NIS2 Incident Reporting Requirements: The Complete 24-Hour, 72-Hour, and 30-Day Timeline
Article 23 of the NIS2 Directive mandates three distinct reporting stages after detecting a significant incident. Each has different requirements, different levels of detail, and the same unforgiving deadlines. Here is exactly what each stage demands.
24 Hours
From the moment you become aware of a significant incident
Early Warning Notification
Your first mandatory submission to the designated CSIRT or competent authority. This is not a full incident report . it is an early alert designed to enable coordinated response across the EU.
- •Indicate whether the incident is suspected to be caused by unlawful or malicious acts
- •Flag potential cross-border impact to trigger coordination between member states
- •Submit to the nationally designated CSIRT , which varies by member state and sector
The multi-entity challenge
Subsidiaries in multiple member states may require simultaneous notifications to different CSIRTs , each with different portals and formats , within the same 24-hour window.
NIS2 Directive (EU) 2022/2555, Article 23(4)(a)
72 Hours
From the moment you became aware of the significant incident
Incident Notification
A more detailed update that builds on your early warning. This is where technical depth becomes critical , your authority expects an initial assessment they can act on.
- •Update the information provided in the early warning with any new findings
- •Include initial assessment of severity, impact scope, and indicators of compromise
- •Document affected systems, services, and estimated number of impacted users or entities
Where most organizations fail
Without pre-defined workflows, teams spend the first 48 hours determining who owns what , leaving barely 24 hours to compile an assessment that meets regulatory standards.
NIS2 Directive (EU) 2022/2555, Article 23(4)(b)
30 Days
From the submission of your 72-hour incident notification
Final Incident Report
The comprehensive, detailed report that becomes part of your permanent compliance record. This is what supervisory authorities will reference in enforcement actions and audits.
- •Detailed description of the incident including severity and full impact assessment
- •Root cause analysis: the type of threat or vulnerability that likely triggered the incident
- •Applied and ongoing mitigation measures, plus cross-border impact documentation
Your audit-readiness moment
Organizations that maintain structured incident workflows generate this report in hours. Those relying on ad-hoc processes spend weeks reconstructing events from email chains and chat logs.
NIS2 Directive (EU) 2022/2555, Article 23(4)(d-e)
Not sure whether your organization qualifies as essential or important under NIS2 , or which CSIRTs you need to notify? Our checklist covers entity classification, notification contacts by member state, and a step-by-step workflow for each reporting stage.
Download the Free NIS2 Incident Reporting Checklist200+
Hours saved on compliance documentation
Medtec reclaimed 200+ hours during ISO 27001 preparation by replacing manual documentation workflows with automated compliance evidence generation.
60%
Reduction in compliance admin time
Aircraft manufacturer achieved a 60% reduction in compliance admin time within 6 months , predictable pricing based on entities, not per-user expansion traps.
3 mo
Ahead of schedule on ISO 27001
Medtec reached audit-readiness three months ahead of their original timeline using Priverion's automated evidence packages and compliance dashboards.
Why mid-market teams are leaving OneTrust for Priverion
You shouldn't need an enterprise sales cycle and a six-figure budget to manage privacy across your group. Here's what the comparison actually looks like when you strip away the marketing.
The typical enterprise platform
What you're used to
Per-user, per-module pricing
Costs balloon every time you add a subsidiary, a user, or a module. Budgets become unpredictable within the first year.
US-hosted infrastructure
Data processed under US jurisdiction. Post-Schrems II, this creates a legal headache for every cross-border transfer assessment.
Feature overload
ESG modules, ethics hotlines, cookie consent, and hundreds of connectors you'll never configure. You pay for everything, use a fraction.
Months-long implementation
Dedicated implementation teams, custom consulting engagements, and a 6-month timeline before you see value.
Complexity requires consultants
The interface assumes you have a dedicated privacy operations team. Most mid-market DPOs are already wearing three hats.
