NIS2

NIS2 · the incident clock

The incident clock: 24 hours, 72 hours, 1 month

The moment you became aware, the member state and whether the incident is significant under Article 23(3); the three deadlines are computed from Article 23(4), the CSIRT is named from the register, and the early warning, the notification and the final report are written with the contents the Directive lists.

Is the entity a trust service provider?

Article 23(4), second subparagraph: a trust service provider gives the incident notification within 24 hours of awareness, the same clock as the early warning.

Is the incident significant?

An incident shall be considered to be significant if: (a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; (b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

Has it caused, or could it cause, severe operational disruption of the services or financial loss for the entity?

Has it affected, or could it affect, other natural or legal persons by causing considerable material or non-material damage?

Which kind of provider is the entity?

Commission Implementing Regulation (EU) 2024/2690 sets the thresholds that make an incident significant for the digital providers it names, read on 13 September 2026; a cloud computing service provider meets its Article 7, a managed or managed security service provider its Article 10, and every relevant entity its Article 3(1). Any other entity reads Article 23(3) of the Directive alone.

Article 3(1): the general criteria, any one of them

An incident shall be considered to be significant for the purposes of Article 23(3) of Directive (EU) 2022/2555 with regard to the relevant entities where one or more of the following criteria are fulfilled:

Article 7: for a cloud computing service, any one of them

With regard to cloud computing service providers, an incident shall be considered significant under Article 3(1)(g) where it fulfils one or more of the following criteria:

Scheduled interruptions of service and planned consequences of scheduled maintenance operations carried out by or on behalf of the relevant entities shall not be considered to be significant incidents.

1. The clock

Enter the moment of awareness above; the deadlines and the reports follow.

2. The early warning, within 24 hours

without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;

3. The incident notification, within 72 hours

without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;

upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates;

4. The final report, within 1 month of the notification

a final report not later than one month after the submission of the incident notification under point (b), including the following:

in the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident.

The document

# NIS2 incident reports

Written on 14 September 2026 at 11:06 with the free page at getstandardos.com; the clock is Article 23(4) of Directive (EU) 2022/2555 and the contents are its points (a), (b) and (d) as the Official Journal words them.

## 1. The clock

Enter the moment of awareness above; the deadlines and the reports follow.

## 2. The early warning, within 24 hours

> without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;

### Is the incident suspected of being caused by unlawful or malicious acts?

Not stated.

### Could the incident have a cross-border impact?

Not stated.

## 3. The incident notification, within 72 hours

> without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;

### Update to the early warning

Not stated.

### Initial assessment of the incident, including its severity and impact

Not stated.

### Indicators of compromise, where available

Not stated.

## 4. The final report, within 1 month of the notification

> a final report not later than one month after the submission of the incident notification under point (b), including the following:

### (i) a detailed description of the incident, including its severity and impact

Not stated.

### (ii) the type of threat or root cause that is likely to have triggered the incident

Not stated.

### (iii) applied and ongoing mitigation measures

Not stated.

### (iv) where applicable, the cross-border impact of the incident

Not stated.

> in the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident.

The hours, the month and the contents are read from the Directive, never typed here; the moment of awareness and the significance are the company's own findings. The transposing law of the member state may add fields and a portal. This is a document, not legal advice.

A software company under the CRA or the GDPR runs a second clock from the same moment of awareness, with a different recipient and threshold: which incident clock runs for a software company

Three reports from one incident record

StandardOS opens the 24-hour clock the moment an incident is recorded, drafts the early warning, the notification and the final report from the same record, and runs the CRA and GDPR clocks beside them where they apply.

The hours, the month, the significance conditions and the contents of the reports are read from Article 23 of the Directive, never typed on this page; the CSIRT is the CSIRTs Network's register. Whether an incident is significant is the company's own reading. This is a document, not legal advice.