NIS2 24-Hour Early Warning: Only Two Facts Are Required — Here’s What to Write
The 24-hour early warning is the shortest report NIS2 will ever ask you for, and the one most teams over-prepare. Article 23(4)(a) names exactly two things it must indicate — and qualifies both with the words “where applicable.” Everything else on a typical early-warning checklist comes from somewhere other than that provision: from the 72-hour notification, from your national portal’s form design, or from a consultant’s idea of what looks thorough.
That distinction matters at 3 a.m. on day one, when the question is not what would be good to send but what you can legally send while you still know almost nothing.
What Article 23(4)(a) Actually Says
Essential and important entities must submit, to their CSIRT or competent authority:
“without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact”
Free DownloadGet the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
As a content specification it names two indications: whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have a cross-border impact.
Article 23 requires no root-cause analysis, impact quantification, indicators of compromise, or systems inventory at the 24-hour mark. Those belong to Article 23(4)(b) — the 72-hour notification, where “an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise” first appears in the Directive’s text.
One duty does sit outside 23(4)(a) and is routinely missed. Article 23(1) obliges Member States to ensure entities report “inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident.” That duty attaches to the notification as a whole, is not qualified the way 23(4)(a) is, and is why cross-border questions appear on the very first form.
Recital 102 backs the minimalism: the early warning “should only include the information necessary to make the CSIRT… aware of the significant incident,” and the obligation to submit it “does not divert the notifying entity’s resources from activities related to incident handling that should be prioritised.” Recitals are interpretive and create no obligation — but they signal that a thin early warning is the design, not a failure to meet it.
The Two Words That Change the Obligation: “Where Applicable”
In plain terms: you must indicate what you suspect, not establish what is true.
“Where applicable” attaches to both indications, and it means the obligation bites where the question is live for your incident. If nothing about the event suggests a cross-border dimension — a single-site failure in one Member State, no shared infrastructure, no customers abroad — you are not obliged to manufacture an analysis. What the qualifier does not do is licence silence when you hold a view: if your SOC has already flagged the traffic as hostile, “we did not have time to assess maliciousness” is not an available position 24 hours later.
Hence the distinction most compliance teams never draw. The Directive asks for your current belief, not your verified conclusion — sharply different evidentiary costs, and only one is achievable inside a day.
The Directive Asks for Two Things. Your National Form Asks for Far More.
This is the gap that catches teams who prepared against the Directive text alone. NIS2 sets the floor; Member States build the plumbing, and the plumbing is a web form with mandatory fields. Two national examples, both from competent authorities’ own published guidance:
| Source of the requirement | What it asks for at the 24-hour stage |
|---|---|
| Directive 2022/2555, Art. 23(4)(a) | Two indications, both “where applicable”: suspected unlawful/malicious cause; possible cross-border impact. |
| Belgium — CCB online form (per the CCB’s NIS2 Notification Guide v1.2, Oct 2024) | Roughly seventeen mandatory fields, including entity type (essential/important), sector, incident type, malicious intent, cross-border impact, free-text incident description, severity assessment, consequences, root cause, whether the incident is resolved, whether CCB support is needed, plus organisation name, email and phone. Each free-text field is capped at 500 characters. |
| Germany — BSI Erstmeldung (§32 BSIG) | Incident classification, reporting reason and situation assessment, a preliminary description of the disruption, its effects, expected duration and suspected or actual cause, timing of occurrence and discovery, affected sectors, suspicion of malicious intent, potential cross-border spread, measures already taken, whether the incident is under control, and contact details. |
Two things follow. Prepare against your national form, not against Article 23(4)(a) — the Article is the floor, the form is the actual test. And the forms are built for partial answers: Belgium’s guide states that at the early-warning stage a severity or consequence assessment “may be very brief and/or partial,” and the 500-character caps make anything else impossible. Germany’s BSI puts it as a principle — Schnelligkeit vor Vollständigkeit, speed before completeness — and confirms that follow-up reports and corrections are possible at any time. Our directory of national CSIRT notification portals covers where to file across eight Member States.
What to Write When You Do Not Know the Cause or the Scope
Start with the answer the Belgian authority supplies itself. On both fields that mirror Article 23(4)(a) — malicious intent and cross-border impact — the CCB’s notification guide instructs: “If you do not know or are not convinced, please tick ‘Uncertain’” and “If you do not know or are not sure, tick ‘Uncertain’.” Uncertainty is a sanctioned answer on the form itself — not a gap you have to talk your way around.
