Glossary · Term

Final report explained

The final report is the last reporting stage after a significant incident and documents the cause, the impact and the measures taken.

At a glance
Meaning
Closing report after an incident
Deadline
Within one month
Content
Cause, impact, measures taken
Stage
Third and last reporting stage
Updated
June 2026
Editorial team
Compliance Compass

What is the final report?

The Final report is the third and last stage of the reporting chain set out under Reporting obligations. While the early warning and the incident notification deliver a first picture under heavy time pressure, the final report sums up, once the incident has been worked through, what actually happened, what impact it had and how it was answered. That makes it the binding closing documentation filed with the competent authority.

What belongs in it

Where it sits in the reporting chain

It follows the early warning (24 h) and the incident notification (72 h), and has to be filed within one month of the incident notification through the national channel your Member State provides. Where a significant incident is still ongoing beyond that month, a progress report on the state of handling falls due first; the final report follows as soon as the incident has been fully handled.

In practice

After a ransomware attack, a hospital operator needed three weeks for forensic analysis and recovery. In the final report it discloses that initial access came through an unpatched VPN vulnerability, that emergency care was restricted for 14 hours, and that multi-factor authentication and tightened patch management will be introduced. In doing so it not only meets the deadline but gives the authority findings that other entities can use.

More than ticking a box

A good final report is valuable internally as well: the lessons you document feed into improving your controls and incident response , and they strengthen your ability to produce evidence for supervisors and for the management body – all the more so given the fines, for which Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover.

Further reading: Directive (EU) 2022/2555, final report under Article 23(4)

Frequently asked questions

What is the final report under NIS2?

The final report is the third and last stage of the three-stage NIS2 reporting chain for significant incidents. Once an incident has been fully worked through, it documents its root cause, the type and extent of the impact, and the countermeasures taken and planned. That makes the final report the binding closing documentation filed with the competent authority, and it gives that authority usable findings about the incident which can benefit other entities too.

What is the deadline for the final report?

The final report has to be filed one month after the incident notification at the latest, through the national channel your Member State provides. It forms the last stage of the NIS2 reporting chain, which begins with the early warning within 24 hours, continues with the incident notification within 72 hours and ends after one month with the final report. The directive has applied since 18 October 2024, and these deadlines are binding from the point your Member State has transposed it.

What if the incident lasts longer than a month?

Where a significant incident is still ongoing beyond the month after the incident notification, a progress report on the current state of handling is filed instead of the final report. The final report itself then follows only once the incident has been fully and conclusively handled. That keeps the competent authority informed throughout, without the fixed one-month deadline forcing a premature closing report.

Reporting obligations

A clean, well-documented close

Compliance Compass supports incident documentation and notifications – right through to an audit-proof final report.