Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you report a significant incident under NIS2?
Updated
Article 23 of Directive (EU) 2022/2555 (NIS2) sets a 24-hour early warning, a 72-hour incident notification, and a one-month final report after that notification. Those three marks are not one number. This page is not legal advice and does not start a clock.
NIS2 jurisdiction guide, last verified 7 September 2026 against Directive (EU) 2022/2555 Articles 2, 3, 4, 23 and 41 and Annexes I and II, Commission Implementing Regulation (EU) 2024/2690 (implementing regulation, not the directive), and ENISA's NIS2 Technical Implementation Guidance (agency guidance, not the directive). It is not legal advice, not a filing, not a determination that you are an essential or important entity, and not a substitute for counsel.
This is NIS2 Article 23, not YOUR entity class
Audience: a CISO, compliance lead, incident commander, or counsel at an organisation that might be an essential or important entity under Directive (EU) 2022/2555. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that NIS2 as transposed applies, that you are essential or important, that an incident is significant, or that you must file.
Article 23 is a legal requirement only if NIS2 as transposed applies to YOUR facts. NIS2 is a directive. Member States transpose it. Transposition wording, portals, and dates vary. Verify YOUR Member State. Last verified 7 September 2026. Not legal advice.
- Statute versus guidance: Articles 2, 3, 23 and 41 are legal requirements only as transposed and only if they apply. Commission Implementing Regulation (EU) 2024/2690 is an implementing regulation for named digital-entity types — it is not the directive. ENISA's NIS2 Technical Implementation Guidance is agency guidance, not the directive.
- This page does not start 24 hours, does not start 72 hours, and does not start the one-month mark. Those three marks are not blended into one number.
- The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The which-jurisdictions-apply page on this site is the applicability map. The GDPR breach-notification guide on this site is Articles 33–34 — a different instrument from Article 23.
- The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. Naming them is not a link. CRA Article 14 is a different instrument from NIS2 Article 23.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is Regulation (EU) 2024/2847 Article 14, not NIS2 Article 23, and it does not file with a CSIRT.
Entity classification — essential, important, or out of scope
This is a decision aid distilled from Articles 2 and 3 and the annexes. It is not a determination that YOU are essential, important, or out of scope. Counsel and, where the directive so provides, the Member State apply those tests. Last verified 7 September 2026. Not legal advice.
| Question | What the directive says | What this page does not do | Source |
|---|---|---|---|
| Are you a public or private entity of a type referred to in Annex I or Annex II, providing services or carrying out activities within the Union, and at least a medium-sized enterprise under Recommendation 2003/361/EC — or larger? | Article 2(1) is the size-cap rule. Medium-sized under Article 2 of the Annex to that Recommendation, or exceeding those ceilings, plus an Annex I or II type, plus Union activity. Article 3(4) of that Annex (linked-enterprise counting) shall not apply for the purposes of this Directive. | Does not size YOUR undertaking. Does not decide that an Annex type fits. Does not quote euro ceilings this page has not restated from the Recommendation itself. | Article 2(1). Legal requirement only as transposed. |
| Regardless of size, do you fall under Article 2(2), 2(3), or 2(4)? | Article 2(2) lists types and situations that sit in scope regardless of size: certain electronic-communications, trust, TLD and DNS providers; sole providers of a service essential for critical societal or economic activities; disruption that could have a significant impact on public safety, public security or public health; disruption that could induce a significant systemic risk; specific national or regional importance; and named public-administration entities. Article 2(3): critical entities under Directive (EU) 2022/2557. Article 2(4): entities providing domain name registration services. | Does not apply Article 2(2)–(4) to YOU. Does not find that you are a critical entity under 2022/2557. | Article 2(2)–(4). |
| If you are in scope — are you essential under Article 3(1)? | Essential entities include: Annex I types that exceed the ceilings for medium-sized enterprises; qualified trust service providers, TLD name registries and DNS service providers regardless of size; medium-sized providers of public electronic communications networks or publicly available electronic communications services; central-government public administration entities referred to in Article 2(2)(f)(i); other Annex I or II types identified by a Member State as essential under Article 2(2)(b)–(e); critical entities under Directive (EU) 2022/2557; and, if the Member State so provides, operators of essential services identified before 16 January 2023 under Directive (EU) 2016/1148 or national law. | Does not classify YOU as essential. Does not read YOUR Member State's list. | Article 3(1). |
