Lesson 5.2 · 6 min
24 hours, 72 hours, one month
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- The early warning. Without undue delay, within 24 hours of becoming aware of the significant incident: short, saying whether a crime or cross-border effects are suspected.
- The notification. Within 72 hours of becoming aware: an initial assessment with severity and impact, and the indicators of compromise where available.
- The final report. Within one month of the notification: a detailed description, type of threat, root cause, remedies and cross-border effects. If the incident is ongoing, a progress report.
- To the CSIRT, through the USP. To the competent sectoral CSIRT, otherwise the national one. Through NIS2-Services in the USP; if the portal is down, with the Federal Office's forms.
- Inform the recipients of your services. If the incident affects your service, inform its recipients without undue delay, including what they can do themselves.
In detail
To whom
Significant incidents must be reported without undue delay to the competent sector-specific CSIRT, or where there is none to the national CSIRT; the CSIRT passes the report on to the authority § 34(1) NISG 2026. Since 1 October 2026 these are the GovCERT for the public administration, the HealthCERT for healthcare and the national CSIRT for everyone else; an entity active in several sectors reports to each competent CSIRT (Federal Office, CSIRTs).
The stages
| What | When | Content |
|---|---|---|
| Early warning § 34(2) no. 1 | without undue delay, within 24 hours of becoming aware | where applicable: whether unlawful or malicious acts are suspected, possible cross-border impact |
| Notification no. 2 | without undue delay, within 72 hours of becoming aware (24 hours for trust services) | update of the early warning; initial assessment with severity and impact; indicators of compromise where available |
| Intermediate report no. 3 | on request of the CSIRT or the authority | relevant status updates |
| Final report no. 4 | within one month of the notification | detailed description with severity and impact; type of threat and likely root cause; remedies applied and ongoing; cross-border impact |
| Progress report no. 5 | instead of the final report if the incident is still ongoing | status; the final report follows within one month of the end of incident handling |
In addition, all information must be sent that lets the CSIRT and the authority determine whether the incident has cross-border impact § 34(2) NISG 2026.
How, in practice
Reports go through the NIS2-Services application in the USP. If the reporting portal is temporarily unavailable, the Federal Office provides forms for each type of report. According to the Federal Office (reporting duty and deadlines):
- The early warning and the notification can each be sent only once; if the notification's information is already available within 24 hours, the notification can be sent straight away, without an early warning.
- A final report can meet all duties at once if everything is available within the deadlines and the incident is closed. But waiting in order to avoid an early warning and notification is not reporting without undue delay.
- If the basis falls away, for instance because the incident turns out not to be significant, the report can be withdrawn as long as no final report has been filed.
The deadlines run from becoming aware, at weekends too, and even if you don't provide services at weekends (Federal Office, FAQ on reporting). A third party such as your IT provider can report on your behalf if authorised (notes on the NISV 2026). If supplier and customer are both covered and the incident is significant for both, both report (FAQ).
What the CSIRT gives back
Within 24 hours of the early warning, the CSIRT responds with initial feedback and, on request, guidance or operational advice; on request it gives additional technical support, and if a crime is suspected it gives guidance on reporting it to the police § 34(4) NISG 2026.
The recipients of your services
If the incident affects the provision of your service, inform its recipients without undue delay and tell them, where possible, what measures they can take themselves § 34(3) NISG 2026. Failing to report or inform risks the high fine range § 45(1) nos. 4 and 5 NISG 2026.
Checklist
- We know which CSIRT is ours, and have tested the way into NIS2-Services in the USP.
- Who reports, and who does it at weekends, is settled; the logins work.
- The Federal Office's forms for a portal outage are at hand, offline too.
- Our template for informing customers is ready.
- Our IT provider knows it must tell us about incidents at once, and whether it may report for us.
Quiz
By when must the early warning be sent?
- Only once the cause is known
- Within 72 hours of the start of the incident
- On the next working day
- Without undue delay, within 24 hours of becoming aware, weekends included
Show the answer
The answer is D: Without undue delay, within 24 hours of becoming aware, weekends included. § 34(2) no. 1 NISG 2026; according to the Federal Office (FAQ on reporting) the deadline runs at weekends too.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 34, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 45, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Federal Office for Cyber Security: reporting duty and deadlines, in German (read on 6 October 2026)
- Federal Office for Cyber Security: computer emergency response teams (CSIRTs), in German (read on 6 October 2026)
- Federal Office for Cyber Security, FAQ: reporting, in German (read on 6 October 2026)
- Explanatory notes to the NISV 2026, PDF, in German
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.