NIS2 Incident Reporting: A 24/72/1-Month CAB Runbook
This article is operational compliance guidance for change and incident teams, not legal advice. Confirm obligations against your national transposition law and competent authority. No affiliate links appear below.
Why this matters now
For years, incident reporting in most European organizations was a loosely defined step somewhere after containment. NIS2 removed that slack. Its Article 23 imposes what one legal guide calls the most prescriptive incident-reporting regime ever placed on network and information system operators in the EU (Glocert Article 23 playbook), and the clock is short enough that a team improvising the workflow during an incident will miss it.
The pressure is rising, not theoretical. On July 8, 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to fully transpose the NIS2 Directive into national law, and asked the court to impose lump-sum and daily financial sanctions (Hunton Andrews Kurth analysis). By late July 2026, 22 of 27 member states had a transposition law in force, with the remaining few still legislating (ISMS Copilot transposition tracker). The obligations are landing country by country, and once they land, the 24-hour clock is live.
For a change advisory board, this is a change-management problem before it is a legal one. The reporting timeline is a process you build, rehearse, and assign owners to in advance, exactly like an emergency-change path. Miss the design work and the deadline arrives mid-crisis with no one holding the pen.
What actually triggers the clock
The obligation is not universal to every outage. It attaches only to a “significant incident.” Article 23(3) defines one as an incident that “has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned,” or that “has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage” (NIS2 Article 23 full text).
Two features of that definition matter for a change team. First, it includes incidents “capable of causing” harm, so a near miss with credible potential impact can qualify before any damage lands. Second, the assessment is the entity’s own initial judgment, made under time pressure. The Commission’s Implementing Regulation (EU) 2024/2690 sets sector-specific significance thresholds for many digital-infrastructure and ICT-service entities to reduce that ambiguity, but the first call still falls to whoever is triaging at hour zero.
The single most misread detail is when the clock starts. It runs from the moment the entity becomes aware of the significant incident, not from when the incident began. An intrusion that dwelled for six weeks does not consume your 24 hours retroactively. But the corollary is strict: your detection-to-awareness handoff has to be fast and documented, because the timestamp on your awareness is what a supervisor will audit against.

The three mandatory stages, and what each must contain
Article 23(4) lays out a staged sequence deliberately designed to balance speed against depth (NIS2 Preamble recital 101). Each stage has a different job.
Stage one, the early warning, within 24 hours. This is a brief alert, not a report. Its required content is narrow: whether the significant incident is suspected to be caused by an unlawful or malicious act, and whether it could have a cross-border impact (Ireland NCSC NIS2 guide). You are not expected to know root cause at hour 24. You are expected to have raised your hand.
Stage two, the incident notification, within 72 hours. This updates the early warning with an initial assessment of the significant incident, including its severity and impact and, where available, indicators of compromise (Finnish Cyber Security Centre notification guide). This is the stage most teams underestimate, because producing a defensible severity-and-impact assessment in three days requires a data pipeline you either built before the incident or scramble to assemble during it.
Stage three, the final report, within one month. Filed within a month of the 72-hour notification, it must contain a detailed description of the incident including its severity and impact, the type of threat or root cause that likely triggered it, the mitigation measures applied and ongoing, and any cross-border impact (Ireland NCSC NIS2 guide). If the incident is still ongoing at the one-month mark, you file a progress report instead, and the final report becomes due one month after the incident is handled. A CSIRT may also request an intermediate status report at any point in between.
A change-safety reading of the reporting duty
Two provisions in Article 23 are easy to skip but change how a CAB should treat reporting.
The first is protective. The directive states plainly that “the mere act of notification shall not subject the notifying entity to increased liability” (NIS2 Article 23(1)). That line exists to stop teams from sitting on a report out of fear it becomes an admission. For a change board weighing whether a borderline event clears the significance bar, the safer posture is to notify, because the notification itself is shielded and the penalty exposure sits on the failure to report.
