Does every cyber incident need a NIS2 report?
No. Article 23 covers incidents that have a significant impact on the provision of an essential or important entity's services. The EU test looks for actual or possible severe operational disruption or financial loss for the entity, or considerable material or non-material damage to another person. Regulation 2024/2690 adds exhaustive horizontal and provider-specific criteria for the provider types in its Article 1; other entities must use the directive, national law, and applicable authority guidance.