EU incident reportingFile 00 / cover

Four EU regimes. One incident. Different clocks.

NIS2, DORA, the GDPR and the Cyber Resilience Act each impose their own reporting deadline, on their own trigger, to their own authority. A Latvian bank can sit inside three of them in the same week. This is what each one actually says, read from the article.

OffSeq is an incident response and offensive security firm in Riga. It runs the containment, forensics and root-cause work a report has to be built on. It is not a law firm, and it does not file notifications on your behalf.

The four instrumentsFile 01 / instruments

Which one reaches you, and since when

One directive, three regulations, and no single resource that reads them against each other. They bind different populations by design, and more than one of them can bind you at the same moment.

  1. Directive (EU) 2022/2555

    NIS2

    Measures for a high common level of cybersecurity across the Union

    Article 23

    Applies since18 Oct 2024

    Binds
    Essential and important entities in the Annex I and II sectors. Size decides which of the two you are, but not what you file: the Article 23 duty is word for word the same for both, and only supervision differs.
    Trigger
    A significant incident: one that has caused or can cause severe operational disruption of your services or financial loss to you, or that has affected or can affect others by causing considerable material or non-material damage.
    Report to
    Your national CSIRT or, where the Member State so provides, the competent authority, which must forward the notification to the CSIRT on receipt.
  2. Regulation (EU) 2022/2554

    DORA

    Digital operational resilience for the financial sector

    Article 19

    Applies since17 Jan 2025

    Binds
    The twenty financial entity types listed in Article 2(1), points (a) to (t). ICT third-party service providers are in scope of the Regulation under point (u), but Article 2(2) does not make them financial entities, so they carry no Article 19 clock of their own.
    Trigger
    A major ICT-related incident, as classified under Delegated Regulation (EU) 2024/1772. The classification is the trigger, not the incident.
    Report to
    The competent authority under Article 46, which routes the details onward to the ESAs, the ECB where relevant, the NIS2 authorities and CSIRTs, and the resolution authorities.
  3. Regulation (EU) 2016/679

    GDPR

    Protection of natural persons with regard to the processing of personal data

    Articles 33 and 34

    Applies since25 May 2018

    Binds
    Every controller, in every sector, at every size. A processor owes its duty to the controller instead, under Article 33(2), and has no deadline of its own in the Regulation.
    Trigger
    A personal data breach as defined in Article 4(12), which includes loss of availability, so ransomware counts with no exfiltration at all. Unless it is unlikely to result in a risk to natural persons.
    Report to
    The supervisory authority competent under Article 55, or your lead authority under Article 56 for cross-border processing. Also the data subjects themselves, where a high risk is likely.
  4. Regulation (EU) 2024/2847

    CRA

    Horizontal cybersecurity requirements for products with digital elements

    Article 14

    Applies since11 Sep 2026

    Binds
    Manufacturers of connected hardware and software products made available on the EU market, marketed under their own name or trademark, whether sold, monetised or given away free.
    Trigger
    An actively exploited vulnerability in the product, or a severe incident affecting the security of the product as defined in Article 14(5).
    Report to
    The CSIRT designated as coordinator and ENISA, simultaneously, over the single reporting platform ENISA runs under Article 16.

Most of the Cyber Resilience Act only applies from 11 December 2027. Article 71(2) brought Article 14 forward to 11 September 2026, and Article 69(3) then applies it, by derogation, to every in-scope product placed on the market before that later date. The product requirements are still coming; the reporting duty already reached the installed base. Each instrument is linked in full at the foot of this page.

Reporting clock finderFile 02 / worksheet

Which clocks are running, and to whom

Pick what you are and what happened. The worksheet returns every reporting duty that applies, the article it comes from, the authority that receives it, what the filing has to contain, and the order the filings fall in. Nothing is sent anywhere and nothing is stored.

What you are

Choose the description that fits the entity making the report. Where two could fit, the notes under the result explain which one displaces the other.

What happened

Select everything that applies. One event routinely starts several clocks, and the duties people miss are the ones they did not think to tick.

Result

5 reporting duties to assess under NIS2; 3 have a stated time limit. Confirm the role, threshold and trigger shown for each.

