Glossary · Term

Reporting obligations explained

The reporting obligations require entities in scope to report significant incidents to the responsible bodies – under NIS2 in three stages.

At a glance
Meaning
Duty to report significant incidents
Stages
Early warning 24 h → notification 72 h → final report 1 month
Recipient
CSIRT or competent authority, via the national portal
Trigger
Significant incidents only
Updated
June 2026
Editorial team
Compliance Compass

What are the reporting obligations?

The Reporting obligations under Article 23 require entities in scope to report significant incidents to the responsible national body. The aim is that authorities can react early, that affected third parties are warned and that similar attacks across the wider economy can be prevented. Under NIS2, which has applied since 18 October 2024, reporting is deliberately built to be multi-stage so that the authority gets a first picture of the situation very quickly, sharpened as things develop, instead of a single complete report arriving only weeks later.

The three reporting stages in detail

The reporting chain at a glance

The clock starts the moment you become aware. Each stage builds on the one before – the table below shows what has to reach your national cybersecurity authority by when:

StageDeadline (from awareness)Content
1. Early warning24 hoursBrief report that a significant incident has occurred; note on a suspected unlawful or malicious cause or cross-border impact.
2. Incident notification72 hoursAssessment of severity and impact, indicators of compromise, immediate measures already taken.
3. Final report1 monthFull root-cause analysis, overall impact, lasting countermeasures; where the incident is still ongoing, a progress report comes first.

Checklist: does my incident have to be reported?

Several ticks? Then the 24-hour clock is running. When in doubt, report.

When is an incident “significant”?

Only significant incidents have to be reported – those with longer outages, a large data leak, noticeable financial damage or many affected users, for instance. Smaller disruptions do not trigger the reporting obligation, but should be documented internally so that, in case of doubt, it stays traceable why no report was made.

Who receives the notification?

Notifications go through the national channels described under Registration portals to the national cybersecurity authority in its role as competent authority. Access often runs through an existing national business identity. Because registration and its deadline are set by national law – and in several Member States that first date has already passed – account and access should be in place before the first incident occurs.

What you actually have to do

An incident on a Friday evening

Friday, 22:14. An energy supplier notices that ransomware has encrypted its control room software. While one team isolates the compromised systems that same night, the other drafts the early warning in parallel and files it through the national portal before the 24 hours are up; on Monday the 72-hour notification follows on time with a first damage assessment, and four weeks later the final report arrives with a full root-cause analysis and the lasting hardening measures. What made the difference was not luck. Roles, access and templates were ready before the attack began.

What happens if you breach the duty?

Breaching the reporting obligations risks substantial fines: Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts. On top of that – through the Governance-related duties – comes the personal responsibility of the management body. A prepared incident response plan helps you meet the deadlines reliably.

Further reading: Directive (EU) 2022/2555, reporting obligations under Article 23

Frequently asked questions

Which deadlines apply to NIS2 reporting?

NIS2 reporting runs in three stages, each counted from the moment you become aware of the incident: first an early warning within 24 hours, then a fuller incident notification with a first assessment within 72 hours, and finally a final report within one month. Where the incident is still ongoing, a progress report takes the place of the final report for the time being. Under Article 23 the notifications go to the CSIRT or, where the Member State so provides, to the competent authority.

Which incidents have to be reported?

Only significant incidents have to be reported under NIS2 – those with longer operational outages, a large data leak, noticeable financial damage or many affected users, for instance. Smaller disruptions trigger no report, but should be documented internally so that it stays traceable why no report was made. Missing a notification risks fines, for which Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities.

Where do you report an incident?

Reporting runs through national channels. NIS2 leaves it to each Member State to designate the CSIRT or competent authority that receives notifications and to operate the portal through which they are filed. Access often depends on an existing national business identity, so the account should be set up in advance. Registration is a matter of national law as well, with the body and the deadline set by your Member State. Have account and access in place before the first incident.

NIS2 reporting

24 hours to the Early warning

From the first suspicion to the final report: Compliance Compass starts the 24/72/one-month clock, fills your portal notifications from templates and logs every step in audit-proof form.