NISG 2026 course All courses

Lesson 5.2 · 6 min

24 hours, 72 hours, one month

Open in the coursewith narrated slides, a checklist to tick off and a quiz

At a glance

In detail

To whom

Significant incidents must be reported without undue delay to the competent sector-specific CSIRT, or where there is none to the national CSIRT; the CSIRT passes the report on to the authority § 34(1) NISG 2026. Since 1 October 2026 these are the GovCERT for the public administration, the HealthCERT for healthcare and the national CSIRT for everyone else; an entity active in several sectors reports to each competent CSIRT (Federal Office, CSIRTs).

The stages

WhatWhenContent
Early warning § 34(2) no. 1without undue delay, within 24 hours of becoming awarewhere applicable: whether unlawful or malicious acts are suspected, possible cross-border impact
Notification no. 2without undue delay, within 72 hours of becoming aware (24 hours for trust services)update of the early warning; initial assessment with severity and impact; indicators of compromise where available
Intermediate report no. 3on request of the CSIRT or the authorityrelevant status updates
Final report no. 4within one month of the notificationdetailed description with severity and impact; type of threat and likely root cause; remedies applied and ongoing; cross-border impact
Progress report no. 5instead of the final report if the incident is still ongoingstatus; the final report follows within one month of the end of incident handling

In addition, all information must be sent that lets the CSIRT and the authority determine whether the incident has cross-border impact § 34(2) NISG 2026.

How, in practice

Reports go through the NIS2-Services application in the USP. If the reporting portal is temporarily unavailable, the Federal Office provides forms for each type of report. According to the Federal Office (reporting duty and deadlines):

The deadlines run from becoming aware, at weekends too, and even if you don't provide services at weekends (Federal Office, FAQ on reporting). A third party such as your IT provider can report on your behalf if authorised (notes on the NISV 2026). If supplier and customer are both covered and the incident is significant for both, both report (FAQ).

What the CSIRT gives back

Within 24 hours of the early warning, the CSIRT responds with initial feedback and, on request, guidance or operational advice; on request it gives additional technical support, and if a crime is suspected it gives guidance on reporting it to the police § 34(4) NISG 2026.

The recipients of your services

If the incident affects the provision of your service, inform its recipients without undue delay and tell them, where possible, what measures they can take themselves § 34(3) NISG 2026. Failing to report or inform risks the high fine range § 45(1) nos. 4 and 5 NISG 2026.

Checklist

Quiz

By when must the early warning be sent?

  1. Only once the cause is known
  2. Within 72 hours of the start of the incident
  3. On the next working day
  4. Without undue delay, within 24 hours of becoming aware, weekends included
Show the answer

The answer is D: Without undue delay, within 24 hours of becoming aware, weekends included. § 34(2) no. 1 NISG 2026; according to the Federal Office (FAQ on reporting) the deadline runs at weekends too.

Sources

This lesson's statements rest on:

Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.