What does the NIS2 72-hour incident notification require?
Submit the without undue delay and in any event within 72 hours of becoming aware of a . It must update the early warning where applicable and indicate the entity's initial assessment, including severity and impact and, where available, indicators of compromise.
Do not wait for perfect root-cause certainty if the Article 23 significance threshold is met. Record what is known, what is estimated, what is unavailable, and which facts will be updated through intermediate reports or the final report.
- Confirm that the incident is significant because it has caused, or is capable of causing, severe operational disruption, financial loss, or considerable material or non-material damage to others.
- For DNS, TLD, cloud, data-centre, CDN, MSP, MSSP, marketplace, search, social-platform, and trust-service entities covered by Implementing Regulation (EU) 2024/2690, apply its horizontal and provider-specific significance criteria as well as Article 23 and national law.
- Start the 72-hour clock from awareness of the , not from the early-warning submission. Preserve detection, initial assessment, awareness, early-warning, and incident-notification times separately.
- Send the notification to the or, where applicable, competent authority for the relevant Member State route.
- Update the early warning and state the initial severity and impact assessment and available indicators of compromise. Label estimates and facts still under investigation.
- Apply the 24-hour incident-notification deadline instead if the reporting entity is a trust service provider and the affects its trust services.
- Keep the submission receipt, report version, approver, and known uncertainty in the incident file.
How should teams handle the NIS2 72-hour ?
Treat it as the Article 23 for a . Without undue delay and within 72 hours of awareness, submit an update to the or competent authority that gives an initial severity and impact assessment and available indicators of compromise. Record the awareness time, route, facts known at submission, uncertainty, and follow-up. A trust service provider must use a 24-hour incident-notification deadline for a significant incident affecting its trust services.
Primary legal source for the 72-hour incident notification, the trust-service-provider 24-hour derogation, the significant-incident threshold, required content, and staged reporting sequence described in recital 102.
Binding source for horizontal and provider-specific significant-incident criteria and the awareness explanation for the covered digital and trust-service entities.