The combined rule

  1. +24 h NIS2 Art. 23(4)(a)
  2. +72 h NIS2 Art. 23(4)(b)
  3. +1 month NIS2 Art. 23(4)(d)

Each mark uses its own trigger. Initial filings generally run from awareness or classification. DORA's intermediate report runs from its initial notification; final reports can run from earlier reports or corrective measures. Read the trigger beside each duty.

  1. +24 h

    NIS2Art. 23(4)(a)

    Early warning

    Deadline
    Within 24 hours of becoming aware of the significant incident
    Report to
    Your national CSIRT or, where your Member State so provides, the competent authority.
    Must contain
    Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have a cross-border impact. Nothing more is required at this point.
  2. +72 h

    NIS2Art. 23(4)(b)

    Incident notification

    Deadline
    Within 72 hours of becoming aware of the significant incident
    Report to
    Your national CSIRT or, where your Member State so provides, the competent authority.
    Must contain
    An update to the early warning plus an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise. A trust service provider files this at 24 hours, not 72, where its trust services are affected.
  3. On request

    NIS2Art. 23(4)(c)

    Intermediate report

    Deadline
    On request only when the CSIRT or competent authority asks for one
    Report to
    Your national CSIRT or, where your Member State so provides, the competent authority.
    Must contain
    Relevant status updates. There is no scheduled intermediate report under NIS2.
  4. +1 month

    NIS2Art. 23(4)(d)

    Final report

    Deadline
    Within one month of submitting the 72-hour incident notification
    Report to
    Your national CSIRT or, where your Member State so provides, the competent authority.
    Must contain
    A detailed description including severity and impact; the type of threat or root cause likely to have triggered it; applied and ongoing mitigation measures; and, where applicable, the cross-border impact. If the incident is still running at that point, Art. 23(4)(e) takes a progress report instead and the final report follows within one month of your handling ending.
  5. Undue delay

    NIS2Art. 23(1)

    Notice to your service recipients

    Deadline
    Without undue delay where the incident is likely to adversely affect the provision of your services
    Report to
    The recipients of your services.
    Must contain
    That the significant incident is likely to affect the service. Under Art. 23(2) a significant cyber threat carries a separate duty to tell potentially affected recipients what they can do about it.

Notes on this combination

First decide whether it is significant

The Article 23 chain starts only for a significant incident: one that has caused or is capable of causing severe operational disruption of your services or financial loss to you, or that has affected or is capable of affecting other persons by causing considerable material or non-material damage. If you are a DNS, TLD, cloud, data-centre, CDN, managed service or managed security service provider, an online marketplace, search engine or social platform, or a trust service provider, Implementing Regulation (EU) 2024/2690 fixes the numbers instead – 30 minutes of complete unavailability, EUR 500 000 of direct loss, a successful malicious unauthorised access, and so on.

This is a reading of the articles cited above and nothing more. It is not legal advice, it cannot know your facts, and it deliberately does not name your national channel: NIS2 is a directive, so the recipient and any national addition come from your own transposition. Confirm both with your national CSIRT and your own counsel.

Open the OffSeq incident response service

Interactive mode is not available. You can read the full reference content below. No answers are assessed and no result is calculated.

The worksheet needs JavaScript to filter this catalogue down to your situation. The complete catalogue is below: every reporting duty the four regimes impose, with its article, its deadline, the trigger the deadline runs from, the recipient, and the content required.

  • NIS2 Art. 23(4)(a) – Early warning

    Deadline: Within 24 hours of becoming aware of the significant incident.

    Report to: Your national CSIRT or, where your Member State so provides, the competent authority.

    Must contain: Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have a cross-border impact. Nothing more is required at this point.

  • NIS2 Art. 23(4)(b) – Incident notification

    Deadline: Within 72 hours of becoming aware of the significant incident.

    Report to: Your national CSIRT or, where your Member State so provides, the competent authority.

    Must contain: An update to the early warning plus an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise. A trust service provider files this at 24 hours, not 72, where its trust services are affected.

  • NIS2 Art. 23(4)(c) – Intermediate report

    Deadline: On request only when the CSIRT or competent authority asks for one.

    Report to: Your national CSIRT or, where your Member State so provides, the competent authority.

    Must contain: Relevant status updates. There is no scheduled intermediate report under NIS2.

  • NIS2 Art. 23(4)(d) – Final report

    Deadline: Within one month of submitting the 72-hour incident notification.

