Directive NIS2 European Union
Cart 0
Art. 23 · Directive (EU) 2022/2555

Incident reporting under NIS2


Three filings, one clock. The clock starts when you become aware — not when the incident began, and not when you finish investigating.

The most expensive misunderstanding

The 24-hour deadline runs from awareness of a significant incident. Organisations routinely lose a day deciding whether an incident qualifies. Decide the criteria in advance, in writing, and let the on-call engineer apply them at 03:00 without convening a committee.

What makes an incident significant


Art. 23(3)
An incident shall be considered to be significant if: (a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; (b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
Directive (EU) 2022/2555

Note « is capable of causing ». A contained incident that could have been severe is still reportable. This is where most internal thresholds are set too high.

The chain


Art. 23(4)(a)
24 hours

Early warning

Submitted to your CSIRT or competent authority within 24 hours of becoming AWARE of the significant incident.

  • Whether the incident is suspected of being caused by unlawful or malicious acts
  • Whether it could have a cross-border impact
  • Enough to let the CSIRT offer assistance or guidance
Art. 23(4)(b)
72 hours

Incident notification

Updates the early warning with a real assessment. This is the substantive filing.

  • An initial assessment of the incident, its severity and impact
  • Indicators of compromise, where available
  • Any update to the cross-border assessment
Art. 23(4)(c)
On request

Intermediate report

Provided when the competent authority or CSIRT asks for it.

  • Relevant status updates
  • Changes to scope or impact assessment
Art. 23(4)(d)
1 month

Final report

Due within one month of the incident notification, not of the incident itself.

  • A detailed description of the incident, its severity and impact
  • The type of threat or root cause that likely triggered it
  • Applied and ongoing mitigation measures
  • Cross-border impact, where applicable

Where you file

To your national CSIRT or competent authority — which means the channel depends on your member state, not on the directive. Some countries run a single portal for all sectors; others route by sector. If you operate in several member states, you may have to file in each affected jurisdiction.

Competent authority and CSIRT per member state →

Telling your customers

Article 23(1) also requires you to notify recipients of your services of significant incidents that are likely to adversely affect the provision of those services. And where the incident is likely to harm them, you must communicate measures or remedies they can take. This is separate from, and additional to, telling the authority.

This is not the only clock

A single incident can trigger NIS2 article 23, GDPR article 33 (72 hours to the data protection authority, where personal data is breached), and sector-specific duties — DORA for financial entities, or national critical infrastructure rules. The deadlines differ and run in parallel. Map them once, before you need them.

Common questions

When exactly does the 24-hour clock start?
When you become aware of a significant incident. Awareness is not the same as full diagnosis: if you know enough to conclude the incident is significant, the clock has started. It does not start when the incident began, nor when your investigation concludes.
What if we are not sure the incident is significant?
The test in article 23(3) includes incidents "capable of causing" severe operational disruption or considerable damage, not only those that did. A contained incident that could have been severe is reportable. Because the assessment must be made within 24 hours, the practical answer is to define your significance criteria in advance so an on-call engineer can apply them without convening a committee.
Is the final report due one month after the incident?
No. It is due within one month of submitting the incident notification — the 72-hour filing — not one month from the incident itself. If the incident is still ongoing at that point, you submit a progress report and then the final report within one month of the incident being handled.
Do we report to one authority if we operate in several member states?
Not necessarily. Reporting goes to the CSIRT or competent authority of the member state concerned, so a cross-border incident can require filings in several jurisdictions, through different portals and in different languages. There are cooperation mechanisms between authorities, but they do not remove your obligation to notify where you are established or providing services.
How does this interact with the GDPR 72-hour breach notification?
They are separate obligations running in parallel. A ransomware incident affecting personal data can trigger NIS2 article 23 (24h early warning to the CSIRT) and GDPR article 33 (72h to the data protection authority) simultaneously, with different recipients, thresholds and content. Financial entities may additionally have DORA reporting duties. Map the deadlines together before an incident, not during one.
Must we tell our customers about an incident?
Yes, where relevant. Article 23(1) requires entities to notify recipients of their services of significant incidents likely to adversely affect the provision of those services, and to communicate any measures or remedies the recipients can take where the incident is likely to harm them. This is additional to notifying the authority.
Art. 23

Article 23 Incident Reporting Template Set

The full reporting chain as fill-in forms, so the 24-hour clock is not spent designing a document.

  • Early warning form (24h) — significance and cross-border indicators
  • Incident notification form (72h) — severity, impact, IoCs
  • Intermediate status report template
  • Final report form (1 month) — root cause, mitigation, cross-border impact
  • Significance decision tree and internal escalation matrix
49 € excl. VAT

Instant download · 30-day money-back guarantee

Cart 0