Ch.17 Identity, Data and Cybersecurity: eIDAS 2.0, Data Act, NIS2, CRA Fact 225 words

NIS2 incident reporting: 24h / 72h / 1 month

Early warning within 24 hours, notification within 72 hours, final report within one month — the trap is mixing up the deadlines or confusing them with other EU reporting rules.

Audio

Écouter cette page (bêta)

Sous-titres

The NIS2 Directive sets three sequential deadlines for reporting significant cybersecurity incidents. You must send an early warning within 24 hours of becoming aware of the incident, then a more detailed notification within 72 hours, and finally a comprehensive final report within one month. The key contrast is with the GDPR's 72-hour breach notification, which is a single deadline, not a three-stage process — mixing these up is a common exam error.

To avoid confusion, remember the sequence as 'alert, explain, close'. The 24-hour warning is just a heads-up with initial impact, the 72-hour notification adds root cause and ongoing effects, and the one-month report covers full investigation and mitigations. A useful elimination trick: if a question mentions 'intermediate report' or 'update', it's likely not NIS2 — NIS2 has only these three fixed stages, not rolling updates. Also note that the 24-hour clock starts from 'awareness', not from the incident itself, so watch for wording like 'discovered' versus 'occurred'.

To lock in the order, think of a 24-hour news alert, a 72-hour detailed briefing, and a one-month post-mortem. Test yourself by reciting: '24 for warning, 72 for details, one month for the full story.' If you see a deadline like 48 hours or 14 days, it's probably from a different regulation such as the Digital Operational Resilience Act (DORA) — flag it as a distractor.

Flashcard liée

What are the headline NIS2 incident reporting windows?

Early warning within 24 hours, notification within 72 hours, and a final report within one month.

Retour à la flashcard Voir toutes les flashcards