    Report to: Your national CSIRT or, where your Member State so provides, the competent authority.

    Must contain: A detailed description including severity and impact; the type of threat or root cause likely to have triggered it; applied and ongoing mitigation measures; and, where applicable, the cross-border impact. If the incident is still running at that point, Art. 23(4)(e) takes a progress report instead and the final report follows within one month of your handling ending.

  • NIS2 Art. 23(1) – Notice to your service recipients

    Deadline: Without undue delay where the incident is likely to adversely affect the provision of your services.

    Report to: The recipients of your services.

    Must contain: That the significant incident is likely to affect the service. Under Art. 23(2) a significant cyber threat carries a separate duty to tell potentially affected recipients what they can do about it.

  • DORA Del. Reg. 2025/301, Art. 5(1)(a) – Initial notification

    Deadline: Within 4 hours of classifying the incident as major, normally capped at 24 hours from awareness. If classification occurs after those 24 hours, Article 5(2) allows four hours from that later classification.

    Report to: The competent authority under DORA Art. 46. A credit institution classified as significant reports to its national authority, which transmits the report to the ECB immediately.

    Must contain: Your incident reference; the date and time of detection and of classification; a description; which of the Articles 1 to 8 criteria of Delegated Regulation (EU) 2024/1772 made it major; the Member States affected; how it was discovered; where available its origin; and whether the business continuity plan has been activated.

  • DORA Del. Reg. 2025/301, Art. 5(1)(b) – Intermediate report

    Deadline: Within 72 hours of submitting the initial notification, even where nothing about the incident has changed.

    Report to: The same competent authority.

    Must contain: When it occurred and, where applicable, when regular activities were recovered; how the 2024/1772 criteria were met; the incident type; the threat actor techniques where applicable; affected functional areas, business processes and infrastructure; the impact on clients' financial interests; which other authorities you have reported to; temporary measures; and indicators of compromise. Update it without undue delay, and in any case once regular activities are back.

  • DORA Del. Reg. 2025/301, Art. 5(1)(c) – Final report

    Deadline: Within one month of the intermediate report, or of the last updated intermediate report.

    Report to: The same competent authority.

    Must contain: Root causes; when the incident was resolved and the root cause addressed; how it was resolved; anything relevant for resolution authorities; direct and indirect costs and losses without netting recoveries, plus the recoveries themselves; and any recurrence.

  • DORA DORA Art. 19(3) – Notice to clients

    Deadline: Without undue delay as soon as you become aware, where the major incident affects clients' financial interests.

    Report to: The clients concerned.

    Must contain: The incident, and the measures taken to mitigate its adverse effects.

  • GDPR Art. 33(1) – Notification to the supervisory authority

    Deadline: Without undue delay and, where feasible, within 72 hours of having become aware of the breach – unless it is unlikely to result in a risk to the rights and freedoms of natural persons.

    Report to: The supervisory authority competent under Art. 55; for cross-border processing, your lead authority under Art. 56.

    Must contain: The nature of the breach with the categories and approximate numbers of data subjects and of records; the data protection officer or other contact point; the likely consequences; and the measures taken or proposed, including mitigation. Art. 33(4) lets you supply this in phases; a notification later than 72 hours must carry reasons for the delay.

  • GDPR Art. 34(1) – Communication to data subjects

    Deadline: Without undue delay once the breach is likely to result in a HIGH risk to the rights and freedoms of natural persons. No hour count attaches to this one.

    Report to: The affected data subjects.

    Must contain: In clear and plain language: the nature of the breach, the DPO contact, the likely consequences and the measures taken. Art. 34(3) removes the duty where the data were rendered unintelligible, for example by encryption; where later measures mean the high risk is no longer likely; or where it would take disproportionate effort, in which case a public communication takes its place.

  • GDPR Art. 33(2) – Notification to the controller

    Deadline: Without undue delay after becoming aware of the personal data breach.

    Report to: The controller you process for.

    Must contain: Enough for the controller to run its own Art. 33 assessment on its own 72-hour clock. The Regulation sets no hour count for a processor; your Art. 28 processing agreement almost certainly does.

  • GDPR Art. 33(5) – Internal record of the breach

    Deadline: Continuously for every breach, including those you decide not to notify, from the moment you become aware.

    Report to: Your own breach register.

