The NIS2 incident reporting timeline, explained.
NIS2 reporting is not one deadline or one form. It is a sequence designed to give authorities useful information as the incident becomes clearer.
Confirm whether malicious activity is suspected and whether the incident could have cross-border impact.
Provide an initial severity and impact assessment, indicators of compromise and available evidence.
Document root cause, mitigation measures, cross-border effects and the complete resolution status.
Start the clock with a reliable case record
The reporting process begins before a legal determination is final. Capture when the event was first detected, which systems and services may be affected, the evidence source and who owns the decision.
Classify impact — and preserve the reasoning
Classification should connect technical facts to operational impact. Record the affected service, users, geographic reach, duration and potential consequences. If AI supports classification, its recommendation should be explainable and reviewable by a human decision-maker.
ComplyIT keeps the signal, classification, approval and regulatory submission in one auditable timeline.
Treat the 72-hour report as an informed update
The incident notification is not expected to contain every final answer. It should clearly distinguish confirmed facts, current assessments and unknowns.
Prepare before the incident
- Define who can classify an event as significant.
- Maintain a current national authority directory.
- Map security sources into one evidence workflow.
- Test approvals outside business hours.
- Keep templates aligned with national implementation.
Turn the next deadline into a controlled workflow.
See how ComplyIT guides classification, approvals and reporting.
Start for free ↗