NIS2Compass — NIS2-Compliance-Plattform
Use CasesPricing
Go to platform

Weiterführende Seiten

  • Blog
  • FAQ
  • Glossar
  • Use Cases
  • Branchen
  • Preisgestaltung

Offizielle Quellen

  • BSI – Bundesamt für Sicherheit in der Informationstechnik
  • NIS2-Richtlinie (EUR-Lex)
  • NIS2UmsuCG (Bundesgesetzblatt)
NIS2Compass — NIS2-Compliance-Plattform

Ihr Navigator durch die NIS2-Compliance

Rechtliches

  • Datenschutzerklärung
  • Allgemeine Geschäftsbedingungen
  • Cookie-Richtlinie
  • Impressum

Ressourcen

  • Blog
  • Use Cases
  • Branchen
  • Preise
  • FAQ
  • Glossar

Kontakt

Kontakt

kontakt@nis2compass.de

NIS2Compass bietet Informationen und Orientierungshilfen zur NIS2-Compliance. Die Inhalte stellen keine Rechtsberatung im Sinne des Rechtsdienstleistungsgesetzes (RDG) dar und ersetzen keine individuelle rechtliche oder fachliche Beratung.

© Copyright 2026 NIS2Compass. Alle Rechte vorbehalten.

Entwickelt in DeutschlandAllianz für Cyber-Sicherheit — Teilnehmer
Home/Blog/NIS2 Incident Reporting: When, What, and to Whom?
Guide

NIS2 Incident Reporting: When, What, and to Whom?

Authored by NIS2Compass Team, NIS2 Compliance Expert
Last updated:August 2, 20269 min read
NIS2 incident reporting as three-stage timeline with hourglass — early warning 24 hours, initial notification 72 hours, final report 1 month to the BSI

Three-stage NIS2 reporting: early warning (24h), initial notification (72h), final report (1 month). Who reports what to whom — and what fines apply for violations?

Anyone subject to NIS2 must report significant security incidents to the BSI in three stages: an early initial notification (frühe Erstmeldung) within 24 hours, a notification (Meldung) after 72 hours, and a final notification (Abschlussmeldung) after one month. According to Bitkom Wirtschaftsschutz 2025, 87 percent of German companies were affected by cyberattacks. The NIS2Compass Pre-Check determines in five minutes whether you are subject to reporting obligations, and the NIS2Compass Implementation Guide then walks you step by step through the reporting process.

When does a security incident count as "significant" and therefore reportable?

Under §2 Nr. 11 BSIG, any security incident that causes or could cause serious operational disruptions, financial losses, or significant material or immaterial damage to third parties is reportable. For providers of digital infrastructure and digital services, EU Implementing Regulation 2024/2690 sets the threshold at 500,000 euros in damages or five percent of annual revenue. The lower value applies.

The definition is intentionally broad. It also covers incidents that have not yet caused actual damage but have the potential to do so. The obligation to assess therefore lies with the affected company itself. A clean upfront classification is consequently an organizational prerequisite for every NIS2 reporting chain.

What typically counts as a significant security incident?

In practice, most reportable incidents fall into one of the following categories:

  • Successful ransomware encryption of production systems with an impact on business operations
  • DDoS attacks causing service outages of several hours that affect customers or third parties
  • Unauthorized access to customer or employee data, even without immediate financial damage
  • Compromised admin accounts or API keys with an impact on availability, confidentiality, or integrity
  • Supplier incidents that impair your own service delivery (so-called supply chain incidents)

According to the Bitkom study, around 34 percent of companies were affected by ransomware in 2025. These incidents reach the reporting threshold in nearly all cases.

What does not count as a significant security incident?

Not every security incident triggers a reporting obligation. The following events typically do not fall under §2 Nr. 11 BSIG:

  • Unsuccessful phishing attempts without clicks or data exfiltration
  • Blocked login attempts and successfully repelled brute-force attacks
  • Planned maintenance outages and scheduled downtimes
  • Individual SPAM emails without further consequences

The distinction looks simple but isn't. When in doubt, you should at least document the incident internally. For more on the consequences of inadequate reporting, see our article on NIS2 fines: which penalties for violations.

Which thresholds apply to digital service providers?

The numerical thresholds of EU Implementing Regulation 2024/2690, among them 500,000 euros in damages or five percent of annual revenue, bind only eleven named types of digital infrastructure and digital service provider. Who they apply to, and why they are not a floor for any other sector, is covered in When is a security incident reportable?.

For other sectors, §2 Nr. 11 BSIG remains the standard. Whether your company falls under these obligations is clarified by the NIS2Compass Pre-Check with sector-specific evaluation.