| If you are in scope but not essential under Article 3(1) — are you important? | Article 3(2): entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 shall be considered to be important entities. This includes entities identified by Member States as important entities pursuant to Article 2(2)(b)–(e). | Does not classify YOU as important. Essential and important both carry Article 23 reporting if a significant incident occurs; supervision and enforcement differ (recital 15). This page is the reporting guide, not the supervision guide. | Article 3(2). |
| Might you be out of scope? | Article 2(7) excludes public administration entities that carry out their activities in national security, public security, defence or law enforcement. Article 2(10): this Directive does not apply to entities which Member States have exempted from the scope of Regulation (EU) 2022/2554 in accordance with Article 2(4) of that Regulation. Not being of an Annex I or II type, and not meeting Article 2(2)–(4), is also outside Article 2(1). | Does not find that YOU are out of scope. Does not treat 'we are a software vendor' as a legal conclusion. | Article 2(1), 2(7), 2(10). |
| Are you a financial entity covered by DORA? | Recital 28: Regulation (EU) 2022/2554 (DORA) should be considered a sector-specific Union legal act in relation to this Directive with regard to financial entities. Member States should therefore not apply the provisions of this Directive on cybersecurity risk-management and reporting obligations, and supervision and enforcement, to financial entities covered by DORA. Article 4 is the sector-specific-act rule. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. | Does not decide that DORA applies. Does not paste NIS2's 24-hour / 72-hour ladder onto DORA. Does not href an unpublished DORA page. | Recital 28; Article 4. Recital 28 is a recital, not an operative article. |
Sectors the annexes name — not an invented list
The tables below restate the sector titles as Annex I and Annex II print them. They are not a determination that YOUR activity sits in a row. Entity types inside each sector are defined in those annexes; this page does not invent extra sectors. Last verified 7 September 2026. Not legal advice.
| Annex I sector as printed | Source |
|---|---|
| Energy | Annex I, point 1 |
| Transport | Annex I, point 2 |
| Banking | Annex I, point 3 |
| Financial market infrastructures | Annex I, point 4 |
| Health | Annex I, point 5 |
| Drinking water | Annex I, point 6 |
| Waste water | Annex I, point 7 |
| Digital infrastructure | Annex I, point 8 |
| ICT service management (business-to-business) | Annex I, point 9 |
| Public administration | Annex I, point 10 |
| Space | Annex I, point 11 |
Annex II — other critical sectors as printed
Annex II is a different list from Annex I. Large Annex I entities are the main Article 3(1)(a) essential class; Annex II types that are in scope and not essential under Article 3(1) are important under Article 3(2). This page does not run that split on YOUR facts.
| Annex II sector as printed | Source |
|---|---|
| Postal and courier services | Annex II, point 1 |
| Waste management | Annex II, point 2 |
| Manufacture, production and distribution of chemicals | Annex II, point 3 |
| Production, processing and distribution of food | Annex II, point 4 |
| Manufacturing | Annex II, point 5 |
| Digital providers | Annex II, point 6 |
| Research | Annex II, point 7 |
Phased timeline — Article 23 as the article states it
Article 23(4) is the phased model. The 24-hour early warning, the 72-hour incident notification, and the one-month final report are three distinct marks. This page does not average them, does not round 72 hours to three days, and does not convert 'one month' into a number of hours. Clock-start is the event the cited point names. Last verified 7 September 2026. Not legal advice.
- Article 23(1): notify, without undue delay, the CSIRT or, where applicable, the competent authority of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 (significant incident). Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. The mere act of notification shall not subject the notifying entity to increased liability.
- Article 23(2) is a different stream: where applicable, communicate without undue delay to recipients potentially affected by a significant cyber threat any measures or remedies those recipients are able to take, and where appropriate inform them of the significant cyber threat itself. That is not the 24-hour early warning and not the 72-hour notification.
- Article 23(5): the CSIRT or the competent authority shall provide, without undue delay and where possible within 24 hours of receiving the early warning, a response to the notifying entity, including initial feedback and, upon request, guidance or operational advice. That 24-hour response mark is the authority's, not yours.
