Law / European Union

NIS2 Directive, Reporting Obligations

Directive (EU) 2022/2555, Art. 23

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 October 2024.

A vulnerability and incident reporting rule binding public and private bodies.

As of 8 September 2026.

What it requires

  • This duty reaches your service where you qualify as a medium-sized enterprise or larger under the EU size-cap rule and you operate an online marketplace, online search engine or social networking services platform under Annex II, or where you are a public administration entity of central or regional government under Annex I.
  • Notify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
  • Where appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take.
  • Treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to your own operations, or considerable material or non-material damage to another person.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 34(4): where a Member State's transposing law is infringed as to Article 23 (or Article 21), an essential entity is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher. This is a directive: the figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly.

Rule
Higher of
As of
8 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The CSIRT or competent authority designated by each EU Member State under Articles 8 and 10 of the Directive, coordinated at Union level through the NIS Cooperation Group and the CSIRTs network.

Settledness

The NIS Cooperation Group adopted common notification templates for Article 23 reporting on 26 May 2026 and the Commission plans to make them mandatory across Member States through an implementing act; no court has construed the reporting duty and none of it is under challenge as of the date shown.

As of
8 September 2026
Guidance link
https://digital-strategy.ec.europa.eu/en/news/nis2-cooperation-group-adopts-common-templates-incident-reporting
Guidance body
European Commission, on behalf of the NIS Cooperation Group (EU Member States, the European Commission and ENISA)

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 23 requires each Member State to ensure that an essential or important entity notifies its CSIRT, or the competent authority where applicable, of any incident that has a significant impact on the provision of its services, on a three-stage clock: an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and, unless already provided, a final report no later than one month after the incident notification.

Where appropriate, the entity must also notify, without undue delay, the recipients of its services that a significant incident is likely to adversely affect, and must communicate to service recipients potentially affected by a significant cyber threat any measures or remedies they can take. An incident is significant where it has caused or is capable of causing severe operational disruption or financial loss to the entity, or considerable material or non-material damage to another person.

When LexLint raises it

  • operates_social_platform

Read the law

Official Journal text, EUR-Lex, Directive (EU) 2022/2555

Back to the example  ·  Lint your app