NIS-2 Incident Reporting Obligations: Deadlines, Reporting Criteria, and Requirements

11. August 2026

A security incident occurs: within 24 hours, your organization must determine whether it is required to notify the German Federal Office for Information Security (BSI). This very time pressure makes the NIS-2 incident reporting obligation a practical challenge for many organizations. When information is still incomplete, responsibilities have not been clearly defined, and the assessment must be made under crisis conditions, the risk of misjudgments and delays increases.

With the NIS-2 Directive, significantly more organizations than before fall within the scope of regulatory requirements. For affected entities, this means that security incidents must be assessed more quickly, coordinated internally, and reported within the applicable deadlines. As a result, several key questions come to the forefront: When does an incident become reportable? Which reporting timelines apply? And how can organizations reliably comply with the legal requirements when an actual incident occurs? In this article, Dr. Nicole Trebel, Senior Security Consultant at usd AG, explores these questions in detail.

What Does the NIS-2 Incident Reporting Obligation Mean for Affected Organizations?

The NIS-2 incident reporting obligation is a key component of the European cybersecurity strategy. Its objective is to ensure that significant security incidents become visible at an early stage, allowing the BSI to assess the situation more quickly, issue targeted warnings, and better contain impacts on other organizations. At the same time, NIS-2 requires organizations to document incidents in a structured manner, assess them in a transparent and traceable way, and communicate them reliably.

In practice, the question is therefore not limited to whether an incident must be reported. What matters is whether organizations have already established clear criteria, defined responsibilities, and implemented an effective reporting process. This is precisely where shortcomings often become apparent during an actual incident, and where NIS-2 creates the greatest pressure to act.

When Is an Incident Reportable Under NIS-2?

Not every IT security incident automatically triggers an incident reporting obligation. The key factor is whether the incident qualifies as a significant security incident and what impact it may have on your organization. An incident is considered significant in particular if it*:

  • may lead to severe disruption of services,
  • may cause financial loss, or
  • may affect third parties.

* Specific thresholds apply to the small sector group under NIS-2 that falls within the scope of Implementing Regulation (EU) 2024/2690.

It is important to note that the mere possibility of such impacts may be sufficient. Organizations do not need to wait until an incident has been fully investigated. Rather, what matters is an early and well-documented initial assessment. This often has to be made under significant time pressure and on the basis of incomplete information.

This is precisely where many organizations struggle in practice. Agreed assessment criteria are often missing, escalation paths are not clearly defined, and the decision on whether an incident must be reported is made only in crisis mode. Organizations should therefore, in case of doubt, classify incidents as potentially reportable at an early stage and ensure they can be assessed internally without delay.

Who Is Subject to the NIS-2 Incident Reporting Obligation?

The NIS-2 incident reporting obligation applies to so-called essential and important entities. These include organizations operating across a wide range of regulated sectors, including energy, transport, healthcare, IT services, and digital services. Operators of critical facilities are also subject to the corresponding reporting obligations.

Compared to previous regulations, the scope is significantly expanded. Medium-sized companies may also fall within scope if they exceed certain thresholds relating to the number of employees, annual turnover, or balance sheet total. In practice, this means that many organizations are facing cybersecurity related regulatory requirements for the first time. Whether an organization actually falls within the scope of NIS-2 should, however, be carefully assessed on a case-by-case basis.

How and When Must Incidents Be Reported Under NIS-2?

Significant security incidents must be reported to the BSI without undue delay after becoming aware of them. In Germany, reports are submitted centrally via the BSI Reporting and Information Portal. It is important to note that KRITIS operators continue to report through the MIP.

The reporting process follows a clearly defined sequence consisting of several successive notifications. The primary objective is to inform the BSI at an early stage:

Early Warning (within 24 hours)

Within 24 hours of becoming aware of a significant security incident, organizations must submit an initial notification to the BSI. This early warning enables the BSI to obtain timely information about the incident and perform an initial assessment. At this stage, not all details need to be available. What matters is that the information already available is reported promptly.

In this initial notification, organizations specify in particular whether the incident may be the result of malicious or unlawful acts and whether impacts beyond their own organization are to be expected, for example on other organizations or across national borders.

Incident Notification (within 72 hours)

Within 72 hours, the initial notification must be supplemented with additional information. Organizations then provide further details on their findings and deliver a more reliable assessment of the severity, cause, affected systems, and mitigation measures already taken.

This reporting stage also includes an initial assessment of the potential impact on the organization itself or on third parties. The quality of this assessment depends largely on whether technical, organizational, and communication responsibilities have been clearly defined in advance.

Final Report (no later than one month after the initial notification)

No later than one month after the initial notification, organizations must submit the final report. Its purpose is to fully document and comprehensively analyse the incident. If the incident is still ongoing at that time, additional progress reports to the BSI may be required.

In the final report, organizations provide a detailed description of the incident, assess its actual impact, analyse its cause, and outline the measures taken as part of incident handling. For this reason, it is advisable not to view the reporting process in isolation, but to closely integrate it with incident response, crisis management, and internal communication.

What Challenges Does the NIS-2 Incident Reporting Obligation Present?

The real challenge usually does not lie in the technical submission of a report, but in the rapid and reliable assessment of the incident. Who determines whether the incident is significant? What information is already available? Who decides whether a report must be submitted? And how are management, business units, IT, and, where applicable, legal or data protection functions involved?

If these questions are only addressed once an incident occurs, the 24-hour deadline quickly becomes an organizational stress test. Organizations should therefore define in advance how security incidents are classified, escalated, and documented. Only then can incident reporting obligations be met reliably without having to improvise under time pressure.

What Organizations Should Do Now

The NIS-2 incident reporting obligation should not be viewed in isolation. Instead, organizations should align the reporting requirements with existing incident response, crisis communication, and, where applicable, data protection processes in order to handle incidents efficiently and meet reporting deadlines.

We support you in implementing these requirements in a practical and efficient manner. Together, we define clear reporting and escalation procedures, integrate them into existing processes, and prepare your organization specifically for incident scenarios. This enables you to assess incidents confidently, respond quickly, and comply with legal deadlines reliably. Contact us.

About the Author: Dr. Nicole Trebel

Dr. Nicole Trebel is a Senior Security Consultant at usd AG. She supports organizations in implementing the requirements of NIS-2, DORA, and ISO 27001. In this role, she assists organizations in advancing their information security practices and establishing effective information security management systems.

NIS-2 Incident Reporting Obligations: Key Facts at a Glance

Who Is Subject to the NIS-2 Incident Reporting Obligation?

Essential and important entities.

What Must Be Reported Under NIS-2?

A significant incident is reportable in particular if it causes, or is capable of causing, severe disruption to services, may result in financial losses, or affects third parties.

Which Reporting Deadlines Apply Under NIS-2?

An Early Warning must be submitted within 24 hours, an Incident Notification within 72 hours, and a Final Report no later than one month after the initial notification.

Which Platform Is Used for Reporting?

Reports are submitted centrally via the BSI Reporting and Information Portal.

Auch interessant:

Kategorien

Kategorien