The clock starts the moment you know. NIS2 gives you 24 hours.
NIS2 Article 23 sets three deadlines from the moment an entity becomes aware of a significant incident: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month.
The deadlines are the easy part — anyone can memorize three numbers. The hard part is what the notification itself asks for: what systems were affected, whether other entities or other countries are involved, and how the incident assesses against the significance criteria. At hour twenty of a seventy-two-hour clock, those answers have to come from a record, not from a reconstruction meeting.
Who these duties bind
Essential and important entities alike — the reporting cascade does not distinguish between them. The clock starts at awareness, which makes early detection part of the compliance obligation in practice. And each member state names its own competent authority and CSIRT to receive the reports — which is why the twenty-seven country pages here track the national side of this duty individually.
The clock
| Deadline | What is due |
|---|---|
| T+0 | The entity becomes aware of a significant incident — the clock starts here, not at diagnosis |
| 24 hours | Early warning to the national competent authority or CSIRT |
| 72 hours | Full notification, with the initial assessment of the incident |
| 1 month | Final report closing the incident |
What it asks, in operating terms
| What Article 23 asks | Where it is answered |
|---|---|
| Know an incident happened, and when you knew | Incident & resilience workflows · clocked from logging, named owner |
| Assess significance with evidence, not recollection | Evidence automation · affected systems and timeline from connected tools |
| File each stage inside its window | Incident & resilience workflows · stage templates, deadline tracked per stage |
| File to the right national authority | Country tracking · authority and requirements per member state |
| Answer for the incident afterwards | Board reporting · incident record rolls into the accountable view |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an incident file is made of:
- Early warning
- filed T+3h 41m · authority named
- Notification
- filed T+31h · initial assessment attached
- Significance assessment
- evidence-linked · cross-border checked
- Final report
- in preparation · due day 30
- Evidence
- sealed · sha256:b7f2…91ae
Where teams usually start
With a demo walked through by TruSecure — an incident drill against the 24-hour clock, from logging to filed early warning, in your country's authority workflow. Onboarding then rehearses the cascade on your real estate; the subscription keeps it current as transpositions and forms change.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
NIS2 Article 23 requires in-scope entities to report significant incidents in three stages: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month. TruSecure starts the reporting clock automatically and pre-builds each stage's evidence pack.