- The who-to-notify page on this site is the recipient-class map. The how-regulators-determine-knowledge page on this site is the clock-start analysis.
| Stage | Deadline (statutory words) | Clock starts | Recipient | Source | Last verified |
|---|---|---|---|---|---|
| Early warning | Without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact. | Becoming aware of the significant incident. Article 23(4)(a). This page does not find that you have become aware, and it does not start the 24 hours. | The CSIRT or, where applicable, the competent authority. Article 23(1) and 23(4). | Article 23(4)(a). Legal requirement, only as transposed. | 7 September 2026 |
| Incident notification | Without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise. | Becoming aware of the significant incident. Article 23(4)(b). Same start event as the 24-hour early warning — not a second, later start. The 24-hour band and the 72-hour band are not averaged into one number. | The CSIRT or, where applicable, the competent authority. | Article 23(4)(b). Legal requirement, only as transposed. | 7 September 2026 |
| Intermediate report | Upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates. | A request — not becoming aware, and not a fixed hour count in Article 23(4)(c). | The CSIRT or, where applicable, the competent authority that requested it. | Article 23(4)(c). Legal requirement, only as transposed. | 7 September 2026 |
| Final report | A final report not later than one month after the submission of the incident notification under point (b), including: a detailed description of the incident, including its severity and impact; the type of threat or root cause that is likely to have triggered the incident; applied and ongoing mitigation measures; and, where applicable, the cross-border impact of the incident. | The one-month mark runs from the submission of the incident notification (Article 23(4)(d)), not from becoming aware. This page does not convert 'one month' into a number of hours. The one-month mark is not the 24-hour mark and not the 72-hour mark. | The CSIRT or, where applicable, the competent authority. | Article 23(4)(d). Legal requirement, only as transposed. | 7 September 2026 |
| Ongoing incident at the final-report mark | In the event of an ongoing incident at the time of the submission of the final report referred to in point (d), Member States shall ensure that entities concerned provide a progress report at that time and a final report within one month of their handling of the incident. | The later final report runs from handling of the incident, not from becoming aware. This page does not find that YOUR incident is ongoing. | The CSIRT or, where applicable, the competent authority. | Article 23(4)(e). Legal requirement, only as transposed. | 7 September 2026 |
| Trust service providers — incident notification derogation | By way of derogation from the first subparagraph, point (b), a trust service provider shall, with regard to significant incidents that have an impact on the provision of its trust services, notify the CSIRT or, where applicable, the competent authority, without undue delay and in any event within 24 hours of becoming aware of the significant incident. | Becoming aware of the significant incident. This derogation shortens the point (b) incident notification to 24 hours for that trust-service impact. It is not the 72-hour mark, and it is not CRA Article 14. | The CSIRT or, where applicable, the competent authority. | Article 23(4), second subparagraph. Legal requirement, only as transposed. | 7 September 2026 |
What 'significant' means — Article 23(3) versus the implementing regulation
Article 23(3) is the directive's test. Commission Implementing Regulation (EU) 2024/2690 further specifies cases for named digital-entity types. The implementing regulation is not the directive. Last verified 7 September 2026. Not legal advice.
- Do not paste the EUR 500 000 figure onto an entity type that 2024/2690 does not name. Article 23(3) has no euro amount.
- Scheduled interruptions and planned consequences of scheduled maintenance carried out by or on behalf of those relevant entities shall not be considered to be significant incidents (2024/2690 Article 3(2)) — again, for those relevant entities, in that implementing regulation.
- The CRA Article 14 reporting guide on this site. CRA Article 14's 24-hour / 72-hour / 14-day ladder is a different instrument. Do not paste it onto NIS2, and do not paste NIS2's one-month final report onto CRA's actively-exploited 14-day final report.
| Text | What it says | Kind of text | Last verified |
|---|---|---|---|
| Article 23(3)(a) | An incident shall be considered to be significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned. | Legal requirement — the directive, only as transposed. No euro figure in this point. | 7 September 2026 |
| Article 23(3)(b) | An incident shall be considered to be significant if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. | Legal requirement — the directive, only as transposed. No euro figure in this point. | 7 September 2026 |
| Implementing Regulation (EU) 2024/2690 Article 3 — named digital entities | For DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms, and trust service providers, an incident is significant where one or more of the listed criteria are fulfilled. Horizontal examples include: direct financial loss exceeding EUR 500 000 or 5 % of total annual turnover in the preceding financial year, whichever is lower; exfiltration of trade secrets; death of a natural person; considerable damage to a natural person's health; successful, suspectedly malicious and unauthorised access capable of causing severe operational disruption; recurring incidents under Article 4; and the entity-type criteria in Articles 5 to 14. | Implementing regulation, not the directive. Article 23(11) second subparagraph authorised it for those entity types. It does not rewrite Article 23(3) for every essential or important entity. | 7 September 2026 |
| Implementing Regulation (EU) 2024/2690 recital 31 — 'aware' | Notification deadlines run from the moment the entity becomes aware of such significant incidents. The relevant entity is to be regarded as having become 'aware' of the significant incident when, after an initial assessment of a suspicious event, that entity has a reasonable degree of certainty that a significant incident has occurred. | Recital of an implementing regulation, not Article 23. Labelled here as that recital. Not a finding that YOU have a reasonable degree of certainty. | 7 September 2026 |
Commission Implementing Regulation (EU) 2024/2690
This heading is the implementing regulation, not the directive. Regulation (EU) 2024/2690 of 17 October 2024 lays down, for the relevant entities listed in its Article 1, the technical and methodological requirements of the Article 21(2) measures and further specifies the cases in which an incident shall be considered to be significant as referred to in Article 23(3). Last verified 7 September 2026. Not legal advice.