Priverion
What it should look like
Predictable, company-based pricing
Pricing based on number of entities and organizational size , not per user or per module. Your CFO gets a number they can trust.
Swiss-built, Swiss-hosted
All data processing within Swiss infrastructure. European data residency guaranteed. In a post-Schrems II world, this isn't a feature . it's a legal requirement.
Purpose-built for privacy
ROPA, DPIAs, DSRs, vendor risk, incident management, AI Register , everything a privacy program needs. Nothing it doesn't. We don't cover ESG, ethics hotlines, or cookie consent, and that's by design.
Operational in weeks, not months
Aircraft manufacturer achieved a 60% reduction in compliance admin time in their first 6 months , including implementation.
Aircraft manufacturer, first 6 months post-deployment
Built for the DPO wearing three hats
AI-assisted drafting and automated recertification mean your team focuses on strategic privacy work , not chasing business units for spreadsheet updates.
Enterprise-grade without enterprise complexity. That's the point.
Book a 30-min walkthroughDownload the NIS2 Incident Reporting Checklist
A step-by-step PDF covering the 24-hour, 72-hour, and 30-day reporting requirements , plus entity classification guidance, CSIRT contact directories by member state, and pre-built internal workflow templates your team can use immediately.
What's inside:
- •Complete timeline with required fields for each reporting stage
- •Essential vs. important entity classification decision tree
- •CSIRT notification contacts and portals by EU member state
- •Internal escalation workflow template for multi-entity groups
- •Cross-border impact assessment template
- •30-day final report structure with example language
Free PDF , no sales follow-up unless you request it. Your data is processed in Switzerland under Swiss data protection law.
NIS2 Incident Reporting: Your Questions Answered
The most common questions we hear from compliance leads and CISOs preparing for NIS2 incident reporting obligations.
What counts as a "significant incident" under NIS2?
Article 23(3) defines a significant incident as one that has caused or is capable of causing severe operational disruption to services or financial loss, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. The threshold is deliberately broad , when in doubt, report. Under-reporting carries far greater regulatory risk than over-reporting.
When does the 24-hour clock start?
The clock starts from the moment your organization becomes aware of the significant incident , not from the moment it occurred. "Awareness" is interpreted broadly: if your monitoring systems detected an anomaly that a reasonable security team would have investigated, the clock may have already started. This is why automated detection and alerting workflows are critical.
Who do we report to , and does it vary by country?
Yes. Each EU member state designates its own CSIRT (Computer Security Incident Response Team) or competent authority. For multi-entity organizations operating across several member states, this means you may need to submit notifications to multiple different authorities , each with different portals, formats, and language requirements , within the same 24-hour window. Our checklist includes a directory of CSIRT contacts by member state.
What happens if we miss the 24-hour deadline?
NIS2 empowers supervisory authorities to impose administrative fines of up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities. Important entities face fines up to €7 million or 1.4% of turnover. Beyond fines, management bodies can be held personally liable . NIS2 Article 20 explicitly holds senior leadership accountable for ensuring compliance with risk management and reporting obligations.
How does NIS2 incident reporting relate to GDPR breach notification?
They are separate obligations with different triggers, timelines, and authorities. A single incident can trigger both: GDPR's 72-hour notification to data protection authorities (if personal data is involved) and NIS2's 24-hour early warning to the CSIRT (if services are disrupted). Your incident response workflow needs to handle both in parallel , which is why integrated incident management platforms matter.
Does Priverion help with NIS2 incident reporting specifically?
Priverion's incident management module provides structured workflows for breach notification and incident documentation, including automated evidence packages and audit-ready reporting. While we built the platform for privacy program management broadly . ROPA, DPIAs, DSRs, vendor risk , the incident management capabilities map directly to NIS2's reporting stages. For organizations managing both GDPR and NIS2 obligations across multiple entities, having a single platform that handles both reporting workflows eliminates the coordination overhead that causes most deadline failures.


