Skip to main content
NIS2 INCIDENT REPORTING

The clock starts the moment you know. NIS2 gives you 24 hours.

NIS2 Article 23 sets three deadlines from the moment an entity becomes aware of a significant incident: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month.

The deadlines are the easy part — anyone can memorize three numbers. The hard part is what the notification itself asks for: what systems were affected, whether other entities or other countries are involved, and how the incident assesses against the significance criteria. At hour twenty of a seventy-two-hour clock, those answers have to come from a record, not from a reconstruction meeting.

Who these duties bind

Essential and important entities alike — the reporting cascade does not distinguish between them. The clock starts at awareness, which makes early detection part of the compliance obligation in practice. And each member state names its own competent authority and CSIRT to receive the reports — which is why the twenty-seven country pages here track the national side of this duty individually.

The clock

NIS2 Article 23 · reporting cascade from awareness
DeadlineWhat is due
T+0The entity becomes aware of a significant incident — the clock starts here, not at diagnosis
24 hoursEarly warning to the national competent authority or CSIRT
72 hoursFull notification, with the initial assessment of the incident
1 monthFinal report closing the incident

What it asks, in operating terms

NIS2 incident reporting · how TruSecure answers it
What Article 23 asksWhere it is answered
Know an incident happened, and when you knewIncident & resilience workflows · clocked from logging, named owner
Assess significance with evidence, not recollectionEvidence automation · affected systems and timeline from connected tools
File each stage inside its windowIncident & resilience workflows · stage templates, deadline tracked per stage
File to the right national authorityCountry tracking · authority and requirements per member state
Answer for the incident afterwardsBoard reporting · incident record rolls into the accountable view

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an incident file is made of:

NIS2 incident file · excerptSample data
Early warning
filed T+3h 41m · authority named
Notification
filed T+31h · initial assessment attached
Significance assessment
evidence-linked · cross-border checked
Final report
in preparation · due day 30
Evidence
sealed · sha256:b7f2…91ae

Where teams usually start

With a demo walked through by TruSecure — an incident drill against the 24-hour clock, from logging to filed early warning, in your country's authority workflow. Onboarding then rehearses the cascade on your real estate; the subscription keeps it current as transpositions and forms change.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

NIS2 Article 23 requires in-scope entities to report significant incidents in three stages: an early warning within 24 hours, a full notification within 72 hours, and a final report within one month. TruSecure starts the reporting clock automatically and pre-builds each stage's evidence pack.