Article 1 names: DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online marketplaces, of online search engines and of social networking services platforms, and trust service providers. The annex to that regulation is risk-management methodology for those entities. ENISA's NIS2 Technical Implementation Guidance (published 26 June 2025) is agency guidance on that annex — not the implementing regulation, and not the directive.
Article 23(11) also lets the Commission adopt implementing acts on the type of information, the format and the procedure of a notification. This page does not treat a missing common template as a licence to skip Article 23(4). Verify the portal YOUR Member State names.
Member-State transposition — variance exists; verify YOUR Member State
NIS2 is a directive. Article 41(1): by 17 October 2024, Member States shall adopt and publish the measures necessary to comply with this Directive. They shall apply those measures from 18 October 2024. Last verified 7 September 2026 against Article 41. Not legal advice.
Transposition is not uniform. Wording, the national list of essential and important entities, the designated CSIRT, the competent authority, the single point of contact, the notification portal, and whether a Member State met the 17 October 2024 mark all vary. This page does not invent a country-by-country transposition table. It does not rank Member States. It does not name YOUR CSIRT.
Article 3(3): by 17 April 2025, Member States shall establish a list of essential and important entities as well as entities providing domain name registration services, and review it at least every two years. Being on that list, or not yet on it, is a fact for counsel and the competent authority — not a conclusion this page draws.
Verify YOUR Member State: the national transposition measure, the designated CSIRT and competent authority, and the portal they name. The EUR-Lex page for Directive (EU) 2022/2555 is the Union text. National law is what you file under. This page is not that national law.
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The reporting-deadlines page on this site is the statute table. The reporting-decision-tree page on this site is the branching tree. The which-jurisdictions-apply page on this site is the applicability map. The how-regulators-determine-knowledge page on this site is the clock-start analysis.
- Does NIS2 as transposed apply? Articles 2 and 3 plus YOUR Member State's measure. This page does not run that test. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. DORA may be lex specialis for in-scope financial entities (recital 28; Article 4).
- Essential or important, or out of scope? Article 3. Marking NIS2 in a product obligation map is not that classification.
- Is the incident significant under Article 23(3)? If you are a 2024/2690 relevant entity, also read that implementing regulation — labelled as such, not as the directive.
- Awareness (UTC): the minute you currently believe the organisation became aware of the significant incident, in Article 23(4)'s words. Do not treat reading this page as becoming aware. This page does not find that minute.
- Early warning: 24 hours from becoming aware — Article 23(4)(a). Recipients: the CSIRT or, where applicable, the competent authority. Do not blend this with the 72-hour notification.
- Incident notification: 72 hours from becoming aware — Article 23(4)(b). Trust service providers: the point (b) derogation is 24 hours for significant incidents that have an impact on the provision of their trust services.
- Final report: one month after submission of the incident notification — Article 23(4)(d). If still ongoing, a progress report then and a final report within one month of handling the incident — Article 23(4)(e). Do not convert 'one month' into hours.
- Recipients of your services: Article 23(1) second sentence and Article 23(2) are different streams from the CSIRT notice. The who-to-notify page on this site is the recipient-class map.
- Document the assessment, including a no-notification decision. The document-your-decision page on this site is the decision record. This page does not keep YOUR file.
Glossary
These words are used as the cited text uses them. This page does not apply them to YOUR facts.
