Ch.17 Identity, Data and Cybersecurity: eIDAS 2.0, Data Act, NIS2, CRA Fact 225 words

NIS2 incident reporting: 24h / 72h / 1 month

Early warning within 24 hours, notification within 72 hours, final report within one month — the trap is mixing up the deadlines or confusing them with other EU reporting rules.

Audio

Ascolta questa pagina (beta)

Sottotitoli

The NIS2 Directive sets three sequential deadlines for reporting significant cybersecurity incidents. You must send an early warning within 24 hours of becoming aware of the incident, then a more detailed notification within 72 hours, and finally a comprehensive final report within one month. The key contrast is with the GDPR's 72-hour breach notification, which is a single deadline, not a three-stage process — mixing these up is a common exam error.

To avoid confusion, remember the sequence as 'alert, explain, close'. The 24-hour warning is just a heads-up with initial impact, the 72-hour notification adds root cause and ongoing effects, and the one-month report covers full investigation and mitigations. A useful elimination trick: if a question mentions 'intermediate report' or 'update', it's likely not NIS2 — NIS2 has only these three fixed stages, not rolling updates. Also note that the 24-hour clock starts from 'awareness', not from the incident itself, so watch for wording like 'discovered' versus 'occurred'.

To lock in the order, think of a 24-hour news alert, a 72-hour detailed briefing, and a one-month post-mortem. Test yourself by reciting: '24 for warning, 72 for details, one month for the full story.' If you see a deadline like 48 hours or 14 days, it's probably from a different regulation such as the Digital Operational Resilience Act (DORA) — flag it as a distractor.

Flashcard collegata

What are the headline NIS2 incident reporting windows?

Early warning within 24 hours, notification within 72 hours, and a final report within one month.

Torna alla flashcard Vedi tutte le flashcard