Breach During a NIS2 Audit: What to Do When the 24-Hour Clock Doesn’t Pause
An inspector from your competent authority is on site with open document requests when the SOC escalates a ransomware detection. Two legal processes now run in parallel, and neither waits for the other. The Article 23 notification clock starts when you become aware of the incident, not when the audit closes. And everything the authority learns over the next three days it learns twice: once from the notification you file, and once through the evidence requests it already has open.
That second channel is where mid-audit breaches go wrong. Article 23(1) protects the act of notifying. It does not protect the audit file. This guide sets out what actually changes, which statutory factors move against you, and the order of operations from hour zero to day thirty.
What Changes When the Regulator Is Already on Site
In plain terms: your obligations do not change at all. Your exposure does. Every deadline in Article 23 runs exactly as it would on any other day. What shifts is that the authority is receiving your incident story and your compliance story at the same time, from two different sources, and can compare them line by line.
| Dimension | Ordinary significant incident | Same incident during an active audit |
|---|---|---|
| Reporting deadlines | 24 hours / 72 hours / one month from awareness | Identical. Supervision neither extends nor suspends any Article 23 deadline. |
| How the authority learns | From your notification | From your notification and from open Article 32(2)(e) to (g) requests, in parallel |
| Evidence of your Article 21 measures | Assembled later, on request | Already submitted, and dated before the incident |
| Route to a further audit | The authority must decide to open one | Article 32(2)(c) names a significant incident as an express ground for an ad hoc audit (essential entities) |
| Right to be heard before enforcement | Article 32(8): preliminary findings, then reasonable time for observations | Article 32(8) permits that time to be withheld where immediate incident action would otherwise be impeded |
The essential-versus-important split matters more here than in most compliance questions. Essential entities are supervised proactively under Article 32, so an audit can simply be routine. For important entities, Article 33(1) conditions ex post supervision on the authority being “provided with evidence, indication or information that an important entity allegedly does not comply with this Directive”. On that wording, ex post supervision presupposes such a trigger already exists, so an important entity under audit should assume a significant incident is landing on top of an open concern rather than arriving on a clean file. Ireland’s NCSC frames the same split as proactive supervision for essential entities and reactive, evidence-triggered supervision for important ones.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The Article 23 Clock Runs From Awareness, Not From the End of the Audit
Article 23(4) sets a staged sequence, and every stage is measured from your own awareness of the incident: an early warning “without undue delay and in any event within 24 hours of becoming aware of the significant incident”; an incident notification “within 72 hours of becoming aware”; an intermediate report “upon the request of a CSIRT or competent authority”; and a final report “not later than one month after the submission of the incident notification”. Where the incident is still running when the final report falls due, paragraph 4(e) substitutes a progress report and moves the final report to one month after the incident is handled.
Nothing in Article 23 conditions those clocks on supervisory activity. There is no tolling provision, no extension on request, and no carve-out for entities under inspection. The one flexibility the text does offer runs the other way: paragraph 4(c) lets the authority demand an additional intermediate report whenever it wants one, and an authority already sitting in your building is the one most likely to ask.
The trap is subtler than a missed deadline. Article 23(1) requires notification “in accordance with paragraph 4” to the CSIRT or, where applicable, the competent authority. Briefing the audit team in the corridor is not that. The audit and the notification usually reach different desks, under different mandates, on different systems, and an entity that assumes the inspector “already knows” can arrive at hour 25 with nothing formally filed. Where your member state routes notifications to the competent authority rather than the CSIRT, paragraph 1 also obliges that authority to forward the notification to the CSIRT on receipt, which is a second reason to use the designated channel rather than the person standing in front of you. Our guide to Article 23 incident notification covers the filing mechanics in detail, and the incident classification decision guide covers the threshold question of whether the event is significant at all.
Three of the Five Statutory “Serious Infringement” Triggers Come Into Play
Article 32(7) tells competent authorities what to weigh before imposing any enforcement measure, and Article 34(3) makes the same list govern whether a fine is imposed and how large it is. Point (a) is the part almost no commentary quotes: it names five things that constitute “serious infringement in any event”. A mid-audit breach is the one scenario that can put three of them on the table at once.
| Article 32(7)(a) | Text | Relevance mid-audit |
|---|---|---|
| (i) | “repeated violations” | Only if the incident exposes a recurrence of something already on the file |
| (ii) | “a failure to notify or remedy significant incidents” | Direct. Applies from hour 25 onward, and again if remediation stalls |
| (iii) | “a failure to remedy deficiencies following binding instructions” | Live only once the authority has issued instructions under Article 32(4)(b) |
| (iv) | “the obstruction of audits or monitoring activities ordered by the competent authority following the finding of an infringement” | Conditional. The qualifier matters – see below |
| (v) | “providing false or grossly inaccurate information in relation to cybersecurity risk-management measures or reporting obligations laid down in Articles 21 and 23” | Direct. Your pre-incident audit answers may have just been falsified by events |
Point (iv) is narrower than it first reads, and the distinction is worth getting right. It bites on obstruction of audits “ordered by the competent authority following the finding of an infringement”. A routine Article 32(2)(b) audit opened on a risk assessment is not that, so slow or incomplete cooperation during a scheduled audit does not automatically become a serious infringement in any event. It still counts: Article 32(7)(h) makes “the level of cooperation” a standalone factor, and Article 32(7)(b) prices delay directly as “the duration of the infringement”. The difference is between an aggravating factor and an automatic classification.
