Glossary · Term

Incident notification explained

The incident notification is the second NIS2 reporting stage after the early warning – with a first assessment of the incident within 72 hours.

At a glance
Meaning
Second of the three reporting stages
Deadline
Within 72 hours
Content
First assessment of severity and impact
Stage
The middle one of three
Updated
June 2026
Editorial team
Compliance Compass

What is the incident notification?

The Incident notification follows the early warning and is the second stage of the NIS2 reporting obligations. Within 72 hours it gives the authority a first solid assessment of severity, impact and possible causes. Where the early warning only signals that something significant has happened, the incident notification answers for the first time the question of what exactly happened and how serious it is.

What it contains

Part of the reporting chain

It is the middle of the three stages of the Reporting obligations: early warning (24 h) → incident notification (72 h) → Final report (one month). The whole chain is triggered only by a significant incident; filing runs through the national channel of the Member State in which you are established.

In practice

A payment service provider filed the early warning about a DDoS attack on the Monday. By Thursday, and so inside the 72-hour deadline, the team follows up with the incident notification: the attack took the payment API down for around six hours, affected an estimated several thousand transactions, is traced to a botnet, and a scrubbing service was activated as an immediate measure. Details like these put the authority in a position to warn other market participants.

Why the 72-hour deadline exists

It gives the authority solid information so that it can react itself and warn other entities where appropriate. Without prepared processes the deadline is hard to meet – an incident response plan with clear roles and templates helps you avoid failures, and with them the fines for which Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover.

Further reading: Directive (EU) 2022/2555, incident notification under Article 23(4)

Frequently asked questions

What is an incident notification?

The incident notification is the second of the three NIS2 reporting stages and follows the early warning. Within 72 hours of becoming aware of a significant incident it gives the CSIRT or competent authority a first solid assessment of the severity, the impact and – as far as it is known – the cause of the incident. Filing runs through the national channel your Member State provides. The directive has applied since 18 October 2024.

What is the deadline for the incident notification?

The incident notification has to be filed within 72 hours of becoming aware of the significant incident, through the national channel your Member State provides. That is 48 hours after the 24-hour deadline for the early warning runs out. The third stage, the final report, follows one month later at the latest. Missed notifications can trigger fines, for which Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities.

What does the incident notification have to contain?

The incident notification contains a first assessment of the severity and of the impact on services and users, the cause and type of attack as far as they are known, and the immediate containment measures already taken. Indications of possible cross-border impact belong in it too. That makes it considerably more detailed than the preceding early warning, which within 24 hours only signals the suspicion.

Reporting obligations

72 hours – solid reporting

Compliance Compass supplies the templates and the workflow so that your incident notification is on time and complete.