NIS2 Directive Compliance

NIS2 Incident Reporting Requirements: What the 24-Hour Deadline Means for Your Organization

Under the NIS2 Directive, you have just 24 hours to submit an early warning after detecting a significant incident. Most organizations aren't operationally ready. Here's exactly what's required , and how to make sure you don't miss the window.

Directive (EU) 2022/2555 introduces the most aggressive incident reporting timelines in EU regulatory history. Failure to comply can result in administrative fines of up to €10 million or 2% of global annual turnover. This page breaks down every requirement so your compliance, IT security, and legal teams can prepare , before the clock starts ticking.

Free PDF , just your name and business email. No sales follow-up unless you ask.

Trusted by privacy and compliance teams managing NIS2 readiness across the EU

Swiss Hosted ISO 27001 Infrastructure GDPR-Compliant Platform 30+ EU Jurisdictions Covered
Trusted by 50+ privacy teams across 14 countries
Healthcare
Aviation
Energy
Legal
Technology
Zurzach logo
AXA logo
Openmedical logo
Glencore logo
Pilatus logo
Liferay logo
CareerFairy logo
Voicepoint logo
Kellerhals Carrard logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo
Liferay logo
CareerFairy logo
Zurzach logo
Voicepoint logo
Openmedical logo
Kellerhals Carrard logo
AXA logo
Aclaris logo
Avantec logo
Diakonie Bethanien logo

NIS2 Incident Reporting Requirements: The Complete 24-Hour, 72-Hour, and 30-Day Timeline

Article 23 of the NIS2 Directive mandates three distinct reporting stages after detecting a significant incident. Each has different requirements, different levels of detail, and the same unforgiving deadlines. Here is exactly what each stage demands.

Stage 1

24 Hours

From the moment you become aware of a significant incident

Early Warning Notification

Your first mandatory submission to the designated CSIRT or competent authority. This is not a full incident report . it is an early alert designed to enable coordinated response across the EU.

  • Indicate whether the incident is suspected to be caused by unlawful or malicious acts
  • Flag potential cross-border impact to trigger coordination between member states
  • Submit to the nationally designated CSIRT , which varies by member state and sector

The multi-entity challenge

Subsidiaries in multiple member states may require simultaneous notifications to different CSIRTs , each with different portals and formats , within the same 24-hour window.

NIS2 Directive (EU) 2022/2555, Article 23(4)(a)

Stage 2

72 Hours

From the moment you became aware of the significant incident

Incident Notification

A more detailed update that builds on your early warning. This is where technical depth becomes critical , your authority expects an initial assessment they can act on.

  • Update the information provided in the early warning with any new findings
  • Include initial assessment of severity, impact scope, and indicators of compromise
  • Document affected systems, services, and estimated number of impacted users or entities

Where most organizations fail

Without pre-defined workflows, teams spend the first 48 hours determining who owns what , leaving barely 24 hours to compile an assessment that meets regulatory standards.

NIS2 Directive (EU) 2022/2555, Article 23(4)(b)

Stage 3

30 Days

From the submission of your 72-hour incident notification

Final Incident Report

The comprehensive, detailed report that becomes part of your permanent compliance record. This is what supervisory authorities will reference in enforcement actions and audits.

  • Detailed description of the incident including severity and full impact assessment
  • Root cause analysis: the type of threat or vulnerability that likely triggered the incident
  • Applied and ongoing mitigation measures, plus cross-border impact documentation

Your audit-readiness moment

Organizations that maintain structured incident workflows generate this report in hours. Those relying on ad-hoc processes spend weeks reconstructing events from email chains and chat logs.

NIS2 Directive (EU) 2022/2555, Article 23(4)(d-e)

Not sure whether your organization qualifies as essential or important under NIS2 , or which CSIRTs you need to notify? Our checklist covers entity classification, notification contacts by member state, and a step-by-step workflow for each reporting stage.

Download the Free NIS2 Incident Reporting Checklist

200+

Hours saved on compliance documentation

Medtec reclaimed 200+ hours during ISO 27001 preparation by replacing manual documentation workflows with automated compliance evidence generation.

60%

Reduction in compliance admin time

Aircraft manufacturer achieved a 60% reduction in compliance admin time within 6 months , predictable pricing based on entities, not per-user expansion traps.

3 mo

Ahead of schedule on ISO 27001

Medtec reached audit-readiness three months ahead of their original timeline using Priverion's automated evidence packages and compliance dashboards.

Why mid-market teams are leaving OneTrust for Priverion

You shouldn't need an enterprise sales cycle and a six-figure budget to manage privacy across your group. Here's what the comparison actually looks like when you strip away the marketing.

The typical enterprise platform

What you're used to

Per-user, per-module pricing

Costs balloon every time you add a subsidiary, a user, or a module. Budgets become unpredictable within the first year.

US-hosted infrastructure

Data processed under US jurisdiction. Post-Schrems II, this creates a legal headache for every cross-border transfer assessment.

