The three reporting stages at a glance
- Within 24 hours: early warning to the BSI as soon as you become aware of a significant incident.
- Within 72 hours: notification with an initial assessment of severity and impact.
- Within one month: final report with cause, measures and impact.
If personal data is affected, a possible GDPR notification to the data protection authority (72 hours) must be checked in parallel – separately from the NIS2 notification.
What is a “significant” incident?
Reportable incidents are those that can cause severe operational disruption or financial loss, or considerably harm other persons. Classification should follow criteria defined in advance. Rule of practice: if in doubt, report – a withdrawn early warning is harmless, a missed one is not.
The process in an emergency
- Detect & record: document the incident with the time of awareness – the deadlines start here.
- Assess: decide against the criteria whether the incident is significant and therefore reportable.
- Escalate: involve the crisis team and management; roles and deputies are defined in advance.
- Report: submit the early warning via the BSI reporting portal; your company files the report itself.
- Contain & recover: restore systems with your IT service provider and forensics, measure recovery against the planned times.
- Follow up: write the final report, turn lessons learned into measures, file the evidence.
What to prepare beforehand
- A documented reporting process with clear criteria for “significant”.
- Roles, deputies and availability – including at night and at weekends.
- Access to the BSI reporting portal and prepared text modules for the notifications.
- A business impact analysis: which processes are critical and how long may they fail?
- Practised crisis communication to customers, employees and, if necessary, the public.
- At least one tabletop exercise per year in which the process is rehearsed with management.
Key point: the 24-hour deadline can only be met if process, roles and access are in place beforehand – and have been practised once.
Operational readiness incl. tabletop exerciseScope: our NIS2 software monitors deadlines and escalates, but does not replace a SIEM/EDR, forensics or technical recovery and does not report to the BSI automatically. This text does not constitute legal advice.