    Must contain: The facts of the breach, its effects and the remedial action taken, in enough detail for the supervisory authority to verify your decision. This is the document that defends a decision not to notify.

  • CRA Art. 14(2)(a) – Early warning – exploited vulnerability

    Deadline: Within 24 hours of becoming aware of the actively exploited vulnerability.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: Where applicable, the Member States on whose territory you are aware the product has been made available.

  • CRA Art. 14(2)(b) – Vulnerability notification

    Deadline: Within 72 hours of becoming aware of the actively exploited vulnerability.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: General information as available about the product; the general nature of the exploit and of the vulnerability; any corrective or mitigating measures taken and any that users can take; and, where applicable, how sensitive you consider the notified information to be.

  • CRA Art. 14(2)(c) – Final report – exploited vulnerability

    Deadline: No later than 14 days after a corrective or mitigating measure is available – not after the notification.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: A description of the vulnerability including severity and impact; where available, information on any malicious actor that exploited it; and details of the security update or other corrective measures made available.

  • CRA Art. 14(4)(a) – Early warning – severe incident

    Deadline: Within 24 hours of becoming aware of the severe incident affecting the product's security.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: At least whether the incident is suspected of being caused by unlawful or malicious acts, and where applicable the Member States where the product has been made available.

  • CRA Art. 14(4)(b) – Incident notification

    Deadline: Within 72 hours of becoming aware of the severe incident.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: General information on the nature of the incident, an initial assessment, corrective or mitigating measures taken and those users can take, and your sensitivity marking.

  • CRA Art. 14(4)(c) – Final report – severe incident

    Deadline: Within one month of submitting the 72-hour incident notification.

    Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).

    Must contain: A detailed description including severity and impact; the type of threat or root cause likely to have triggered it; and applied and ongoing mitigation measures.

  • CRA Art. 14(8) – Notice to product users

    Deadline: After becoming aware of the exploited vulnerability or the severe incident.

    Report to: Impacted users of the product, and where appropriate all users.

    Must contain: The vulnerability or incident and, where necessary, the risk mitigation and corrective measures users can deploy – where appropriate in a structured, machine-readable format. If you do not tell users in time, the notified CSIRTs may do it for you.

A duty is listed here whether or not it applies to you. The four guides set out which populations each regime reaches, and the NIS2 and DORA guides explain which one displaces the other for a financial entity.

The combined ruleFile 03 / the rule

Every deadline the four regimes impose, in order

Five marks carry all of it. Three of the four regimes want something inside 24 hours, and every 72-hour milestone is reachable if the first one was made. Read each mark together with the trigger printed under it.

  1. +4 h

    from classifying the incident as major

    • DORA Initial notification Del. Reg. 2025/301, Art. 5(1)(a)
  2. +24 h

    from becoming aware

    • NIS2 Early warning Art. 23(4)(a)
    • CRA Early warning, exploited vulnerability Art. 14(2)(a)
    • CRA Early warning, severe incident Art. 14(4)(a)
    • DORA Outer limit for the initial notification Del. Reg. 2025/301, Art. 5(1)(a)
  3. +72 h

    from becoming aware, except DORA, which runs from its own initial notification

    • NIS2 Incident notification Art. 23(4)(b)
    • GDPR Notification to the supervisory authority Art. 33(1)
    • CRA Vulnerability notification Art. 14(2)(b)
    • CRA Incident notification Art. 14(4)(b)
    • DORA Intermediate report Del. Reg. 2025/301, Art. 5(1)(b)
  4. +14 days

    from a corrective or mitigating measure becoming available

    • CRA Final report on the exploited vulnerability Art. 14(2)(c)
  5. +1 month

    from the 72-hour filing, or from the last intermediate report

    • NIS2 Final report, or a progress report if it is still running Art. 23(4)(d) and (e)
    • DORA Final report Del. Reg. 2025/301, Art. 5(1)(c)
    • CRA Final report on the severe incident Art. 14(4)(c)

Three duties sit off the rule because no hour count attaches to them: the GDPR communication to data subjects under Article 34(1), due without undue delay whenever a high risk is likely; the NIS2 notice to service recipients under Article 23(1); and the DORA notice to clients under Article 19(3). Two exceptions move a mark: a trust service provider files the NIS2 notification at 24 hours rather than 72 where its trust services are affected, and Article 5(4) of Delegated Regulation (EU) 2025/301 lets most financial entities file by noon of the next working day where a deadline falls on a weekend or bank holiday.