Feature overload

ESG modules, ethics hotlines, cookie consent, and hundreds of connectors you'll never configure. You pay for everything, use a fraction.

Months-long implementation

Dedicated implementation teams, custom consulting engagements, and a 6-month timeline before you see value.

Complexity requires consultants

The interface assumes you have a dedicated privacy operations team. Most mid-market DPOs are already wearing three hats.

Priverion

What it should look like

Predictable, company-based pricing

Pricing based on number of entities and organizational size , not per user or per module. Your CFO gets a number they can trust.

Swiss-built, Swiss-hosted

All data processing within Swiss infrastructure. European data residency guaranteed. In a post-Schrems II world, this isn't a feature . it's a legal requirement.

Purpose-built for privacy

ROPA, DPIAs, DSRs, vendor risk, incident management, AI Register , everything a privacy program needs. Nothing it doesn't. We don't cover ESG, ethics hotlines, or cookie consent, and that's by design.

Operational in weeks, not months

Aircraft manufacturer achieved a 60% reduction in compliance admin time in their first 6 months , including implementation.

Aircraft manufacturer, first 6 months post-deployment

Built for the DPO wearing three hats

AI-assisted drafting and automated recertification mean your team focuses on strategic privacy work , not chasing business units for spreadsheet updates.

Enterprise-grade without enterprise complexity. That's the point.

Book a 30-min walkthrough

Download the NIS2 Incident Reporting Checklist

A step-by-step PDF covering the 24-hour, 72-hour, and 30-day reporting requirements , plus entity classification guidance, CSIRT contact directories by member state, and pre-built internal workflow templates your team can use immediately.

What's inside:

  • Complete timeline with required fields for each reporting stage
  • Essential vs. important entity classification decision tree
  • CSIRT notification contacts and portals by EU member state
  • Internal escalation workflow template for multi-entity groups
  • Cross-border impact assessment template
  • 30-day final report structure with example language

Free PDF , no sales follow-up unless you request it. Your data is processed in Switzerland under Swiss data protection law.

NIS2 Incident Reporting: Your Questions Answered

The most common questions we hear from compliance leads and CISOs preparing for NIS2 incident reporting obligations.

What counts as a "significant incident" under NIS2?

Article 23(3) defines a significant incident as one that has caused or is capable of causing severe operational disruption to services or financial loss, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. The threshold is deliberately broad , when in doubt, report. Under-reporting carries far greater regulatory risk than over-reporting.

When does the 24-hour clock start?

The clock starts from the moment your organization becomes aware of the significant incident , not from the moment it occurred. "Awareness" is interpreted broadly: if your monitoring systems detected an anomaly that a reasonable security team would have investigated, the clock may have already started. This is why automated detection and alerting workflows are critical.

Who do we report to , and does it vary by country?

Yes. Each EU member state designates its own CSIRT (Computer Security Incident Response Team) or competent authority. For multi-entity organizations operating across several member states, this means you may need to submit notifications to multiple different authorities , each with different portals, formats, and language requirements , within the same 24-hour window. Our checklist includes a directory of CSIRT contacts by member state.

What happens if we miss the 24-hour deadline?

NIS2 empowers supervisory authorities to impose administrative fines of up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities. Important entities face fines up to €7 million or 1.4% of turnover. Beyond fines, management bodies can be held personally liable . NIS2 Article 20 explicitly holds senior leadership accountable for ensuring compliance with risk management and reporting obligations.

How does NIS2 incident reporting relate to GDPR breach notification?

They are separate obligations with different triggers, timelines, and authorities. A single incident can trigger both: GDPR's 72-hour notification to data protection authorities (if personal data is involved) and NIS2's 24-hour early warning to the CSIRT (if services are disrupted). Your incident response workflow needs to handle both in parallel , which is why integrated incident management platforms matter.

Does Priverion help with NIS2 incident reporting specifically?

Priverion's incident management module provides structured workflows for breach notification and incident documentation, including automated evidence packages and audit-ready reporting. While we built the platform for privacy program management broadly . ROPA, DPIAs, DSRs, vendor risk , the incident management capabilities map directly to NIS2's reporting stages. For organizations managing both GDPR and NIS2 obligations across multiple entities, having a single platform that handles both reporting workflows eliminates the coordination overhead that causes most deadline failures.

Stop managing privacy in spreadsheets

See what group-wide privacy management looks like when it actually works

In 30 minutes, we'll walk you through exactly how organizations like Aircraft manufacturer automated ROPA recertification across every subsidiary , and cut compliance admin time by 60% in their first six months.

Weeks, not months

Average time to full deployment

No per-user pricing

Predictable costs based on entities, not seats

100% Swiss-hosted

Data sovereignty guaranteed

Book a 30-minute walkthrough

No commitment required. We'll tailor the session to your entity structure and compliance gaps.

The Privacy Compliance Briefing

Monthly insights on GDPR enforcement, Swiss FADP updates, and automation strategies for DPOs and compliance teams.

No spam. Unsubscribe anytime.