The free-text fields are the harder problem: you need sentences that are true at hour six, that do not foreclose findings you have not made, and that fit inside 500 characters. The patterns below are practical drafting guidance built from the field definitions above — not regulatory text, and no authority has blessed a specific form of words. Adapt them to your facts.
| Field | Language that works when you do not yet know |
|---|---|
| Incident description | “At [time, timezone] on [date], [system/service] became [unavailable/degraded/anomalous]. Detected by [source]. Investigation opened at [time]. Cause not yet established. Affected scope under assessment; this description will be updated in the 72-hour notification.” |
| Suspected cause / root cause | “Not established at time of submission. Working hypotheses under investigation; no hypothesis confirmed. Update to follow.” Where you do have a view: “Preliminary indications are consistent with [X]; not confirmed.” |
| Malicious intent | Tick “Uncertain” unless you have grounds. Where you have grounds: “Suspected. Based on [observed indicator]. Attribution not assessed.” |
| Severity | “Preliminary and partial. [Service] unavailable to [approximate population] since [time]. Severity assessment ongoing; figures are estimates subject to revision.” |
| Consequences / impact | “Assessment in progress. Confirmed to date: [what you actually know]. Not yet assessed: [data exposure / third-party impact / duration].” |
| Cross-border impact | Tick “Uncertain” where unknown. If services reach other Member States, say so as a fact even when the impact is unquantified: “Uncertain. Entity serves recipients in [countries]; potential impact not yet assessed.” |
The shared structure is what makes these sentences safe: state what is established, state what is not yet assessed, and state that an update follows. A sentence that separates those three things cannot later be characterised as a misstatement — it was accurate about its own limits when written. “No customer data was affected,” written on day one before anyone has looked, can be.
Is a Suspicion Enough? That Is Two Questions, Not One
They get conflated constantly, and they have different answers.
Is a suspicion enough to start the clock? Almost. The Directive ties the deadline to “becoming aware of the significant incident” and does not define awareness. The formulation comes from Recital 31 of Commission Implementing Regulation (EU) 2024/2690: an entity is regarded as having become aware “when, after such initial assessment, that entity has a reasonable degree of certainty that a significant incident has occurred.” That is a recital, so it is interpretive rather than binding, and the Implementing Regulation itself formally binds only the digital-infrastructure categories in its Article 1 — but Belgium’s CCB reproduces the same wording in national guidance addressed to all NIS2 entities, which is a fair signal of how authorities elsewhere are reading it. A raw alert does not start the clock; a brief triage that leaves you reasonably confident something significant is happening does — long before you can prove it. Note what the threshold attaches to: reasonable certainty that the incident is significant under the Article 23(3) test, not certainty about its cause.
Nor is the window permission to use it. The CCB reads “without undue delay” as an obligation to notify “as soon as possible, without waiting for the maximum deadlines of 24 hours and 72 hours,” with only “duly justified special circumstances” excusing a filing at the very end — and adds that internal procedures “must not lead to an unreasonable delay.” An approval chain that reliably burns 20 hours is a compliance defect, not a mitigating factor.
Is a suspicion enough to put in the report? Yes — it is the statutory verb. Article 23(4)(a) asks whether the incident is “suspected of being caused by unlawful or malicious acts.” Reporting a suspicion as a suspicion is exact compliance, not a hedge.
The two failure modes are not equally expensive. Filing for something that turns out not to be significant carries no penalty defined anywhere in the Directive, and Article 23(1) provides that “the mere act of notification shall not subject the notifying entity to increased liability.” Missing a genuine significant incident is an infringement of Article 23 — one of the two provisions Article 34 attaches administrative fines to.
What Not to Put in an Early Warning
The Article 23(1) liability shield is narrower than it is usually quoted as being. It protects the act of notifying — you are not worse off for having reported. It does not say the contents cannot be used, and it says nothing about accuracy. Under Article 23(7) a CSIRT or competent authority may also inform the public about a significant incident, after consulting you, where public awareness is necessary or otherwise in the public interest. Write on the assumption that what you file may be read beyond the analyst who receives it.
Four things to keep out of a 24-hour filing:
- Attribution. Naming a threat actor or a nation state on day one is a claim you cannot support and will likely revise. “Suspected malicious” is what is asked for; who did it is not.
- Attacker claims repeated as fact. A ransom note asserting 4 TB was exfiltrated is an assertion by a hostile party — report it as a claim made in a ransom note, not a finding. Our guide to ransomware reporting obligations goes deeper.
- Legal conclusions. Whether the event is a personal data breach under GDPR Article 33 is a separate assessment on a separate clock, running in parallel rather than in sequence. See dual NIS2 and GDPR notification.
