Glossary · NIS2

Incident Notification (72 Hours)

The second NIS2 incident report, due within 72 hours, updating the early warning with an initial assessment of severity and impact.

Explained in depth: NIS2 incident reporting timeline

Within 72 hours of becoming aware of a significant incident, the entity must submit an incident notification that updates the information in the early warning and provides an initial assessment of the incident, including its severity and impact, and, where available, indicators of compromise. Note that the 72-hour clock runs from awareness of the incident, not from the early warning. The 72-hour deadline invites comparison with GDPR's 72-hour personal data breach notification, but they are separate obligations to separate authorities: an incident involving personal data at an in-scope entity may require both a NIS2 notification to the CSIRT and a GDPR notification to the data protection authority.

Why it matters

This is the report where substance is expected: severity, impact on services, and technical indicators. Incident response playbooks should schedule an internal assessment checkpoint well before hour 72 so the notification is grounded in facts rather than guesswork.

Used in

See also

← All glossary terms