Skip to content

NIS2 incident reporting timeline: the 24h / 72h / 1-month framework

We already covered which companies are covered by NIS2 in Spain. The question that comes next, and often catches people off guard, is what happens the day a real incident hits: you have 24 hours for the first notification, not for thinking it over.

The 3 stages, with no room for interpretation

Article 23 of NIS2 (Directive EU 2022/2555) sets out the most structured incident reporting framework in EU cybersecurity regulation — considerably stricter than GDPR's single-notification model.

Stage 1 — Early warning, within 24 hours of detection

A brief notice, not a full report: it indicates whether malicious intent is suspected, whether there's potential cross-border impact, and an initial severity assessment. The goal is to get the authority aware fast, not to already have every answer.

Stage 2 — Incident notification, within 72 hours

This is where substance is expected: an initial assessment of severity and impact, plus indicators of compromise (IOCs) if already available. It expands on what was reported in the 24-hour warning.

Stage 3 — Final report, within 1 month of the notification

A detailed description of the incident, root cause, mitigation measures applied, and cross-border impact if any. This formally closes the case with the authority.

What if the incident is still ongoing past the month?

A progress report is submitted at that one-month mark, and the definitive final report is filed within one month of the incident being fully resolved — there's no deadline forcing you to "close" an incident that's genuinely still open, but there is an obligation to keep reporting for as long as it lasts.

Who you notify in Spain

The relevant CSIRT for your sector: INCIBE-CERT for the private sector, CCN-CERT for the public sector. If the incident affects an AI system regulated under the AI Act, AESIA may separately request additional information — two different authorities, two different channels, that can both be triggered by the same incident.

An important nuance on Spain's transposition status

Based on sources available in mid-2026, Spain's NIS2 transposition law remains pending final publication, with the European Commission actively pressing over the delay. This doesn't exempt compliance — NIS2's substantive obligations have applied directly since October 2024, regardless of whether the national law has been published yet.

When NIS2 and GDPR overlap on the same incident

When the incident also involves personal data, both clocks run in parallel from the moment you become aware: the 24-hour warning to your CSIRT under NIS2, and the 72-hour notification to the data protection authority under GDPR Art. 33. They're different authorities, and you need to check your national transposition law to confirm which notification applies to your sector.

Why this can't be figured out on the day it happens

With 24 hours for the first notice, there's no time to decide on the fly who to notify, using what template, or who inside the company has authority to send it. That has to be decided and documented in advance — which is exactly what the NIS2 security policy required under Art. 21 covers.

The procedure, already drafted

The NIS2 Security Policy includes the incident notification procedure with all 3 deadlines already structured, ready for leadership sign-off.

See the NIS2 Security Policy → Am I covered? NIS2 Checklist →