NIS2 Article 23 imposes a three-tiered incident reporting regime that turns every cyber event into a ticking clock. Miss the 24-hour early warning and you risk a fine of up to €10 million or 2 % of global turnover; fail to classify severity correctly and you may notify the wrong authority, triggering a second enforcement action. This article provides an operational decision tree, severity matrix, and CSIRT routing table so CISOs in essential and important entities can meet the deadlines without
NIS2 Article 23 imposes a three-tiered incident reporting regime that turns every cyber event into a ticking clock. Miss the 24-hour early warning and you risk a fine of up to €10 million or 2 % of global turnover; fail to classify severity correctly and you may notify the wrong authority, triggering a second enforcement action. This article provides an operational decision tree, severity matrix, and CSIRT routing table so CISOs in essential and important entities can meet the deadlines without over-reporting or under-reporting.
---
1. NIS2 Article 23 three-step reporting framework explained
NIS2 Article 23(3)–(5) establishes three distinct deadlines, each with its own trigger, recipient, and content requirements.
1.1 24-hour early warning (Article 23(3))
- Trigger: any incident that has a “substantial impact” on service continuity.
- Recipient: the single point of contact (SPOC) designated by the Member State where the entity is established.
- Content: a preliminary assessment of the incident’s nature, severity, and potential cross-border impact.
- Purpose: enable CSIRTs to pre-position resources and issue early warnings to other Member States.
1.2 72-hour incident notification (Article 23(4))
- Trigger: the same incident, once it is classified as either “significant” or “major” under the severity matrix in Article 23(2).
- Recipient: the competent CSIRT or, in some Member States, the sectoral regulator.
- Content: a structured form that includes root-cause analysis, affected systems, and initial containment measures.
- Purpose: allow the CSIRT to coordinate national response and, if necessary, activate the EU Cyber Crises Liaison Organisation Network (CyCLONe).
1.3 1-month final report (Article 23(5))
- Trigger: 30 calendar days after the 72-hour notification.
- Recipient: the same CSIRT or regulator.
- Content: a full forensic report, lessons learned, and evidence of remediation.
- Purpose: close the incident record and provide input for the annual NIS2 report to the European Commission.
---
2. Decision tree – when does the 24h clock start
flowchart TD
A[Incident detected] --> B{Is service continuity\nsubstantially affected?}
B -->|Yes| C[24h clock starts\nimmediately]
B -->|No| D[Log internally\nNo 24h report]
C --> E{Can root cause\nbe contained\nwithin 24h?}
E -->|Yes| F[File 24h early warning\nthen monitor]
E -->|No| G[File 24h early warning\nand proceed to 72h classification]
G --> H{Severity matrix\nsignificant or major?}
H -->|Significant| I[File 72h incident notification]
H -->|Major| J[File 72h incident notification\nand escalate to CyCLONe if cross-border]
I & J --> K[30-day clock starts\non 72h filing date]
K --> L[File 1-month final report]Key rule: the 24-hour period begins the moment the entity becomes aware that service continuity is “substantially affected”, not when the root cause is identified. NIS2 Recital 92 clarifies that “awareness” can be triggered by automated alerts, user complaints, or third-party notifications.
---
3. Severity classification matrix: significant vs major incident
NIS2 Article 23(2) defines two severity thresholds. The matrix below operationalises the criteria for an EU mid-cap energy distributor (essential entity) and an EU large logistics provider (important entity).
| Criterion | Significant incident (72h report) | Major incident (72h report + CyCLONe) |
|---|---|---|
| Duration | ≥ 4 h service outage | ≥ 12 h service outage |
| Users affected | ≥ 10 000 users or 5 % of user base | ≥ 100 000 users or 20 % of user base |
| Financial loss | ≥ €250 000 | ≥ €2.5 M |
| Physical damage | Minor (e.g., single substation) | Major (e.g., regional blackout) |
| Cross-border impact | Single Member State | ≥ 2 Member States |
| Data breach | ≤ 10 000 records | > 10 000 records or sensitive data |
| Supply-chain disruption | Single tier-2 supplier | Tier-1 supplier or multiple tier-2 |
Interpretation rule: if any single criterion meets the “major” threshold, the incident is major. If two or more criteria meet the “significant” threshold, the incident is also major.
