What does the NIS2 24-hour early warning require?
Under NIS2 Article 23, essential and important entities notify their CSIRT or competent authority of significant incidents. The first required step is an early warning submitted without undue delay and, in any event, within 24 hours of becoming aware of the significant incident.
The early warning is not the full incident report. It should flag that a significant incident exists and, where applicable, say whether the incident is suspected to involve unlawful or malicious acts or could have a cross-border impact.
- Start with the Article 23 significance test: severe operational disruption, financial loss, or considerable material or non-material damage to others.
- Record the point at which the entity became aware that the incident was significant.
- Send the early warning through the national route designated for the entity, usually the CSIRT or competent authority.
- Keep the 72-hour incident notification, requested intermediate reports, and final report linked to the same incident record.
Article 23 sets the significant-incident notification duty and the 24-hour early-warning deadline.
Commission overview of NIS2 scope, sectors, and policy context for covered entities.
Further specifies significant-incident cases and awareness timing for listed digital and trust-service providers.