Skip to content
NIS2 & Cbw · · 2 min read

The NIS2 reporting duty explained: what, when, and to whom you report

NIS2 requires organisations to report serious incidents quickly. How that reporting duty works, which deadlines apply, and how to prepare for it.

By Limburg Cyber Group

One of the most concrete obligations under NIS2 is the reporting duty: organisations that fall under the law must report serious incidents within tight deadlines to the supervisory authority. For many business owners that raises questions, what counts as “serious”, how fast must it be, and to whom? This article lays it out.

Why there is a reporting duty

The aim is twofold: the government gains insight into what is happening and can issue warnings, and organisations are forced to handle incidents seriously and in a structured way. Reporting is therefore not a punishment, but part of collective resilience.

The phased deadlines

NIS2 works with a staged report. Broadly:

  1. Within 24 hours an initial, early report (an “early warning”) as soon as you suspect a significant incident.
  2. Within 72 hours a more detailed report with an initial assessment of the nature and impact.
  3. Within one month at the latest a final report on what happened and which measures were taken.

These deadlines are short. That is what makes thinking ahead so important: if you only work out how to report during an incident, you are too late.

What counts as a reportable incident?

Broadly, it concerns incidents with a significant impact on your services, think of a major disruption, outage, or a data breach of significance. The exact thresholds are being detailed further in the Dutch implementation (the Cybersecurity Act). In doubt? Document the incident and coordinate; reporting too cautiously is better than too late.

Note: this sits alongside the GDPR reporting duty

Important misconception: the NIS2 reporting duty does not replace the data breach reporting duty from the GDPR. In an incident involving personal data you may face both, towards different authorities. So do not confuse those two reporting routes.

How to prepare

  • Set out an incident procedure: who decides, who reports, which data you collect.
  • Assign roles so that in an incident it is immediately clear who does what.
  • Practise it once with a fictional scenario, that exposes the gaps.
  • Keep contact details ready for the relevant authorities and your IT partner.

Need help?

We help you draw up a workable incident and reporting procedure that fits your organisation. See our NIS2 approach or book a conversation.

Read more

Shall we meet?

No sales pitch. Just a conversation about where you stand and what makes sense for your business.