NIS2 Directive, Reporting Obligations
Directive (EU) 2022/2555, Art. 23
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 18 October 2024.
A vulnerability and incident reporting rule binding public and private bodies.
As of 8 September 2026.
What it requires
- This duty reaches your service where you qualify as a medium-sized enterprise or larger under the EU size-cap rule and you operate an online marketplace, online search engine or social networking services platform under Annex II, or where you are a public administration entity of central or regional government under Annex I.
- Notify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
- Where appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take.
- Treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to your own operations, or considerable material or non-material damage to another person.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 34(4): where a Member State's transposing law is infringed as to Article 23 (or Article 21), an essential entity is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher. This is a directive: the figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly.
- Rule
- Higher of
- As of
- 8 September 2026
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The CSIRT or competent authority designated by each EU Member State under Articles 8 and 10 of the Directive, coordinated at Union level through the NIS Cooperation Group and the CSIRTs network.
Settledness
The NIS Cooperation Group adopted common notification templates for Article 23 reporting on 26 May 2026 and the Commission plans to make them mandatory across Member States through an implementing act; no court has construed the reporting duty and none of it is under challenge as of the date shown.
- As of
- 8 September 2026
- Guidance link
- https://digital-strategy.ec.europa.eu/en/news/nis2-cooperation-group-adopts-common-templates-incident-reporting
- Guidance body
- European Commission, on behalf of the NIS Cooperation Group (EU Member States, the European Commission and ENISA)
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 23 requires each Member State to ensure that an essential or important entity notifies its CSIRT, or the competent authority where applicable, of any incident that has a significant impact on the provision of its services, on a three-stage clock: an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and, unless already provided, a final report no later than one month after the incident notification.
Where appropriate, the entity must also notify, without undue delay, the recipients of its services that a significant incident is likely to adversely affect, and must communicate to service recipients potentially affected by a significant cyber threat any measures or remedies they can take. An incident is significant where it has caused or is capable of causing severe operational disruption or financial loss to the entity, or considerable material or non-material damage to another person.
When LexLint raises it
operates_social_platform