What are the NIS2 reporting deadlines for a security incident?
Quick Answer
Article 23 sets a chain of reports rather than a single deadline. An early warning is due within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, an intermediate report whenever the CSIRT or competent authority requests one, a progress report if the incident is still ongoing at the one-month mark, and a final report within one month of the notification. Trust service providers report within 24 hours at the notification stage, under the derogation in the closing subparagraph of Article 23(4). Reports go to the CSIRT or, where applicable, the competent authority. Article 23(1) adds a duty that is routinely missed: entities must, where appropriate, also notify the recipients of their services of significant incidents likely to adversely affect those services.
Detailed Explanation
Related Topics

Erfahre in diesem Artikel, wie Data Discovery dabei helfen kann, relevante Daten in Hubspot, Mailchimp und Co. aufzuspüren und so für DSGVO-Dokumentation aufzubereiten.

Erfahre in diesem Artikel, wie Data Discovery dabei helfen kann, relevante Daten in Hubspot, Mailchimp und Co. aufzuspüren und so für DSGVO-Dokumentation aufzubereiten.

Erfahre in diesem Artikel, wie Data Discovery dabei helfen kann, relevante Daten in Hubspot, Mailchimp und Co. aufzuspüren und so für DSGVO-Dokumentation aufzubereiten.