One incident, several clocksFile 04 / interaction

Four rules that decide which clocks are actually yours

The instruments were drafted separately and overlap on purpose. Four rules settle almost every case, and the first of them is the one most often got wrong in the wrong direction.

  1. DORA displaces NIS2 for a financial entity

    DORA Article 1(2) declares the Regulation a sector-specific Union legal act for the purposes of NIS2 Article 4. Article 4(1) of the Directive then disapplies the relevant NIS2 provisions for those entities, supervision and enforcement included. A bank does not run a parallel Article 23 chain for the same incident. It files under DORA, and its competent authority routes the details to the NIS2 CSIRT and single point of contact itself. Filing twice is not caution; it is a second set of facts to keep consistent while you are busy.

    DORA Art. 1(2) · NIS2 Art. 4(1) and 4(2)

  2. The GDPR is never displaced

    NIS2 Article 2(12) states in terms that the Directive applies without prejudice to Regulation (EU) 2016/679, and nothing in DORA or the CRA carves the GDPR out either. If personal data are in the incident, the Article 33 clock runs in addition to everything else, to a different authority, on its own 72 hours, with its own content requirements. It is the one clock that reaches every entity type on this page.

    NIS2 Art. 2(12) · GDPR Art. 33(1)

  3. The CRA sits on the product, not on the operator

    NIS2 and DORA regulate the security of the services you operate. CRA Article 14 regulates the products you place on the market. A great many companies are both, and then a single week carries an operator clock running to your own national CSIRT and a manufacturer clock running to the coordinator CSIRT and ENISA together, on different facts, with different content.

    CRA Art. 14(1) and 14(3) · Art. 16(1)

  4. The clocks do not start together

    NIS2 and the CRA run from becoming aware. The GDPR runs from having become aware. DORA's first filing runs from classification and is capped at 24 hours from awareness, so an entity that takes twenty hours to classify has four hours left, and one that classifies on day three has four hours from that moment under Article 5(2). An incident timeline with a single start time will mis-state at least one deadline.

    NIS2 Art. 23(4) · GDPR Art. 33(1) · Del. Reg. 2025/301, Art. 5(1)(a) and 5(2)

What the authorities must tell each other
ProvisionWho tells whomWhen
NIS2 Art. 35(1)The NIS2 competent authority tells the GDPR supervisory authority under Art. 55 or 56Without undue delay, where it becomes aware in supervision or enforcement that an Article 21 or 23 infringement can entail a personal data breach notifiable under GDPR Article 33
NIS2 Art. 35(2)Neither authority fines you twice for the same conductWhere the GDPR authority has imposed a fine under Article 58(2)(i), the NIS2 authority may not impose one under Article 34 for the same conduct. Its other enforcement measures remain available
DORA Art. 19(6)The financial competent authority tells the ESAs, the ECB, the NIS2 authorities, single points of contact and CSIRTs, the resolution authorities and the SRBIn a timely manner, on receipt of the initial notification and of each report
CRA Art. 16(2)The coordinator CSIRT that received the notification tells the CSIRTs of every Member State where the manufacturer said the product was made availableWithout delay, unless dissemination is delayed on justified cybersecurity grounds for a strictly necessary period
CRA Art. 16(3)The coordinator CSIRTs tell their national market surveillance authoritiesAs needed for those authorities to fulfil their obligations under the Regulation
The traffic runs one way. An authority passing your report to another authority does not discharge your own duty to either of them, and it does not stop the second clock.

Where the national channel differsFile 05 / transposition

Two Member States, two different first phone calls

NIS2 is a directive. It fixes the hours and leaves the recipient, the channel and any national addition to each Member State. Latvia and Finland both transposed it faithfully, and ended up with different answers to the only question that matters at hour one.

Nacionālās kiberdrošības likums, Article 34

Latvia

Early warning
24 hours, submitted electronically
Initial report
72 hours. A trust service provider files at 24 hours
Final report
One month after the initial report. An intermediate report on request; a progress report if it is still unresolved at that point
Goes to
The competent cyber incident response institution. For private legal persons that is the Institute of Mathematics and Computer Science of the University of Latvia, which operates CERT.LV. Defence bodies report to the Military Intelligence and Security Service instead
Contact point
The National Cyber Security Centre, within the Ministry of Defence
In force
Article 34(2) to (5) has applied since 1 July 2025

The national addition: Article 34(1) requires an entity that detects any cyber incident, significant or not, to inform the competent incident response institution immediately and to follow the instructions it gives. An owner or lawful possessor of ICT critical infrastructure must also inform the competent state security institution. The Directive has no equivalent duty.

