Skip to content

nis2

NIS2 Incident Reporting: When, What, and to Whom?

Three-stage NIS2 reporting: early warning (24h), initial notification (72h), final report (1 month). Who reports what to whom, and what fines apply for violations?

By KaitoSec · Published 27 April 2026 · Updated 26 August 2026 · 14 min read

NIS2 Incident Reporting: When, What, and to Whom?

Anyone subject to NIS2 must report significant security incidents to the BSI in three stages: an early warning within 24 hours, an initial notification after 72 hours, and a final report after one month. According to Bitkom Wirtschaftsschutz 2025, 87 percent of German companies were affected by cyberattacks.

When does a security incident count as "significant" and therefore reportable?

Under §2 Nr. 11 BSIG, any security incident that causes or could cause serious operational disruptions, financial losses, or significant material or immaterial damage to third parties is reportable. For IT, telecommunications, and digital services, EU Implementing Regulation 2024/2690 sets the threshold at 500,000 euros in damages or five percent of annual revenue. The lower value applies.

The definition is intentionally broad. It also covers incidents that have not yet caused actual damage but have the potential to do so. The obligation to assess therefore lies with the affected company itself. A clean upfront classification is consequently an organizational prerequisite for every NIS2 reporting chain.

What typically counts as a significant security incident?

In practice, most reportable incidents fall into one of the following categories:

  • Successful ransomware encryption of production systems with an impact on business operations
  • DDoS attacks causing service outages of several hours that affect customers or third parties
  • Unauthorized access to customer or employee data, even without immediate financial damage
  • Compromised admin accounts or API keys with an impact on availability, confidentiality, or integrity
  • Supplier incidents that impair your own service delivery (so-called supply chain incidents)

According to the Bitkom study, around 34 percent of companies were affected by ransomware in 2025. These incidents reach the reporting threshold in nearly all cases.

What does not count as a significant security incident?

Not every security incident triggers a reporting obligation. The following events typically do not fall under §2 Nr. 11 BSIG:

  • Unsuccessful phishing attempts without clicks or data exfiltration
  • Blocked login attempts and successfully repelled brute-force attacks
  • Planned maintenance outages and scheduled downtimes
  • Individual SPAM emails without further consequences

The distinction looks simple but isn't. When in doubt, you should at least document the incident internally. For more on the consequences of inadequate reporting, see our article on NIS2 fines: which penalties for violations.

Which thresholds apply to IT and telecommunications services?

For providers of DNS, cloud, CDN, and hosting services, specific thresholds from EU Implementing Regulation 2024/2690 apply. An incident is reportable when it causes a direct financial loss exceeding 500,000 euros or five percent of annual revenue, when it affects more than five million users, or when it triggers a service outage of more than one hour with significant reach.

For other sectors, §2 Nr. 11 BSIG remains the standard.

How does the three-stage reporting procedure under §32 BSIG work?

§32 BSIG requires essential and important entities to submit three sequential reports: an early warning within 24 hours, an initial notification with situation assessment after 72 hours, and a final report after one month. All reports go through the BSI reporting portal. The deadline begins with awareness of the incident, meaning the moment an employee identifies the incident during working hours.

According to the BSI Situation Report 2024, around 309,000 new malware variants were registered daily. The probability of becoming subject to reporting at least once a year is real for most regulated entities.

What must the early warning (24 hours) contain?

The early warning is a pure signal report and does not require a complete analysis. It contains the preliminary classification of the incident and the situation assessment. Added to this is the indication of whether there is suspicion of a malicious act and whether cross-border effects are possible.

Also mandatory are the contact details of the reporting entity and a brief overview of initial containment measures. The BSI does not require more at this stage.

What must the initial notification (72 hours) contain?

The initial notification confirms or corrects the early warning and provides an initial assessment of severity and impact. Known Indicators of Compromise (IOCs) must be listed insofar as they are available at this point.

Added to this is the current status of mitigation measures as well as an overview of affected sectors and systems. The initial notification thus closes the gap between the first signal and the complete analysis.

What must the final report (1 month) contain?

The final report is the complete documentation of the incident. Mandatory elements include a detailed description, the final severity rating with concrete impacts, as well as the type of threat and the suspected root cause.

This is supplemented by all implemented and ongoing remediation measures and, where relevant, an assessment of cross-border effects.

What happens with ongoing incidents?

If an incident lasts longer than one month, a progress report replaces the final report. The final report follows only after the matter has been fully resolved. The BSI may request additional interim reports at any time.

Reports already submitted cannot be withdrawn. Corrections take place exclusively through follow-up reports. Details on format and content are provided by the BSI reporting obligation information package.

"The 24-hour deadline sounds tight, but it's deliberately low-threshold. It doesn't require a complete analysis, just a structured initial signal. Anyone who confuses this loses valuable time," says **Dr.

