
The NIS2 reporting obligation and deadlines: 24 hours, 72 hours, one month
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What is a significant incident under the Cyber Security Act (NIS2)?
Not every disruption needs to be reported. The Cyber Security Act defines a significant incident as one that causes, or is capable of causing, a serious disruption to your services or financial loss to your own organization, or one that causes, or is capable of causing, significant material or non-material damage to other organizations or individuals. The precise thresholds vary by sector and are detailed in ministerial regulations, so what is a routine incident for one organization may be reportable for another. If in doubt, assume the worst-case scenario and report it rather than risk under-reporting.
A concrete example: when is an incident significant for MSPs and MSSPs?
The law itself remains intentionally general, but EU Implementing Regulation 2024/2690 sets out criteria per sector in concrete figures, and this regulation serves as a guide for the RDI and the NCSC. If you fall under a different sector, other articles and thresholds apply to your type of service, so check the regulation applicable to your sector if you are unsure.
For managed service providers and managed security service providers (MSPs and MSSPs), an incident is considered significant as soon as at least one of these criteria is met (Article 10):
- The service is completely unavailable for more than 30 minutes.
- The availability of the service is restricted for more than one hour for more than 5% of users in the EU, or for more than 1 million users, whichever is the smaller number.
- The integrity, confidentiality, or authenticity of data associated with the service has been compromised as a result of a suspected malicious act.
- That same integrity, confidentiality, or authenticity has been compromised with consequences for more than 5% of users in the EU, or for more than 1 million users, whichever is the smaller number.
If your organization does not fall into this category, this example remains useful: it shows how the abstract legal text above is translated into hard numbers per sector, as laid down in a separate regulation.
Why must you report a significant incident?
The reporting obligation contributes directly to the digital security of the Netherlands and other EU member states. Reported incidents provide the NCSC and regulators with an up-to-date picture of current threats, and they use that information to warn other organizations and help them better defend themselves.
Reporting also benefits your own organization. From the moment you provide an early warning, you are entitled to assistance from your sectoral CSIRT, which will respond within 24 hours and can provide support with advice, analysis, and practical help in mitigating damage. In the case of a large-scale or complex incident, this may extend to additional technical support, for example from a cyber response team. If the incident also has consequences in other EU countries, the central reporting point will inform the other member states and ENISA so that the response can be coordinated across borders.
When does the clock start ticking under the Cyber Security Act?
The three deadlines start from the moment your organization becomes aware of the significant incident. This is a different moment than when the incident itself began, and the difference is greater than it seems: a technical problem may have been ongoing for days before anyone notices it. The reporting obligation only begins upon that discovery.
Milestone 1: The 24-hour early warning
As soon as you become aware of a significant incident, you must send an initial warning to your sectoral CSIRT and the competent supervisory authority (via MijnNCSC) as soon as possible, and no later than 24 hours after discovery. In this warning, indicate whether the incident is suspected to be the result of unlawful or malicious activity, whether there are cross-border (international) consequences, and who your contact person is. You do not need to have a full analysis at this stage; the warning is primarily intended to notify the CSIRT and the supervisory authority.
Milestone 2: The 72-hour notification
A more detailed notification follows within 72 hours. In this report, you update your initial warning with a preliminary assessment of the severity and impact of the incident. Additionally, share any indicators of compromise if they are already known. This notification may still be a preliminary assessment; you do not need to provide a conclusive report yet. You must, however, clearly state:
- The measures you have taken (or are currently implementing)
- The (potential) cause of the incident
- The scope of the incident
Milestone 3: The final report after one month
The sectoral authority may request interim updates; you will be notified if this is required. The final report must be submitted no later than one month after the early warning. In it, describe the incident, the suspected cause, the severity and impact, and the measures you have taken or are still taking, including any cross-border impact. If the incident is not yet resolved after that month, submit a progress report at that time. The final report must then be submitted within one month of the incident being resolved.
Who do you report a significant NIS2 incident to?
All three notifications are submitted via MijnNCSC: you report to your sectoral CSIRT and the supervisory authority responsible for your sector. This reporting obligation governs your relationship with the government. Any agreements you make with customers or suppliers regarding the sharing of incident information should be documented in your contracts.
What happens if you do not report?
The reporting obligation is a mandatory requirement, and there are consequences for non-compliance. If you fail to report a significant incident, or if your report is late or incomplete, the RDI (or the supervisory authority responsible for your sector) will oversee the matter, which may include an inspection following the incident itself. This oversight follows a tiered approach, ranging from guidance and proposals for improvement to a formal directive, an administrative order subject to a penalty, or, in extreme cases, an administrative fine.
For violations of the Cybersecurity Act, including the reporting obligation, the same maximum fine amounts apply as for other obligations under the Act: up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1.4% for important entities, whichever is higher. The actual amount imposed depends on the nature and severity of the violation: the RDI considers factors such as the seriousness of the breach, the degree of culpability, and your organization's financial capacity.
{{LINKCARD}}
How can you prepare for a significant NIS2 incident?
- Define who within your organization is authorized to decide whether an event qualifies as a significant incident.
- Make sure you know how to report to your sector-specific CSIRT and supervisory authority before you actually need to.
- Simulate an incident and practice the reporting deadlines so that everyone knows who takes which step the moment the clock starts ticking.
- Ensure you can demonstrably provide logging and evidence, even during the stress of an incident. This is crucial information for your reports.
This way, when things go wrong, you won't have to figure out what to do; you will have already done that work. You can then simply follow your established process, even under pressure.
Want to know what else is expected of you beyond the NIS2 reporting obligation? Download our NIS2 checklist above or schedule a no-obligation consultation below.

%202.png)
.jpg)


