Kyberturvallisuuslaki 124/2025, sections 11 to 13

Finland

Early warning
24 hours from detecting the significant incident
Follow-up
72 hours from detection. A trust service provider files at 24 hours where its trust services are affected
Final report
One month after the follow-up notification, or one month after handling ends for a long-lasting incident, which also carries an interim report at one month
Goes to
Your sector supervisory authority, not the CSIRT. Section 17 then requires the supervisor to pass the notification to the CSIRT unit immediately
Contact point
Traficom's National Cyber Security Centre, which is also where the CSIRT unit sits
In force
8 April 2025

The national addition: section 33 requires the supervisory authority itself to notify the Data Protection Ombudsman where it learns that a failure of the Chapter 2 duties may lead, or has led, to a personal data breach notifiable under GDPR Article 33, including where the competent GDPR authority sits in another Member State.

What this site will not tell you

Estonia and Lithuania are not covered here. Their statutes are published on portals this site could not read as text, and a deadline reproduced from memory is worse than no deadline at all. Ask your national CSIRT for both the hours and the channel. Where the instrument is a regulation rather than a directive – DORA, the GDPR and the Cyber Resilience Act – the text is identical in every Member State and only the authority is national.

QuestionsFile 07 / questions

The questions that decide the first day

Answers are read from the article named in each one. Where an instrument leaves the answer to national law, that is said rather than guessed.

Does a bank report the same incident under both NIS2 and DORA?
No. DORA Article 1(2) declares the Regulation a sector-specific Union legal act for the purposes of NIS2 Article 4, and Article 4(1) of the Directive then disapplies the relevant NIS2 provisions for financial entities identified as essential or important. The bank files under DORA. Its competent authority is required by DORA Article 19(6)(c) to pass the details to the NIS2 competent authorities, single points of contact and CSIRTs itself. The GDPR still runs separately if personal data are involved.
When exactly does the GDPR 72-hour clock start, and when can I skip the notification?
Article 33(1) runs from having become aware of the personal data breach, and requires notification without undue delay and, where feasible, within 72 hours. You may skip it only where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. That is a negative test and the default is to notify: you need a positive, recorded conclusion that a risk is unlikely, not merely the absence of evidence that one is likely. Article 33(5) requires you to document the breach and that reasoning either way.
Is ransomware a personal data breach if nothing was stolen?
Usually yes. Article 4(12) defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Loss of availability is expressly inside that definition, so encrypting a database engages the Article 33 assessment whether or not anything left the network. Whether you then notify depends on the Article 33(1) risk test, not on whether exfiltration occurred.
What has to be in the 24-hour early warning?
Very little, deliberately. NIS2 Article 23(4)(a) asks only that the early warning indicate, where applicable, whether the significant incident is suspected of being caused by unlawful or malicious acts and whether it could have a cross-border impact. CRA Article 14(2)(a) asks for the Member States where you know the product has been made available. Neither requires a diagnosis. The first filing is a flag, not a report.
DORA says four hours. Four hours from what?
From classification. Article 5(1)(a) of Delegated Regulation (EU) 2025/301 requires the initial notification as early as possible and in any case within four hours of classifying the incident as a major ICT-related incident, and no later than 24 hours from the moment the entity became aware of it. Article 5(2) covers the late case: if you classify it as major more than 24 hours after becoming aware, the four hours run from that classification.
What makes a DORA incident major?
Article 8(1) of Delegated Regulation (EU) 2024/1772: the incident must have affected critical services, and then either the data-loss threshold in Article 9(5)(b) is met on its own, which is any successful, malicious and unauthorised access that may result in data losses, or two or more of the other thresholds are met. Those others are 10 per cent of clients or 100 000 clients, 30 per cent of financial counterparts, 10 per cent of daily transactions by number or value, any reputational trigger, duration over 24 hours or downtime over two hours on a critical function, impact in two or more Member States, and costs and losses over 100 000 euro.
Does the Cyber Resilience Act already apply?
Article 14 does. The Regulation as a whole applies from 11 December 2027, but Article 71(2) brings Article 14 forward to 11 September 2026, and Article 69(3) applies it by derogation to every in-scope product placed on the market before 11 December 2027. So the reporting duty covers products you shipped years ago, while the product requirements that would have prevented the vulnerability are still to come.
My ICT provider was breached. Do they report under DORA?
Not under Article 19. ICT third-party service providers are in scope of DORA under Article 2(1)(u), but Article 2(2) defines financial entities as points (a) to (t) only, and Article 19 obliges financial entities. The provider's duties run through the contract: Article 30(2)(f) requires it to assist you at no additional cost or at a cost fixed in advance when an ICT incident related to its service occurs, and Article 30(2)(g) requires full cooperation with your competent and resolution authorities. It may separately be a NIS2 managed service provider with its own Article 23 clock.
Who receives a NIS2 report, and is that the same everywhere?
No. Article 23(1) lets each Member State choose between its CSIRT and its competent authority, and where the authority receives it the Member State must ensure it is forwarded to the CSIRT. Latvia routes reports from private entities to the cyber incident response institution, which for private legal persons is the Institute of Mathematics and Computer Science of the University of Latvia, operating CERT.LV. Finland routes them to the sector supervisory authority, which section 17 then requires to pass them to the CSIRT unit at Traficom. A group operating in both must maintain both channels.
Which single deadline should a response plan be built around?
Start with the earliest applicable deadline and its trigger. Several regimes have a 24-hour early filing, while DORA normally requires an initial notification within four hours of classification, capped at 24 hours from awareness; Article 5(2) covers later classification. Prepare later reports in parallel. Early filing does not guarantee the next deadline will be met, and incomplete facts should be identified and updated through the applicable reporting process.

