NIS2 incident reporting: 24 hours, 72 hours, 1 month
Published:
Short answer: if your organisation is in scope of Law 5160/2024 and a significant incident occurs, you must notify the National Cybersecurity Authority in stages: an early warning without undue delay and within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the notification or the “closing” of the incident. The deadlines run from the moment you become aware of the significant incident.
What counts as a “significant incident”
An incident is any event that compromises the availability, integrity or confidentiality of data or of services offered through network and information systems. It is significant when it has caused or may cause serious operational disruption of services or financial loss to the entity, or when it has affected or may affect other natural or legal persons by causing significant material or non-material damage. Mandatory reporting concerns significant incidents, not every event.
The reporting stages
| Stage | Deadline | What it contains |
|---|---|---|
| Early warning | Without undue delay and within 24 hours | States whether it is suspected that the incident was caused by unlawful or malicious acts or could have a cross-border impact |
| Incident notification | Without undue delay and within 72 hours | Updates the information and includes an initial assessment: severity, impact and, where available, indicators of compromise |
| Intermediate report | Upon request of the Authority | Updates on the status |
| Final report | No later than one month after the notification or the “closing” of the incident | Completes the reporting of the incident |
Source: the Authority’s guide “The NIS2 Directive in Greece” (in Greek).
Where and how to report
The Authority has an “Incident Reporting” page with the current procedure. On its contact page it states that security incidents are reported by sending the relevant form to incident@cyber.gov.gr. The procedure may change, so always use the Authority’s up-to-date page.
Who reports
The entity itself makes the notification. According to the Authority’s guide, the ICT Systems Security Officer (Y.A.S.P.E.) is the point of contact and cooperates with the Authority and the competent CSIRT. Top management remains responsible for choosing and applying the measures, for being informed about potential incidents and for providing the information required by the Authority.
What to have ready before it happens (our own practical advice)
- Decide in advance who decides whether an incident is significant, and who stands in for them. The 24 hours do not wait.
- Note the exact time you became aware of the incident. The deadlines run from there.
- Keep a contact list ready: the security officer, management, your IT or security provider, legal counsel, your insurer.
- Prepare a template for the first warning, so you can quickly write what you know and what you do not yet, and whether malicious action or cross-border impact is suspected.
- Preserve logs and evidence so they are available for the notification and the final report.
- Test the procedure in an exercise, at least once a year.
And the GDPR?
If personal data was also breached, there is a separate obligation towards the Data Protection Authority (GDPR, Article 33), usually without undue delay and, where feasible, within 72 hours. The two notifications are independent of each other.
Frequently asked questions
When does the 24-hour deadline start?
From the moment the entity becomes aware of the significant incident, according to the Authority’s guide.
Do I report every security incident?
Mandatory reporting to the Authority concerns significant incidents, meaning those that have caused or may cause serious operational disruption or financial loss to the entity, or significant damage to others. The assessment must be made promptly.
Does reporting apply to small businesses?
It applies to entities in scope of Law 5160/2024. Most small and micro businesses are not in scope, except in certain cases regardless of size. See the scope check tool.