How does the three-stage reporting procedure under §32 BSIG work?

§32 BSIG requires essential and important entities to submit three sequential reports: an early initial notification within 24 hours, a notification with situation assessment after 72 hours, and a final notification after one month. These are the terms the statute uses; the widespread term "early warning" comes from the English version of the NIS2 Directive and does not appear in the BSIG. All reports go through the BSI reporting portal. The deadline begins with awareness of the incident, meaning the moment an employee identifies the incident during working hours.

According to the BSI Situation Report 2024, around 309,000 new malware variants were registered daily. The probability of becoming subject to reporting at least once a year is real for most regulated entities.

What must the early initial notification (24 hours) contain?

The early initial notification is a pure signal report and does not require a complete analysis. It contains the preliminary classification of the incident and the situation assessment. Added to this is the indication of whether there is suspicion of a malicious act and whether cross-border effects are possible.

Also mandatory are the contact details of the reporting entity and a brief overview of initial containment measures. The BSI does not require more at this stage.

What must the initial notification (72 hours) contain?

The initial notification confirms or corrects the early initial notification and provides an initial assessment of severity and impact. Known Indicators of Compromise (IOCs) must be listed insofar as they are available at this point.

Added to this is the current status of mitigation measures as well as an overview of affected sectors and systems. The initial notification thus closes the gap between the first signal and the complete analysis.

What must the final report (1 month) contain?

The final report is the complete documentation of the incident. Mandatory elements include a detailed description, the final severity rating with concrete impacts, as well as the type of threat and the suspected root cause.

This is supplemented by all implemented and ongoing remediation measures and, where relevant, an assessment of cross-border effects.

What happens with ongoing incidents?

If an incident lasts longer than one month, a progress report replaces the final report. The final report follows only after the matter has been fully resolved. The BSI may request additional interim reports at any time.

Reports already submitted cannot be withdrawn. Corrections take place exclusively through follow-up reports. NIS2Compass documents this deadline logic in the Implementation Guide and provides templates that allow you to prepare the three reporting stages in a structured way. Details on format and content are provided by the BSI reporting obligation information package.

When does the 24-hour deadline actually begin?

The deadline begins with becoming aware, that is, the moment an employee of the entity identifies the incident during working hours. Neither the time of the incident itself nor the conclusion of the analysis starts the clock. Anyone who applies the deadline incorrectly risks fines under §65 BSIG of up to 10 million EUR for essential entities and up to 7 million EUR for important entities.

This interpretation is not our own reading but follows from the BSI reporting obligation information package. The BSI clarifies that what counts is the moment when the entity, through its personnel, learns of the incident, specifically during regular working hours.

Who triggers the deadline?

  • Any employee who identifies the incident in the course of their work
  • External notifications (sub-processors, customers, authorities) count from the moment they reach the entity
  • Automated SIEM alerts count from the point at which personnel evaluate them

A pure machine alert without human evaluation does not trigger the deadline. As soon as an analyst reviews the alert and classifies it as security-relevant, however, the clock starts running.

What does this mean in practice for shift work and on-call duty?

  • Incident detected on Sunday evening: the deadline runs from Sunday evening, not from Monday
  • On-call services must have reporting authority or a defined escalation chain
  • The IR plan should contain 24/7 contact details for internal escalation
  • Clear definition of who legally represents "the entity" under §32 BSIG

This becomes particularly relevant in sectors with high attack pressure. According to the Bitkom study on cybercrime 2025, one in four companies falls victim to a DDoS attack every year. Such incidents often arrive on weekends.

What to do if assessment takes longer than 24 hours?

Report anyway. The early initial notification is explicitly designed as a signal report; a complete analysis is not required. It is better to send a preliminary early initial notification and update it through follow-up reports than to miss the deadline.

The BSI does not interpret the early initial notification as an admission of guilt but as proof of compliance. NIS2Compass recommends planning a separate escalation level in the reporting process for uncertain situations, so that the team reports when in doubt rather than hesitating.

To whom is reporting done, and is the BSI report alone sufficient?

NIS2 reports go to the BSI through the online portal. If personal data is affected, the reporting obligation under Art. 33 GDPR to the data protection supervisory authority of the respective federal state applies in parallel, also within 72 hours. NIS2 and GDPR are separate regimes with separate deadlines, and one report never replaces the other.

Where is the NIS2 report submitted?

The main channel is the BSI reporting portal. Registration was mandatory by 6 March 2026. Anyone not yet registered can use the online form without registration on a transitional basis.

The legal basis for the reporting channel is provided by §32 BSIG. Missing registration does not exempt you from the reporting obligation and makes it harder, in an emergency, to submit the initial report within the 24-hour deadline.

