NIS2 incident reporting: 24h early warning, 72h notification, final report
NIS2 sets a multi-stage reporting process for significant incidents, sent to the CSIRT or competent authority. This page explains the deadlines, the content of each report and how to judge whether an incident is significant.
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
The reporting timeline step by step
An early warning is due without undue delay and in any event within 24 hours of becoming aware of the significant incident. Where applicable, it indicates whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.
An incident notification follows within 72 hours of becoming aware of the incident. It updates the early warning and gives an initial assessment of severity and impact, plus indicators of compromise where available. The CSIRT or authority can request an intermediate report on relevant status updates.
A final report is due no later than one month after the incident notification. It covers a detailed description, the likely root cause, mitigation measures and any cross-border impact. If the incident is still ongoing, a progress report is submitted at that time and the final report within one month of handling the incident.
When is an incident significant?
Under Article 23(3), an incident is significant if it has caused or is capable of causing severe operational disruption of services or financial loss for the entity, or if it has affected or can affect other persons by causing considerable material or non-material damage.
For DNS, cloud, data centre, CDN, managed (security) service providers, online marketplaces, search engines, social networks and trust service providers, Implementing Regulation (EU) 2024/2690 adds criteria. These include direct financial loss exceeding EUR 500,000 or 5% of total annual turnover of the preceding financial year, whichever is lower, exfiltration of trade secrets, death or considerable damage to a person's health.
Recurring incidents linked by the same apparent root cause count collectively as significant if together they meet the financial loss criterion and occurred at least twice within six months.
Questions fréquentes
Does notifying an incident expose us to more liability?
No. Article 23 states that the mere act of notification shall not subject the notifying entity to increased liability.
What does the CSIRT do after receiving the early warning?
It must respond without undue delay and where possible within 24 hours, with initial feedback and, on request, guidance or operational advice on mitigation. If the incident is suspected to be criminal, it also gives guidance on reporting to law enforcement.
Are trust service providers subject to a different deadline?
Yes. For significant incidents affecting the provision of their trust services, trust service providers must notify within 24 hours of becoming aware of the incident, instead of the 72-hour incident notification.
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.