What does the NIS2 24-hour early warning require?
Under NIS2 Article 23, essential and important entities notify their or competent authority of significant incidents. The first required step is an submitted without undue delay and, in any event, within 24 hours of becoming aware of the .
The is not the full incident report. It must indicate, where applicable, whether unlawful or malicious acts are suspected or whether the incident could have a cross-border impact. The 72-hour incident notification supplies the initial severity and impact assessment and available indicators of compromise.
- Start with the Article 23 significance test: severe operational disruption, financial loss, or considerable material or non-material damage to others.
- For entities covered by Implementing Regulation (EU) 2024/2690, also test its horizontal and provider-specific criteria. Examples include direct financial loss exceeding the lower of EUR 500,000 or 5 percent of prior-year turnover, malicious unauthorised access capable of severe disruption, and sector thresholds for outage duration, affected users, or compromised data.
- Record detection, escalation, initial assessment, awareness, approval, and submission times separately. A supplier alert or security event may start triage without yet establishing awareness of a .
- Send the through the national route designated for the entity, usually the or competent authority.
- Keep the 72-hour incident notification, requested intermediate reports, and final report linked to the same incident record.
How should teams handle 24-hour under the EU NIS2 Directive?
Submit the without undue delay and within 24 hours after the entity becomes aware of a . Record why Article 23(3) is met, the awareness time, suspected unlawful or malicious activity and possible cross-border impact where applicable, and the national or competent-authority route. Do not delay the warning for a complete root-cause analysis.
Article 23 sets the significant-incident notification duty and the 24-hour early-warning deadline.
Commission overview of NIS2 scope, sectors, and policy context for covered entities.
Further specifies significant-incident cases and awareness timing for listed digital and trust-service providers.