---
4. CSIRT routing per Member State
NIS2 Article 5(2) allows Member States to designate either a single CSIRT or multiple sectoral authorities. The table below lists the current routing for France, Germany, Spain, and Italy (as of 1 July 2024).
| Member State | Essential entities (24h/72h) | Important entities (24h/72h) | Final report recipient | Notes |
|---|---|---|---|---|
| France | ANSSI (via portal) | ANSSI (via portal) | ANSSI | Single CSIRT model; sectoral regulators (ACPR, ARCEP) receive copies for financial and telecoms. |
| Germany | BSI (via Meldeportal) | BSI (via Meldeportal) | BSI | Single CSIRT model; Länder authorities notified for regional incidents. |
| Spain | INCIBE-CERT | INCIBE-CERT | INCIBE-CERT | Single CSIRT model; sectoral regulators (CNMC, Banco de España) receive copies. |
| Italy | CSIRT-Italia | Sectoral CSIRTs (e.g., CERTFin for finance) | Same as 72h recipient | Multi-CSIRT model; coordination via CSIRT-Italia. |
Action for CISOs: verify the latest routing table on the ENISA national CSIRT contact list (ENISA, “National CSIRTs Network”, updated quarterly).
---
5. Common pitfalls: late notification penalties and remediation
5.1 Late notification
- 24h early warning: failure to file within 24 hours triggers an automatic fine under NIS2 Article 34(4)(a) (up to €10 million or 2 % of global turnover).
- 72h incident notification: late filing is treated as non-filing; same fine cap applies.
- 1-month final report: late filing incurs a separate fine under Article 34(4)(b) (up to €7 million or 1.4 % of global turnover).
Real-world example: an EU mid-cap manufacturer missed the 24-hour deadline because the SOC manager was on leave. The supervisory authority imposed a €250 000 fine and ordered a third-party audit.
5.2 Over-reporting
- Filing a 24-hour early warning for every minor incident clogs CSIRT queues and may trigger enforcement for “frivolous reporting”.
- Mitigation: implement an internal triage playbook that mirrors the severity matrix; only escalate to the CISO if the “substantial impact” threshold is met.
5.3 Under-reporting
- Misclassifying a major incident as significant (or vice versa) leads to incorrect routing and delayed response.
- Mitigation: run a weekly “red-team” exercise where the CISO and DPO jointly classify past incidents using the matrix.
5.4 Remediation gaps
- NIS2 Article 21(2)(d) requires entities to “take appropriate and proportionate technical and organisational measures” to prevent recurrence.
- Evidence required: root-cause analysis (RCA) report, patch logs, and updated risk assessment.
- Enforcement risk: if the 1-month final report shows no remediation, the supervisory authority may impose an additional fine under Article 34(4)(c) (up to €5 million or 1 % of global turnover).
---
6. Evidence pack required for the 1-month final report
NIS2 Article 23(5) and the Implementing Regulation (EU) 2024/1328 specify the minimum evidence pack. The table below lists the required artefacts and retention periods.
| Artefact | Format | Retention period | Notes |
|---|---|---|---|
| Incident timeline | CSV or SIEM export | 5 years | Must include timestamps in UTC. |
| Root-cause analysis (RCA) | PDF report | 5 years | Signed by CISO or equivalent. |
| Forensic images | E01 or AFF | 5 years | Hashes must be notarised. |
| Logs (network, endpoint, cloud) | Raw logs + SIEM alerts | 5 years | Must cover 72 h before and after incident. |
| Patch management records | PDF or ticketing system | 5 years | Must show patch level at time of incident. |
| Communication records | Email, Slack, Teams | 5 years | Internal and external (vendors, CSIRT). |
| Lessons