The second is the stakes. Article 34 sets maximum administrative fines of at least €10 million or 2% of global annual turnover, whichever is higher, for essential entities, and at least €7 million or 1.4% for important entities (NIS2 Directive fines overview). Article 20 layers on management-body accountability, so the reporting workflow is not something a CAB can treat as purely a technical runbook. Enforcement is already moving: by mid-2026 supervisors had issued dozens of formal orders across Germany and France even before the first company fines landed (RegDossier EU enforcement tracker).
This is the same discipline behind the risk-based deadline model we covered in our breakdown of CISA BOD 26-04 for CABs: the obligation attaches to a clock you must design against, not to a task you improvise. It also overlaps operationally with financial-sector rules, so teams in scope for both should reconcile it with our DORA operational-resilience checklist for change managers rather than run two parallel reporting motions.
What to do about it
Build the reporting runbook before you need it, and treat each item as a pre-approved change to your incident process.
- Pre-assign the report owners now. Name who drafts the 24-hour early warning, who owns the 72-hour assessment, and who compiles the one-month final report, with named backups. A deadline this short cannot survive a “who’s doing this?” conversation at hour 20.
- Wire detection to an awareness timestamp. Define, in writing, the event that constitutes “becoming aware,” and log that timestamp automatically. Every downstream deadline is measured from it, so it must be defensible.
- Pre-build the significance decision. Turn the Article 23(3) definition and any sector thresholds in Implementing Regulation 2024/2690 into a short triage checklist your on-call lead can run in minutes. Score the borderline calls with our change risk score tool so significance is consistent across shifts.
- Template all three reports. Draft fill-in-the-blank templates for the early warning, the notification, and the final report, each pre-loaded with the exact fields your national CSIRT portal requires. Structure the internal review with our CAB agenda generator.
- Confirm your competent authority and portal per country. Reporting goes to the CSIRT or competent authority where you provide services, and cross-border incidents require parallel notification to each affected member state. Record the portal URL and contact for every country you operate in.
- Rehearse the 72-hour assessment specifically. Run a tabletop that forces the team to produce a severity-and-impact assessment with indicators of compromise inside the window. That stage fails most often, and only practice exposes the missing data.
For the vulnerability-side companion to this workflow, keep watch on active-exploitation drivers with our live CISA KEV tracker, and see the full set of governance analyses on our compliance pillar.
Frequently asked questions
What are the NIS2 Article 23 reporting deadlines? Three mandatory stages from awareness: an early warning within 24 hours, a notification within 72 hours, and a final report within one month, with an on-request intermediate report and a progress-report fallback for ongoing incidents.
When does the NIS2 reporting clock start? From when the entity becomes aware of the significant incident, not from incident onset. The awareness timestamp must be defensible because every deadline runs from it.
What counts as a significant incident? One capable of causing severe operational disruption or financial loss, or considerable damage to others, per Article 23(3). Near misses with credible potential impact qualify, and Implementing Regulation 2024/2690 adds sector thresholds.
Who do you report to? The national CSIRT or competent authority where you provide services, with parallel notification to each affected member state for cross-border incidents.
What are the penalties? Up to at least €10M or 2% of global turnover for essential entities and €7M or 1.4% for important entities, plus management-body accountability under Article 20.
Does reporting increase liability? No. Article 23(1) shields the mere act of notification; the exposure is on failing to report.
Sources
- NIS2 Directive (EU) 2022/2555, Article 23 full text
- NIS2 Directive, Preamble recitals 101-110 (staged reporting rationale)
- ENISA, mapping NIS2 obligations with ECSF role profiles
- Ireland National Cyber Security Centre, NIS2 quick reference guide
- Finnish Cyber Security Centre, NIS2 incident notification instructions
- Commission Implementing Regulation (EU) 2024/2690 (significance thresholds)
- Hunton Andrews Kurth, Commission refers four member states to CJEU over NIS2
- ISMS Copilot, NIS2 transposition tracker for all 27 member states
- NIS2 Directive fines and penalties overview
Published August 6, 2026.