When does the 24-hour deadline actually begin?

The deadline begins with becoming aware, that is, the moment an employee of the entity identifies the incident during working hours. Neither the time of the incident itself nor the conclusion of the analysis starts the clock. Anyone who applies the deadline incorrectly risks fines of up to 5 million EUR under §65 BSIG.

This interpretation is not our own reading but follows from the BSI reporting obligation information package. The BSI clarifies that what counts is the moment when the entity, through its personnel, learns of the incident, specifically during regular working hours.

Who triggers the deadline?

  • Any employee who identifies the incident in the course of their work
  • External notifications (sub-processors, customers, authorities) count from the moment they reach the entity
  • Automated SIEM alerts count from the point at which personnel evaluate them

A pure machine alert without human evaluation does not trigger the deadline. As soon as an analyst reviews the alert and classifies it as security-relevant, however, the clock starts running.

What does this mean in practice for shift work and on-call duty?

  • Incident detected on Sunday evening: the deadline runs from Sunday evening, not from Monday
  • On-call services must have reporting authority or a defined escalation chain
  • The IR plan should contain 24/7 contact details for internal escalation
  • Clear definition of who legally represents "the entity" under §32 BSIG

This becomes particularly relevant in sectors with high attack pressure. According to the Bitkom study on cybercrime 2025, one in four companies falls victim to a DDoS attack every year. Such incidents often arrive on weekends.

What to do if assessment takes longer than 24 hours?

Report anyway. The early warning is explicitly designed as a signal report; a complete analysis is not required. It is better to send a preliminary early warning and update it through follow-up reports than to miss the deadline.

The BSI does not interpret the early warning as an admission of guilt but as proof of compliance.

To whom is reporting done, and is the BSI report alone sufficient?

NIS2 reports go to the BSI through the online portal. If personal data is affected, the reporting obligation under Art. 33 GDPR to the data protection supervisory authority of the respective federal state applies in parallel, also within 72 hours. NIS2 and GDPR are separate regimes with separate deadlines, and one report never replaces the other.

Where is the NIS2 report submitted?

The main channel is the BSI reporting portal. Registration was mandatory by 6 March 2026. Anyone not yet registered can use the online form without registration on a transitional basis.

The legal basis for the reporting channel is provided by §32 BSIG. Missing registration does not exempt you from the reporting obligation and makes it harder, in an emergency, to submit the initial report within the 24-hour deadline.

When must the data protection authority also be informed?

If personal data is affected, typically in cases of data theft, ransomware with data exfiltration, or account takeover, Art. 33 GDPR applies in parallel: notification within 72 hours to the responsible state data protection authority.

Where there is a high risk to the rights of data subjects, Art. 34 GDPR requires direct notification of those affected. Both obligations run independently of the NIS2 report. How both regimes can be cleanly integrated into an existing ISMS is described in our article on NIS2-ISMS integration.

Must customers or business partners be informed?

The BSI may instruct essential and important entities to inform users of their services without delay about significant incidents (§35 Abs. 1 BSIG).

For sectors such as finance, IT, telecommunications, and digital services, an additional standalone obligation applies to inform potentially affected customers about significant cyber threats, including recommended countermeasures. According to the Bitkom Wirtschaftsschutz study 2025, personal data is also frequently affected in successful cyberattacks, which makes the dual reporting obligation under NIS2 plus GDPR the rule in practice.

Which other parties may need to be involved?

Depending on the incident and contractual situation, additional addressees may be involved:

  • Cyber insurers: contractual reporting obligation, often within 24 hours of awareness
  • Sector CERTs and ISACs: sectoral early warning and information-sharing structures
  • Law enforcement authorities: when filing a complaint (LKA, ZAC, BKA)
  • Management: mandatory information under §38 BSIG, including personal liability of governing bodies

Which fines apply for violations of the reporting obligation?

Violations of the reporting obligation under §32 BSIG are sanctioned independently in the fine schedule of §65 BSIG. Late or incomplete reports can be subject to fines of up to 5 million EUR, regardless of any sanctions for the actual incident. Added to this is the personal liability of management under §38 BSIG.

Which fine levels apply to which entities?

The BSIG tiers maximum amounts by entity type and type of violation:

  • Essential entities: up to 10 million EUR or 2% of global annual revenue (whichever is higher)
  • Important entities: up to 7 million EUR or 1.4% of global annual revenue
  • Pure reporting and registration violations: up to 5 million EUR
  • Personal liability of management: §38 BSIG, the approval and supervision of measures cannot be delegated

What happens with late or incomplete reports?

NIS2 precedents do not yet exist, since the law has only been in force since December 2025. The underlying supervisory logic is, however, well known from GDPR practice: Booking.com was sanctioned in 2021 with 475,000 EUR, not for the incident itself, but for reporting it 22 days late. For NIS2, comparable supervisory practice is to be expected, since §32 BSIG explicitly designs the 24-hour deadline as a standalone obligation.

