify transposition. Confirm the national rules, and read the directive text on EUR-Lex. This article is not legal advice.
Frequently asked questions
What is the NIS2 24-hour rule?
Article 23(4)(a) requires an early warning to the CSIRT or competent authority without undue delay and in any event within 24 hours of becoming aware of a significant incident, indicating where applicable whether it is suspected to be malicious or could have a cross-border impact.
Is the NIS2 final report due one month after the incident?
No. It is due not later than one month after the submission of the incident notification. If the incident is still ongoing then, you provide a progress report and the final report within one month of handling the incident.
Do we have to report every incident under NIS2?
Mandatory reporting covers significant incidents only, as defined in Article 23(3). Article 30 allows voluntary notification of other incidents, cyber threats and near misses, which Member States may process with lower priority.
Must the CSIRT reply to our early warning?
Yes. Article 23(5) requires a response without undue delay and, where possible, within 24 hours of receiving the early warning, including initial feedback and, on request, guidance or operational advice on mitigation.
Are trust service providers subject to the same 72-hour deadline?
No. For significant incidents affecting their trust services, they must notify within 24 hours of becoming aware (Article 23(4), second subparagraph).
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.