Glossary · NIS2

Article 23

The NIS2 provision setting the mandatory incident reporting timeline.

Explained in depth: NIS2 incident reporting timeline

Article 23 obliges essential and important entities to report significant incidents to their national CSIRT or competent authority in three stages: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours that updates and assesses the incident, and a final report no later than one month after the incident notification. If the incident is still ongoing at the one-month mark, a progress report is submitted instead, with the final report due within one month of the incident being handled. Entities must also, where appropriate, notify the recipients of their services about significant incidents that are likely to adversely affect them, and about measures those recipients can take in response to significant cyber threats.

Why it matters

24 hours is short. Meeting the deadline requires a pre-defined incident classification procedure, an on-call escalation path, and templates prepared in advance. Failure to report on time is itself an infringement, separate from the incident.

Used in

See also

← All glossary terms