How can the risk be reduced in practice?

According to the Bitkom Wirtschaftsschutz study 2025, only about half of German companies have a documented emergency or crisis plan. This means many lack the foundation to even meet the 24-hour deadline.

Practical measures to reduce risk:

  • An IR plan with a clear escalation chain and 24/7 reachability
  • Predefined reporting templates for early warning, initial notification, and final report
  • Tabletop exercises with reporting simulation, at least annually
  • Pre-registration in the BSI portal (deadline was 6 March 2026)

What does the NIS2 reporting chain look like in practice?

A mid-sized mechanical engineering company with 180 employees discovers an active ransomware encryption on Thursday morning. The IT manager follows the documented escalation path: early warning to the BSI after just under 6 hours, parallel GDPR notification due to exfiltrated employee data, initial notification on Sunday, final report after 28 days. Without a structured process, the 24-hour deadline would have been missed by hours.

Starting position

The company employs 180 people and generates 35 million EUR in annual revenue. As an important entity, it falls under Annex II BSIG. The Information Security Officer (ISO) works in this role part-time, and the IT team consists of five people.

A tabletop exercise in February 2026 had already run through the escalation chain once.

The course of events in detail

  • Thursday, 07:42: Detection: A SIEM alert reports unusual encryption activity on the central file server. The IT staff member on early shift confirms the incident. From this moment, the 24-hour deadline under §32 BSIG starts running, with the deadline ending on Friday at 07:42.
  • Thursday, 09:00: Escalation: The ISO is informed, and management at 09:30. Affected servers are isolated, and backup recovery is prepared. An external IT forensics provider is contacted.
  • Thursday, 13:50: Early warning to the BSI: Submitted via the BSI reporting portal just under 6 hours after detection. Content: ransomware suspected, presumably a malicious act, no cross-border effect identifiable. In parallel, a report is filed with the cyber insurer (contractual deadline 24 hours).
  • Thursday, 16:00: GDPR notification: Initial indications of exfiltrated employee data trigger a parallel notification under Art. 33 GDPR to the responsible state supervisory authority. The 72-hour GDPR deadline runs in parallel with the NIS2 initial notification deadline.
  • Sunday, 06:30: Initial notification to the BSI: The 72-hour deadline is met. Content: severity classified as "significant", attack vector identified as a phishing email with compromised link, IOC list, recovery status at 60 percent.
  • Day 28: Final report: Root cause was an unpatched VPN component combined with a successful phishing email. Damage: four days of production downtime, estimated at 280,000 EUR. Corrective measures: revised patch management, enterprise-wide MFA, mandatory phishing training.

What would have happened without a process?

Without a documented IR plan, without BSI pre-registration, and without prepared reporting templates, the early warning would have been submitted only after 30 hours or later. Under §65 BSIG, fines of up to 5 million EUR then become possible, regardless of the actual incident. Added to this would be the personal liability of management under §38 BSIG.

The scenario is anonymized and serves illustrative purposes only.

Frequently asked questions about NIS2 reporting obligations

What happens if I don't yet have all the information after 24 hours?

Report anyway. The early warning under §32 BSIG is a pure signal report with minimal mandatory information. A preliminary report with the note "further details to follow" is significantly better than a late but complete report. Corrections are made through follow-up reports, which the BSI explicitly anticipates.

Do I also have to report near misses?

No, there is no obligation to report near misses under §32 BSIG. Voluntary reports are possible and are welcomed by the BSI, since they improve the national situation picture. There is no penalty for failing to report a near miss. Internal documentation is still worthwhile for your own lessons learned.

Who in my company is allowed to submit a NIS2 report?

The BSIG does not prescribe a specific person. In practice, the ISO or an explicitly designated representative should be authorized, since the deadline runs from the moment of becoming aware. Important: management bears the ultimate responsibility under §38 BSIG and must be involved in every report.

Is the NIS2 report sufficient when personal data is also affected?

No. NIS2 (BSI) and GDPR (data protection authority) are two separate reporting channels with separate deadlines. Both typically run in parallel within 72 hours. NIS2 addresses security of supply, while GDPR addresses the rights of data subjects. One report never replaces the other: failure to comply risks two separate fines side by side.

What does it cost to prepare the reporting processes?

All templates can be found in the Vorlagen-Bibliothek, and in-depth background articles on NIS2 in the NIS2-Wissensbereich. External consulting for the same scope typically costs 8,000–15,000 EUR. Detailed comparison: NIS2 consultant or do it yourself?

  • nis2
  • guide
  • NIS2
  • Meldepflicht
  • BSI
  • §32 BSIG
  • Incident Response
  • Sicherheitsvorfall
  • BSIG
  • KMU

Back to the blog