NIS2 · the incident clock
The incident clock: 24 hours, 72 hours, 1 month
The moment you became aware, the member state and whether the incident is significant under Article 23(3); the three deadlines are computed from Article 23(4), the CSIRT is named from the register, and the early warning, the notification and the final report are written with the contents the Directive lists.
1. The clock
Enter the moment of awareness above; the deadlines and the reports follow.
2. The early warning, within 24 hours
without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;
3. The incident notification, within 72 hours
without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;
upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates;
4. The final report, within 1 month of the notification
a final report not later than one month after the submission of the incident notification under point (b), including the following:
in the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident.
The document
# NIS2 incident reports Written on 14 September 2026 at 11:06 with the free page at getstandardos.com; the clock is Article 23(4) of Directive (EU) 2022/2555 and the contents are its points (a), (b) and (d) as the Official Journal words them. ## 1. The clock Enter the moment of awareness above; the deadlines and the reports follow. ## 2. The early warning, within 24 hours > without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact; ### Is the incident suspected of being caused by unlawful or malicious acts? Not stated. ### Could the incident have a cross-border impact? Not stated. ## 3. The incident notification, within 72 hours > without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise; ### Update to the early warning Not stated. ### Initial assessment of the incident, including its severity and impact Not stated. ### Indicators of compromise, where available Not stated. ## 4. The final report, within 1 month of the notification > a final report not later than one month after the submission of the incident notification under point (b), including the following: ### (i) a detailed description of the incident, including its severity and impact Not stated. ### (ii) the type of threat or root cause that is likely to have triggered the incident Not stated. ### (iii) applied and ongoing mitigation measures Not stated. ### (iv) where applicable, the cross-border impact of the incident Not stated. > in the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident. The hours, the month and the contents are read from the Directive, never typed here; the moment of awareness and the significance are the company's own findings. The transposing law of the member state may add fields and a portal. This is a document, not legal advice.
A software company under the CRA or the GDPR runs a second clock from the same moment of awareness, with a different recipient and threshold: which incident clock runs for a software company
Three reports from one incident record
StandardOS opens the 24-hour clock the moment an incident is recorded, drafts the early warning, the notification and the final report from the same record, and runs the CRA and GDPR clocks beside them where they apply.
The hours, the month, the significance conditions and the contents of the reports are read from Article 23 of the Directive, never typed on this page; the CSIRT is the CSIRTs Network's register. Whether an incident is significant is the company's own reading. This is a document, not legal advice.