| Term | How this page uses it |
|---|---|
| Essential entity | Article 3(1) class. Not a product mark. Not a finding that YOU are essential. |
| Important entity | Article 3(2) class. In-scope Annex I or II types that are not essential under paragraph 1. Not a lesser reporting duty under Article 23. |
| Significant incident | Article 23(3) test, further specified for named digital-entity types in Implementing Regulation (EU) 2024/2690. Not 'any incident'. |
| Early warning | Article 23(4)(a): 24 hours from becoming aware of the significant incident. Not the 72-hour notification, and not CRA Article 14's early warning. |
| Incident notification | Article 23(4)(b): 72 hours from becoming aware, updating the early warning. Trust-service derogation: 24 hours for that impact. Not the one-month final report. |
| Final report | Article 23(4)(d): not later than one month after the incident notification. Not CRA Article 14's 14-day final report on the actively-exploited track. |
| CSIRT | Computer security incident response team designated by the Member State. Article 23(1) and 23(4) recipient, 'or, where applicable, the competent authority'. |
| Competent authority | The national authority the Member State designates under the directive. Not ENISA as the Article 23 filing desk, and not the CRA Single Reporting Platform. |
| Becoming aware | Article 23(4) clock-start for the 24-hour and 72-hour stages. Implementing Regulation (EU) 2024/2690 recital 31 discusses a reasonable degree of certainty after initial assessment — that recital is not Article 23. |
| Transposition | Member State measures required by Article 41 by 17 October 2024, applying from 18 October 2024. Variance exists. Verify YOUR Member State. |
| Implementing regulation | Commission Implementing Regulation (EU) 2024/2690. Not the directive. Not ENISA guidance. |
Where this shows up in ShipReady Metrics
The signed-in app does not decide that you are an essential or important entity, does not decide that an incident is significant, does not start an Article 23 clock, and does not file with a CSIRT or a competent authority. None of the surfaces below is 'NIS2 applies', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organisation has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a NIS2 Article 23 tracker. The 24-hour / 72-hour CRA clocks run from the organisation's recorded awareness — a human determination the platform must not backdate. It does not start a NIS2 clock. A named human still submits.
The obligation map lists frameworks the organisation has marked in-scope, including NIS2 if that mark is set. That mark is not a determination that you are an essential or important entity, not a determination that NIS2 as transposed applies, and not a legal opinion. The framework catalog's NIS2 starter subset is Article 21 risk-management measures crosswalked for readiness work; it is not an Article 23 filing desk. The cyber risk register lives under Security. None of those surfaces files an Article 23 early warning, incident notification, or final report with a CSIRT.
Primary sources (last verified 7 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Directive (EU) 2022/2555 of 14 December 2022 (NIS2), Articles 2, 3, 4, 23 and 41 and Annexes I and II, is a legal requirement only as transposed and only if you are an in-scope essential or important entity. Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 is an implementing regulation for the digital-entity types it names — not the directive. ENISA, NIS2 Technical Implementation Guidance (26 June 2025) is agency guidance on that implementing regulation's annex, not the directive and not a filing rule. Recital 28 of the directive addresses DORA as lex specialis for financial entities; The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. Regulation (EU) 2024/2847 Article 14 is a different instrument; the CRA Article 14 reporting guide on this site. These are not a complete world list. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The which-jurisdictions-apply page on this site is the applicability map. The who-to-notify page on this site is the recipient-class map. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The do-I-have-to-report page on this site is the class map. The prepare-regulatory-report page on this site is the field checklist. The GDPR breach-notification guide on this site is Articles 33–34. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. A dedicated SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.
Frequently asked questions
When must you report a significant incident under NIS2?
Article 23(4) of Directive (EU) 2022/2555 sets three distinct marks from becoming aware of a significant incident: an early warning within 24 hours, an incident notification within 72 hours, and a final report not later than one month after that notification. Those marks are not one number. Only if NIS2 as transposed applies. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a jurisdiction guide distilled from Directive (EU) 2022/2555 Articles 2, 3, 23 and 41 and Annexes I and II, plus Commission Implementing Regulation (EU) 2024/2690 labelled as an implementing regulation, not the directive. Whether you are essential or important, whether an incident is significant, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file NIS2 reports?
No. The signed-in app does not file with a CSIRT or a competent authority, does not start an Article 23 clock, and does not decide that you are an essential or important entity. Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the org classified as CRA-in-scope. That is one product tracker for CRA, not a NIS2 filing desk. The obligation map is frameworks marked in-scope, not a legal opinion.
Are the 24-hour, 72-hour, and one-month marks the same deadline?
No. Article 23(4)(a) is 24 hours from becoming aware (early warning). Article 23(4)(b) is 72 hours from becoming aware (incident notification). Article 23(4)(d) is one month after submission of the incident notification (final report). This page does not average those marks and does not convert one month into hours. Trust service providers have a 24-hour derogation for the point (b) notification when the significant incident affects their trust services.
Does marking NIS2 in the obligation map mean we are an essential entity?
No. The obligation map lists frameworks the organisation has marked in-scope. That mark is not a determination that you are an essential or important entity, not a determination that NIS2 as transposed applies, and not a legal opinion. Articles 2 and 3 plus YOUR Member State's transposition decide class. This page does not.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.