Law / European Union

NIS2 Directive, Reporting Obligations

Directive (EU) 2022/2555, Art. 23

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 18 October 2024.

A vulnerability and incident reporting rule binding public and private bodies.

As of 8 September 2026.

What it requires

  • This duty reaches your service where you qualify as a medium-sized enterprise or larger under the EU size-cap rule and you operate an online marketplace, online search engine or social networking services platform under Annex II, or where you are a public administration entity of central or regional government under Annex I.
  • Notify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification.
  • Where appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take.
  • Treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to your own operations, or considerable material or non-material damage to another person.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 34(4): where a Member State's transposing law is infringed as to Article 23 (or Article 21), an essential entity is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher. This is a directive: the figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly.

Rule
Higher of
As of
8 September 2026
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The CSIRT or competent authority designated by each EU Member State under Articles 8 and 10 of the Directive, coordinated at Union level through the NIS Cooperation Group and the CSIRTs network.

Enforcement record

Article 23 is enforced by each Member State's own competent authority or CSIRT under the same Chapter VII (Arts. 31 to 37) supervisory and enforcement measures that apply to Article 21, and no Union-level register or tracker counts the resulting actions. The European Commission's own NIS2 policy page describes the Directive as calling on Member States to define national cybersecurity strategies and collaborate with the EU for cross-border reaction and enforcement, and names the NIS Cooperation Group, the one standing body bringing together Member States, the Commission and ENISA on NIS2 implementation, as an issuer of non-binding guidelines and recommendations. No count, fine total or median penalty for action taken under Article 23 is published anywhere on that page. Enforcement here is national and uncounted at Union level; actions_per_year is left unrecorded rather than estimated across 27 separate national registers.

As of
17 September 2026
Source link
https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

Settledness

The NIS Cooperation Group adopted common notification templates for Article 23 reporting on 26 May 2026 and the Commission plans to make them mandatory across Member States through an implementing act; no court has construed the reporting duty and none of it is under challenge as of the date shown.

As of
8 September 2026
Guidance link
https://digital-strategy.ec.europa.eu/en/news/nis2-cooperation-group-adopts-common-templates-incident-reporting
Guidance body
European Commission, on behalf of the NIS Cooperation Group (EU Member States, the European Commission and ENISA)

What it reaches

Obligation class

Reporting, Security

Also on the record

EEA status

Status
Pending
Source link
https://www.efta.int/eea-lex/32022l2555

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 23 requires each Member State to ensure that an essential or important entity notifies its CSIRT, or the competent authority where applicable, of any incident that has a significant impact on the provision of its services, on a three-stage clock: an early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours, and, unless already provided, a final report no later than one month after the incident notification.

Where appropriate, the entity must also notify, without undue delay, the recipients of its services that a significant incident is likely to adversely affect, and must communicate to service recipients potentially affected by a significant cyber threat any measures or remedies they can take. An incident is significant where it has caused or is capable of causing severe operational disruption or financial loss to the entity, or considerable material or non-material damage to another person.

When LexLint raises it

  • operates_social_platform
  • operates_essential_service

Read the law

Official Journal text, EUR-Lex, Directive (EU) 2022/2555

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app