When must the data protection authority also be informed?

If personal data is affected, typically in cases of data theft, ransomware with data exfiltration, or account takeover, Art. 33 GDPR applies in parallel: notification within 72 hours to the responsible state data protection authority.

Where there is a high risk to the rights of data subjects, Art. 34 GDPR requires direct notification of those affected. Both obligations run independently of the NIS2 report. How both regimes can be cleanly integrated into an existing ISMS is described in our article on NIS2-ISMS integration.

Must customers or business partners be informed?

The BSI may instruct essential and important entities to inform users of their services without delay about significant incidents (§35 Abs. 1 BSIG).

For sectors such as finance, IT, telecommunications, and digital services, an additional standalone obligation applies to inform potentially affected customers about significant cyber threats, including recommended countermeasures. According to the Bitkom Wirtschaftsschutz study 2025, personal data is also frequently affected in successful cyberattacks, which makes the dual reporting obligation under NIS2 plus GDPR the rule in practice.

Which other parties may need to be involved?

Depending on the incident and contractual situation, additional addressees may be involved:

  • Cyber insurers: contractual reporting obligation, often within 24 hours of awareness
  • Sector CERTs and ISACs: sectoral early warning and information-sharing structures
  • Law enforcement authorities: when filing a complaint (LKA, ZAC, BKA)
  • Management: mandatory information under §38 BSIG, including personal liability of governing bodies

A BSI report alone does not cover these obligations. NIS2Compass recommends including all relevant addressees as a fixed escalation chain in the incident response plan.

Which fines apply for violations of the reporting obligation?

Violations of the reporting obligation under §32 BSIG are sanctioned independently in the fine schedule of §65 BSIG. Late or incomplete reports can be subject to fines of up to 10 million EUR for essential entities and up to 7 million EUR for important entities, regardless of any sanctions for the actual incident. Added to this is the personal liability of management under §38 BSIG.

Which fine levels apply to which entities?

The BSIG tiers maximum amounts by entity type and type of violation:

  • Reporting and risk-management violations, essential entities: up to 10 million EUR; above a total turnover of 500 million EUR, up to 2% of total turnover instead
  • Reporting and risk-management violations, important entities: up to 7 million EUR; above a total turnover of 500 million EUR, up to 1.4% of total turnover instead
  • Pure registration violations: up to 500,000 EUR
  • Personal liability of management: §38 BSIG, the approval and supervision of measures cannot be delegated

Details on calculation and practice can be found in the NIS2Compass article on NIS2 fines.

What happens with late or incomplete reports?

NIS2 precedents do not yet exist, since the law has only been in force since December 2025. The underlying supervisory logic is, however, well known from GDPR practice: Booking.com was sanctioned in 2021 with 475,000 EUR, not for the incident itself, but for reporting it 22 days late. For NIS2, comparable supervisory practice is to be expected, since §32 BSIG explicitly designs the 24-hour deadline as a standalone obligation.

How can the risk be reduced in practice?

According to the Bitkom Wirtschaftsschutz study 2025, only about half of German companies have a documented emergency or crisis plan. This means many lack the foundation to even meet the 24-hour deadline.

Practical measures to reduce risk:

  • An IR plan with a clear escalation chain and 24/7 reachability
  • Predefined reporting templates for the early initial notification, the notification, and the final notification
  • Tabletop exercises with reporting simulation, at least annually
  • Pre-registration in the BSI portal (deadline was 6 March 2026)

The NIS2Compass Template Library provides the appropriate templates for IR plans, crisis communication, and reporting processes as a starting point.

What does the NIS2 reporting chain look like in practice?

A mid-sized mechanical engineering company with 180 employees discovers an active ransomware encryption on Thursday morning. The IT manager follows the documented escalation path: early initial notification to the BSI after just under 6 hours, parallel GDPR notification due to exfiltrated employee data, notification on Sunday, final notification after 28 days. Without a structured process, the 24-hour deadline would have been missed by hours.

Starting position

The company employs 180 people and generates 35 million EUR in annual revenue. As an important entity, it falls under Annex II BSIG. The Information Security Officer (ISO) works in this role part-time, and the IT team consists of five people.

In advance, an incident response plan based on the NIS2Compass template was implemented. A tabletop exercise in February 2026 had already run through the escalation chain once.

