MB Bluejuice
Security

How to report a cyber incident to the national CSIRT

Who must report, within what deadlines and what information you will need. A practical checklist.

· updated 2026-10-07

The duty to report depends on the entity. For public sector bodies and entities in scope of NIS2 it is set out in law; for others reporting is voluntary but often useful.

NIS2 deadlines

  • 24 hours — early warning: what happened, whether unlawful action is suspected, whether cross-border impact is possible.
  • 72 hours — incident notification: initial assessment of severity and impact, indicators of compromise.
  • 1 month — final report: root cause, impact, measures taken and planned.

The clock starts when the entity became aware of a significant incident — not when the incident began.

Information you will need

  • Date and time of detection and how it was noticed.
  • Affected systems and services, and how long they were unavailable.
  • The entry vector, if already established.
  • Whether personal data was reached, which categories and roughly how many people.
  • Measures applied and the current state.

A separate duty for personal data

If personal data leaked, the duty to notify the data protection authority is assessed separately under the GDPR, on its own timeline. Two different notifications, even though the underlying facts are the same.

We prepare drafts of both, with a timeline and impact assessment — the entity decides whether to submit. More: incident response.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.