NIS2

NIS2 reporting duty: how a security incident unfolds over 24 h, 72 h and one month

When a significant security incident occurs under NIS2, the clock is ticking: the first notification must reach the BSI within 24 hours. Anyone who only then clarifies responsibilities loses valuable time. This guide shows the process and what to prepare in advance.

All guidesAndreas Behrens, FutureProfAIUpdated: 02 October 20265 min read

The three reporting stages at a glance

  • Within 24 hours: early warning to the BSI as soon as you become aware of a significant incident.
  • Within 72 hours: notification with an initial assessment of severity and impact.
  • Within one month: final report with cause, measures and impact.

If personal data is affected, a possible GDPR notification to the data protection authority (72 hours) must be checked in parallel – separately from the NIS2 notification.

What is a “significant” incident?

Reportable incidents are those that can cause severe operational disruption or financial loss, or considerably harm other persons. Classification should follow criteria defined in advance. Rule of practice: if in doubt, report – a withdrawn early warning is harmless, a missed one is not.

The process in an emergency

  • Detect & record: document the incident with the time of awareness – the deadlines start here.
  • Assess: decide against the criteria whether the incident is significant and therefore reportable.
  • Escalate: involve the crisis team and management; roles and deputies are defined in advance.
  • Report: submit the early warning via the BSI reporting portal; your company files the report itself.
  • Contain & recover: restore systems with your IT service provider and forensics, measure recovery against the planned times.
  • Follow up: write the final report, turn lessons learned into measures, file the evidence.

What to prepare beforehand

  • A documented reporting process with clear criteria for “significant”.
  • Roles, deputies and availability – including at night and at weekends.
  • Access to the BSI reporting portal and prepared text modules for the notifications.
  • A business impact analysis: which processes are critical and how long may they fail?
  • Practised crisis communication to customers, employees and, if necessary, the public.
  • At least one tabletop exercise per year in which the process is rehearsed with management.

Key point: the 24-hour deadline can only be met if process, roles and access are in place beforehand – and have been practised once.

Operational readiness incl. tabletop exercise

Scope: our NIS2 software monitors deadlines and escalates, but does not replace a SIEM/EDR, forensics or technical recovery and does not report to the BSI automatically. This text does not constitute legal advice.

Free risk triage

In 30 minutes we clarify where you stand and what makes sense next.

Book a call

Further reading

Frequently asked questions