The course of events in detail

  • Thursday, 07:42 — Detection: A SIEM alert reports unusual encryption activity on the central file server. The IT staff member on early shift confirms the incident. From this moment, the 24-hour deadline under §32 BSIG starts running, with the deadline ending on Friday at 07:42.
  • Thursday, 09:00 — Escalation: The ISO is informed, and management at 09:30. Affected servers are isolated, and backup recovery is prepared. An external IT forensics provider is contacted.
  • Thursday, 13:50 — Early warning to the BSI: Submitted via the BSI reporting portal just under 6 hours after detection. Content: ransomware suspected, presumably a malicious act, no cross-border effect identifiable. In parallel, a report is filed with the cyber insurer (contractual deadline 24 hours).
  • Thursday, 16:00 — GDPR notification: Initial indications of exfiltrated employee data trigger a parallel notification under Art. 33 GDPR to the responsible state supervisory authority. The 72-hour GDPR deadline runs in parallel with the NIS2 initial notification deadline.
  • Sunday, 06:30 — Initial notification to the BSI: The 72-hour deadline is met. Content: severity classified as "significant", attack vector identified as a phishing email with compromised link, IOC list, recovery status at 60 percent.
  • Day 28 — Final report: Root cause was an unpatched VPN component combined with a successful phishing email. Damage: four days of production downtime, estimated at 280,000 EUR. Corrective measures: revised patch management, enterprise-wide MFA, mandatory phishing training.

What would have happened without a process?

Without a documented IR plan, without BSI pre-registration, and without prepared reporting templates, the early initial notification would have been submitted only after 30 hours or later. Under §65 BSIG, fines of up to 10 million EUR then become possible, regardless of the actual incident. Added to this would be the personal liability of management under §38 BSIG.

The success factor was the preparation: the NIS2Compass template for the incident response plan provided the escalation matrix, the reporting templates, and the role assignments that had to hold up under pressure.

The scenario is anonymized and serves illustrative purposes only.

Frequently asked questions about NIS2 reporting obligations

What deadlines apply to reporting NIS2 security incidents?

Under §32 BSIG, three deadlines apply: an early initial notification within 24 hours of becoming aware of the incident, a notification after 72 hours with an updated situation assessment, and a final notification after one month with a complete analysis. The clock starts when an employee identifies the incident during working hours — not the moment the incident itself occurred.

What happens if I don't yet have all the information after 24 hours?

Report anyway. The early initial notification under §32 BSIG is a pure signal report with minimal mandatory information. A preliminary report with the note "further details to follow" is significantly better than a late but complete report. Corrections are made through follow-up reports, which the BSI explicitly anticipates.

Do I also have to report near misses?

No, there is no obligation to report near misses under §32 BSIG. Voluntary reports are possible and are welcomed by the BSI, since they improve the national situation picture. There is no penalty for failing to report a near miss. Internal documentation is still worthwhile for your own lessons learned.

Who in my company is allowed to submit a NIS2 report?

The BSIG does not prescribe a specific person. In practice, the ISO or an explicitly designated representative should be authorized, since the deadline runs from the moment of becoming aware. Important: management bears the ultimate responsibility under §38 BSIG and must be involved in every report.

Is the NIS2 report sufficient when personal data is also affected?

No. NIS2 (BSI) and GDPR (data protection authority) are two separate reporting channels with separate deadlines. Both typically run in parallel within 72 hours. NIS2 addresses security of supply, while GDPR addresses the rights of data subjects. One report never replaces the other: failure to comply risks two separate fines side by side.

What does it cost to prepare the reporting processes?

NIS2Compass includes, in the Pro plan (29 EUR/month), the IR plan toolkit, crisis communication templates, and a step-by-step guide to building up the reporting framework. All templates can be found in the Template Library, and in-depth background articles on NIS2 in the Knowledge Hub. External consulting for the same scope typically costs 8,000–15,000 EUR. Detailed comparison: NIS2 consultant or do it yourself?

Implement NIS2 step by step

NIS2Compass guides you step by step through implementation – with guide, templates and knowledge hub.

Get started

Ähnliche Artikel

guide

When Is a Security Incident Reportable? (§ 32 BSIG)

A significant security incident under § 2 no. 11 BSIG: when you have to report to the BSI, and why the 500,000 euro threshold binds only eleven types of digital service provider.

9 Min. Lesezeit

tips-tricks

Management Self-Check under Section 38 BSIG: The Free Excel Template

Free Management Self-Check under Section 38 BSIG as an Excel template: 20 yes/no questions, 5 sections, traffic-light status, no email gate.

6 Min. Lesezeit

guide

NIS2 Guide: How 8 Chapters Lead to Compliance

The NIS2Compass NIS2 Guide walks you through 8 chapters, from registration to training, toward NIS2 compliance. What each chapter covers and how templates help.

10 Min. Lesezeit

Back to Blog