- Negative certainties you have not earned. “No data was exfiltrated” and “no third parties affected” are findings, not defaults. Before anyone has looked, the truthful entry is “not yet assessed.”
Filing Also Starts a 24-Hour Clock Running the Other Way
The early warning is generally framed as a one-way obligation. It is not. Article 23(5) obliges the CSIRT or competent authority to respond “without undue delay and where possible within 24 hours of receiving the early warning,” with initial feedback and, on request, “guidance or operational advice on the implementation of possible mitigation measures” — plus additional technical support if asked, and guidance on reporting to law enforcement where the incident is suspected to be criminal.
Belgium operationalises this: whether you need CCB support is a mandatory field, not an afterthought. Filing early does not only stop a deadline running — it opens a technical support channel on the day you most need one. Teams that treat the early warning purely as legal exposure routinely tick past the field that would have got them help.
Who Files It, and What to Prepare Now
| Role | Owns at the 24-hour mark |
|---|---|
| Incident lead / SOC manager | Declares the awareness timestamp and records what triggered it. This single entry decides whether the filing was late. |
| Compliance officer | Files, or holds delegated authority to file without further sign-off. Retains the submission reference and a copy of exactly what was sent. |
| Legal | Reviews wording only where time permits — legal review must not be a blocking gate inside the 24-hour window. |
| Management body | Informed, not consulted. Under Article 20(1) management bodies approve and oversee risk-management measures and can be held liable for infringements; that is an argument for pre-approving the filing authority, not for inserting a board decision into the window. |
Three things are worth doing before an incident, and all three take under a day: register for your national portal and confirm who can reach it out of hours; pre-approve in writing who may file without escalation; and write your organisation’s standing description — legal name, registration number, sector, entity classification, contact details — into a document your on-call team can paste from. Those are the fields that waste time at 3 a.m., and none depend on knowing anything about the incident. For the full three-stage picture, see our guide to NIS2 incident notification under Article 23 and the incident response mistakes that most often turn a manageable incident into a reporting failure.
The next filing is where the content rule widens — but far less than most guides claim. Our guide to the NIS2 72-hour incident notification requirements covers the three elements Article 23(4)(b) names, two of which are conditional, and how to draft them while the investigation is still open.
Frequently Asked Questions
Does the 24-hour clock run over a weekend or public holiday? Yes. Article 23(4)(a) sets a fixed 24-hour period from awareness with no suspension for non-working days. This is precisely why filing authority needs to be delegated in advance.
Can I submit the early warning and the 72-hour notification together? Only if you can genuinely meet the 72-hour content requirement within 24 hours, which is rare. The stages are cumulative, and filing the early warning early is the point. Note the related trap on the far end: the one-month final report clock in Article 23(4)(d) runs from submission of the 72-hour notification, not from the incident.
What if I file and later conclude the incident was not significant? The Directive sets no withdrawal procedure. In practice you correct the record at the next stage — both the CCB and the BSI confirm that follow-up reports and corrections are accepted at any time. The Article 23(1) liability shield covers the act of having notified.
Do we file in every Member State where we operate? Generally you notify the CSIRT or competent authority of your own Member State. Cross-border propagation is handled between authorities: Article 23(6) requires the CSIRT, competent authority or single point of contact to inform other affected Member States and ENISA where the incident concerns two or more Member States. That is why the cross-border question is asked so early.
Is a near miss reportable? Not under Article 23, which is limited to significant incidents. Article 30 provides a separate voluntary route covering incidents, cyber threats and near misses, and protects you: voluntary reporting “shall not result in the imposition of any additional obligations upon the notifying entity to which it would not have been subject had it not submitted the notification.” Germany’s BSI form carries an explicit Beinahevorfall (near-miss) classification.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- “NIS 2 Directive, Article 23: Reporting obligations” — Directive (EU) 2022/2555, full text (nis-2-directive.com)
- “Article 23 — Reporting obligations, Directive (EU) 2022/2555” — nis2resources.eu
- “NIS 2 Directive, Preamble 101–110 (Recitals 101, 102, 106)” — nis-2-directive.com
- “NIS2 Notification Guide, Version 10.2024 — 1.2” — Centre for Cybersecurity Belgium (CCB). A later version (1.3, August 2025) is published at ccb.belgium.be
- “#nis2know: NIS-2-Meldepflicht” — Bundesamt für Sicherheit in der Informationstechnik (bsi.bund.de)
- “The notification of NIS2 incidents” — Centre for Cybersecurity Belgium (ccb.belgium.be)
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
