NIS 2 introduces one of the most demanding incident reporting frameworks in cybersecurity regulation. Organizations must issue an early warning within 24 hours, a detailed notification within 72 hours, and a comprehensive final report within one month of becoming aware of a significant incident. Missing these deadlines can result in penalties on top of the incident itself. This guide breaks down each reporting phase, what constitutes a significant incident, and how to build an incident reporting process that meets NIS 2 requirements.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
Missing NIS 2 reporting deadlines can result in administrative fines and other enforcement measures. Competent authorities consider the severity and circumstances when determining penalties. Even if you miss the 24-hour deadline, submit the early warning as soon as possible — late reporting is better than no reporting, and demonstrating good faith efforts can mitigate penalties.
This depends on how your member state has transposed NIS 2. Some member states designate the CSIRT as the primary recipient, others designate sector-specific competent authorities, and some establish a single reporting point. Check your national transposition law for the correct reporting channel. In many cases, ENISA provides a directory of national reporting contacts.
When in doubt, report. The early warning is intentionally lightweight, and submitting an early warning for an incident that ultimately proves less severe carries minimal regulatory risk. Failing to report a significant incident, however, can result in substantial penalties. Your internal classification criteria should include a presumption of significance for incidents affecting critical services.
Some member states are working toward single reporting portals that accept combined notifications. However, NIS 2 and GDPR reports go to different authorities (CSIRT/competent authority versus Data Protection Authority) and have different requirements. For now, organizations should prepare separate reports but use a single internal incident record to ensure consistency across submissions.
If a significant incident has cross-border impact, you must indicate this in the early warning. The national CSIRT will coordinate with CSIRTs in affected member states through the CSIRTs Network. You are required to report to the authorities in the member state where your main establishment is located (or where your representative is designated for non-EU entities).
Yes. If the incident is still being handled at the one-month mark, you must submit a progress report at that time and then submit a final report within one month after the incident handling is complete. This prevents organizations from being forced to submit incomplete final reports for complex, long-running incidents.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for NIS 2 Directive compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free