NIS2 Incident Reporting Timeline: the 24-Hour Early Warning, 72-Hour Notification and Final Report
NIS2 sets a three-stage clock for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month of the notification (or a progress report, then the final report within one month of handling the incident, if it is still running). The CSIRT must reply to the early warning, where possible within 24 hours. For UK organisations whose security operations centre handles incidents for EU entities, the challenge is less the rule than the routing: which national CSIRT, under which country's law, with which evidence.
The UK angle: whose obligation is it?
Article 23 of Directive (EU) 2022/2555 places the reporting duty on the essential or important entity, not on whoever operates the SOC. If your UK headquarters runs detection and response for an EU subsidiary, the subsidiary remains the reporting entity under the national law of the Member State concerned. If you are a UK-based provider of a digital service listed in Article 26(1)(b), such as cloud computing, managed services or managed security services, with no EU establishment, your designated EU representative is the point of contact: the directive defines the representative as the person that "may be addressed by a competent authority or a CSIRT in the place of the entity itself".
UK domestic incident-reporting regimes are not among the sources of the NIS2 knowledge base and are not covered here. Keep them in a separate column of your playbook.
What starts the clock
Every deadline runs "from becoming aware of the significant incident". Two definitions matter:
- Significant incident (Article 23(3)): an incident that "has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned", or that "has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage".
- Aware (recital 31 of Implementing Regulation (EU) 2024/2690): the entity is regarded as aware "when, after such initial assessment, that entity has a reasonable degree of certainty that a significant incident has occurred". The initial assessment of a suspicious event must itself be carried out "in a timely manner".
For the digital infrastructure and ICT service providers covered by that Implementing Regulation, significance is partly quantified. For instance, any incident causing or capable of causing direct financial loss above EUR 500,000 or 5% of the previous year's turnover, whichever is lower, is significant; so is a successful, suspectedly malicious and unauthorised access capable of causing severe operational disruption. Recurring incidents with the same apparent root cause, occurring at least twice within six months, are treated as one significant incident if together they meet the financial-loss criterion.
Hour by hour: the Article 23(4) sequence
From awareness to closure
| Time from awareness | What is due | Key content |
|---|---|---|
| Up to 24 hours | Early warning | Whether the incident is suspected of being caused by unlawful or malicious acts, or could have a cross-border impact (where applicable) |
| Up to 72 hours | Incident notification | Update of the early warning; initial assessment of severity and impact; indicators of compromise where available |
| Any time, on request | Intermediate report | Relevant status updates |
| One month after the notification | Final report | Detailed description, severity and impact; threat type or likely root cause; applied and ongoing mitigation; cross-border impact where applicable |
| If still ongoing at that date | Progress report, then final report within one month of handling | Current status, then the full final report |
Each deadline is a ceiling: the directive requires reports "without undue delay and in any event within" the period. A worked example: awareness at 15:00 CET on a Friday means an early warning by 15:00 on Saturday and a notification by 15:00 on Monday. Article 23 does not mention any weekend or bank-holiday pause, so plan your on-call rota accordingly. If the notification goes in on Sunday, the final report is due one month after that Sunday submission.
Trust service providers: 24 hours, not 72
Under the second subparagraph of Article 23(4), a trust service provider must notify significant incidents affecting its trust services within 24 hours of becoming aware, rather than 72.
Drafting each report
The early warning
Keep it lean. Recital 102 of NIS2 says it "should only include the information necessary" to make the CSIRT aware and allow you to seek assistance, and that reporting should not divert resources from incident handling. Include who you are, what is affected, whether malicious activity is suspected, possible cross-border reach, and whether you want support.
The incident notification
Correct or complete the early warning, then give an initial assessment of severity and impact and, where available, indicators of compromise. Article 23(1) also asks for "any information enabling the CSIRT … to determine any cross-border impact", which matters for groups with operations in several Member States.
The final report
This is where root cause analysis pays off. Implementing Regulation 2024/2690 (Annex, point 3.6) requires the digital providers it covers to carry out post-incident reviews identifying, where possible, the root cause and documenting lessons learned. ENISA's June 2025 guidance suggests investigating significant incidents and writing "final incident reports, including actions taken and recommendations". Reuse that work for the regulatory report.
What the authorities owe you
- A reply. Under Article 23(5), the CSIRT or competent authority must respond "without undue delay and where possible within 24 hours of receiving the early warning", with initial feedback and, on request, guidance or operational advice on mitigation.
- Technical support on request, and guidance on reporting to law enforcement where the incident is suspected to be criminal.
- No extra liability for reporting. "The mere act of notification shall not subject the notifying entity to increased liability" (Article 23(1)).
- Consultation before publicity. The CSIRT or authority may inform the public, or require you to, but only after consulting you (Article 23(7)).
- Cross-border relay. Where the incident concerns two or more Member States, the national bodies inform the others and ENISA (Article 23(6)).
Five failure points to design out
- Unclear routing. Record in advance, per EU entity, the Member State with jurisdiction under Article 26 and the CSIRT or authority's channel.
- No predefined criteria. Point 3.4.2 of the Implementing Regulation's Annex requires assessment "based on predefined criteria laid down in advance" and a quarterly check for recurring incidents.
- Forgotten customers. Where appropriate, service recipients must be told of significant incidents likely to affect the service (Article 23(1)) and of remedies against significant cyber threats (Article 23(2)).
- Weak evidence. The Annex (point 3.5.4) requires the digital providers it covers to log incident response activities and record evidence, and supervisors may ask for proof of implementation.
- Untested process. ENISA's guidance suggests testing incident response at least annually and, where necessary, involving management bodies so they understand their role.
Failing to notify or remedy significant incidents is listed among serious infringements in Article 32(7), which authorities weigh when choosing enforcement measures and fines. If the incident also involves personal data, Article 35 has the NIS2 authority inform the data protection authority; the GDPR's own rules are outside this base.
Give your responders an answer they can cite
The NIS2 knowledge base answers questions such as "If a CSIRT receives our early-warning notification, are they required to respond?" with the exact passage from the directive or the Implementing Regulation.
National transposing laws set portals and procedures, and transposition was still incomplete in some Member States when the Commission's tracker was consulted on 2 October 2026. Check the transposition status for each country concerned. This guide explains the EU rules and is not legal advice.
Frequently asked questions
How long do you have to report an incident under NIS2?
24 hours from becoming aware of a significant incident for the early warning, 72 hours for the incident notification, and one month after the notification for the final report (Article 23(4)). Trust service providers have 24 hours for the notification.
Does a UK company report NIS2 incidents to a UK authority?
NIS2 reports go to the CSIRT or competent authority of the EU Member State with jurisdiction under Article 26. UK domestic reporting duties are not covered by the base.
When are you 'aware' of an incident under NIS2?
According to recital 31 of Implementing Regulation (EU) 2024/2690, when, after a timely initial assessment, the entity has a reasonable degree of certainty that a significant incident has occurred.
What must a NIS2 final report include?
A detailed description including severity and impact, the type of threat or likely root cause, the mitigation measures applied and ongoing, and, where applicable, the cross-border impact (Article 23(4)(d)).
Can we report incidents that are not significant?
Yes. Article 30 provides for voluntary notification of incidents, cyber threats and near misses; Member States may prioritise mandatory notifications over voluntary ones.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.