Before the clock starts

Several initial reporting deadlines run from awareness, while others depend on classification, earlier reports or corrective measures. Detection, documented decisions and prepared reporting processes all matter. These OffSeq engagements help teams identify incidents and prepare their response.

Sources

  1. Directive (EU) 2022/2555 (NIS2), Article 23 EUR-Lex · 2022 The 24-hour early warning, the 72-hour notification, the intermediate report on request, the one-month final report and the progress report, plus the significance test in Article 23(3) and the sector-specific act rule in Article 4.
  2. Regulation (EU) 2022/2554 (DORA), Articles 19 and 20 EUR-Lex · 2022 The reporting obligation, the scope list in Article 2, the lex specialis declaration in Article 1(2), the competent authorities in Article 46 and the contractual duties of ICT providers in Article 30.
  3. Commission Delegated Regulation (EU) 2025/301 EUR-Lex · 2025 The DORA time limits in Article 5, and the content of the initial notification and the intermediate and final reports in Articles 1 to 4.
  4. Commission Delegated Regulation (EU) 2024/1772 EUR-Lex · 2024 The classification criteria and materiality thresholds that decide when a DORA incident is major, and therefore when the four-hour clock starts.
  5. Regulation (EU) 2016/679 (GDPR), Articles 33 and 34 EUR-Lex · 2016 The 72-hour notification and its unless-unlikely test, the phased-information allowance, the documentation duty, and the separate high-risk threshold for telling data subjects.
  6. Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14 and 16 EUR-Lex · 2024 The 24-hour, 72-hour, 14-day and one-month duties, the severity test in Article 14(5), the single reporting platform, and the application dates in Articles 69(3) and 71(2).
  7. Commission Implementing Regulation (EU) 2024/2690 EUR-Lex · 2024 The numeric significance thresholds for DNS, TLD, cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines, social platforms and trust service providers.
  8. Nacionālās kiberdrošības likums (National Cyber Security Law), Latvia Likumi.lv · 2024 Article 34 for the Latvian reporting chain and the national duty to report every incident; Article 9(2) for the receiving institutions; transitional provision 11 for the 1 July 2025 start.
  9. Kyberturvallisuuslaki 124/2025 (Cybersecurity Act), Finland Finlex · 2025 Sections 11 to 13 for the Finnish reporting chain, section 17 for the forwarding duty to the CSIRT unit, section 33 for the notification to the Data Protection Ombudsman, and section 47 for the 8 April 2025 entry into force.