Skip to content
Stop Ransomware

Resource Center · NIS2 & compliance

NIS2 Incident Reporting: The 24-Hour and 72-Hour Process Explained

Published 3 July 2026 · Updated 3 July 2026 · 7 min read

The short answer

For a significant incident, NIS2 requires a staged notification to your CSIRT or competent authority: an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours, intermediate updates on request, and a final report within one month. Where relevant, you must also inform the recipients of your services. The clock starts at awareness — not at full understanding.

First: what counts as a “significant incident”?

Article 23 gives two triggers. An incident is significant if it:

Note the phrase capable of causing — you do not wait for the damage to materialise. For certain digital sectors (cloud, DNS, data centres, managed service providers and others), Implementing Regulation (EU) 2024/2690 sets concrete thresholds for when an incident is significant. For entities not covered by specific implementing thresholds, significance must be assessed against the general Article 23 criteria, the applicable national rules and any relevant sector guidance. The assessment criteria should be defined before an incident and documented internally.

Two quick examples

The three deadlines, and what goes in each

DeadlineWhat it isWhat it must contain
24 hours
from awareness
Early warning That a significant incident occurred; whether you suspect it was caused by unlawful or malicious acts; whether it could have cross-border impact.
72 hours
from awareness
Incident notification Updates the early warning: your initial assessment of severity and impact, and indicators of compromise where available.
1 month
after the 72h notification
Final report Detailed description of the incident, its severity and impact; the threat type or root cause; mitigation applied and ongoing; cross-border impact where relevant. If the incident is still ongoing, a progress report instead — with the final report one month after you close it.

Two calibrations that keep the table honest. The 24-hour report is an early warning, not a completed forensic investigation — and the 72-hour notification contains the information reasonably available at that time. In between, the authority or CSIRT can request intermediate status updates, and ongoing incidents move to progress reporting with the final report following once handling ends, under the rules above.

Additional or sector-specific reporting rules may apply. Where a sector-specific Union legal act imposes cybersecurity risk-management and incident-reporting requirements that are at least equivalent, it may operate as lex specialis for those obligations. This must be assessed regime by regime.

Who else must be told

Romania implementation note

Reporting channels, forms and portals differ by member state. What follows is one national example, not the universal EU process:

Legal requirement vs good practice

The part nobody plans for: reporting while firefighting

The 24- and 72-hour clocks run during your worst day — while systems are down and the team is containing the incident. The practical fix is separation of duties: one person owns containment, another owns the reporting track. If your entire technical response is one person, that is itself a finding — and one of the strongest arguments for having an external response team on call.

This article is general information about EU legislation, not legal advice. Reporting channels, forms and some thresholds are defined by national transposition and sector rules — confirm specifics with your national CSIRT or competent authority (in Romania: DNSC) or legal counsel. This article reflects the legislation in force on the last-reviewed date; proposed amendments are not treated as adopted law.

Could you hit these deadlines today?

Reporting readiness — contacts, criteria, evidence, templates — is one of the areas the free NIS2 Gap Assessment scores. Find out where you stand before an incident does it for you.

Book your free NIS2 Gap Assessment