Point (v) is the one that catches careful organisations. Your audit responses about Article 21 measures were accurate when submitted. Then an incident demonstrates that a control described as operating was not. The statements do not become false retrospectively, but leaving them uncorrected while you now know better moves you toward “grossly inaccurate information in relation to cybersecurity risk-management measures”. Correcting the record in writing, promptly, is cheap. Not correcting it is the expensive option.
The Notification and the Audit File Are Two Different Legal Doors
Article 23(1) closes with a protection that is widely quoted and widely over-read: “The mere act of notification shall not subject the notifying entity to increased liability.” The clause does exactly what it says. It stops the fact of reporting from being turned against you, which is what makes mandatory reporting workable. It does not immunise the underlying non-compliance, it does not cover the content of what you disclose beyond the act itself, and it says nothing at all about material the authority obtains through a different power.
That other power is Article 32(2), and during an audit it is already switched on. Point (f) covers “requests to access data, documents and information necessary to carry out their supervisory tasks”. Point (g) reaches “evidence of implementation of cybersecurity policies, such as the results of security audits carried out by a qualified auditor and the respective underlying evidence”. A forensic report, an incident log, a post-incident review – all of these are underlying evidence about the implementation of your policies. Nothing in Article 23(1) shields a document produced under Article 32(2). Article 32(3) is the only real constraint: the authority must “state the purpose of the request and specify the information requested”, which is your basis for asking that broad requests be scoped rather than answered wholesale.
The file also travels further than most entities expect. Article 31(3) requires competent authorities to “work in close cooperation with supervisory authorities under Regulation (EU) 2016/679 when addressing incidents resulting in personal data breaches”. If your incident touches personal data, cooperation with the data protection authority is not a discretionary courtesy, it is an obligation on the regulator – which is why the NIS2 and GDPR narratives must be the same narrative. Our guide to dual NIS2 and GDPR breach notification covers that overlap. Article 32(9) and (10) add the same duty toward CER authorities under Directive (EU) 2022/2557 and, for critical ICT third-party providers, the DORA Oversight Forum.
Practical consequence for legal counsel: run one factual chronology, maintained by one owner, feeding the Article 23 filings, the audit responses, and any parallel notification. Divergence between them is the finding, not the incident.
What the Authority Can Do While It Is Still on Your Premises
Article 32(4)(b) is the provision to know, because it is the only enforcement power drafted to operate during an incident rather than after it. It lets the authority “adopt binding instructions, including with regard to measures necessary to prevent or remedy an incident, as well as time-limits for the implementation of such measures and for reporting on their implementation”. In practice that means a regulator standing in your crisis room can direct part of your response and set the deadline. Point (d) is the companion power: an order to bring Article 21 measures into compliance or to fulfil Article 23 reporting “in a specified manner and within a specified period”.
Two procedural points follow. First, Article 32(2)(c) makes “a significant incident” an express ground for an ad hoc audit of an essential entity, so the audit you are currently in does not absorb the incident – a second one can be opened on it. Note that the entity-pays cost rule in Article 32(2) attaches to targeted security audits under point (b), not to ad hoc audits under point (c). Second, Article 32(8) normally guarantees preliminary findings and “a reasonable time for those entities to submit observations”, but adds an exception “in duly substantiated cases where immediate action to prevent or respond to incidents would otherwise be impeded”. A live incident is precisely the circumstance that can compress your right to be heard, even though the Article 32(7) chapeau still requires authorities to “comply with the rights of the defence”.
The asymmetry between entity classes is sharper than the headline fine figures suggest:
| Power | Essential entity | Important entity |
|---|---|---|
| Ad hoc audit on the ground of a significant incident | Yes – Article 32(2)(c) | No equivalent limb in Article 33(2) |
| Binding instructions on incident prevention or remedy | Yes – Article 32(4)(b) | Article 33(4)(b) covers deficiencies and infringements, without the incident limb |
| Temporary suspension of certification or authorisation; temporary ban on managerial functions | Yes – Article 32(5), after a missed deadline where earlier measures failed | No – Article 33(5) imports only Article 32(6), (7) and (8) |
| Article 32(7) serious-infringement factors | Yes | Yes – via Article 33(5), mutatis mutandis |
| Administrative fine ceiling for infringing Article 21 or 23 | At least EUR 10 000 000 or 2% of total worldwide annual turnover, whichever is higher | At least EUR 7 000 000 or 1.4% of total worldwide annual turnover, whichever is higher |
The management-function ban in Article 32(5)(b) is not an on-the-spot sanction. It becomes available only where earlier enforcement measures proved ineffective, a deadline was set, and it passed. For a full treatment of the personal exposure, see our guide to management liability and breach exposure.
Order of Operations: Hour 0 to Day 30
Two workstreams, one chronology. The audit column is the part generic incident-response plans leave out.
| Window | NIS2 obligation | Audit-specific action | Owner |
|---|---|---|---|
| Hour 0-1 | Start the awareness log: who knew what, when | Notify the audit lead in writing that an incident is under assessment; do not pause outstanding responses | Incident manager + compliance officer |
| Hour 0-24 | Article 23(4)(a) early warning to the CSIRT or competent authority, through the designated channel | Record the filing reference in the audit file so both records reconcile | Compliance officer |
| Hour 24-72 | Article 23(4)(b) notification: initial assessment, severity, impact, indicators of compromise | Review every submitted audit answer that the incident may have falsified; issue written corrections | Compliance officer + CISO |
| Day 3-30 | Respond to any Article 23(4)(c) intermediate report request; prepare the final report | Log any Article 32(4)(b) binding instruction with its stated time-limit and reporting duty | Legal counsel |
| By day 30 | Article 23(4)(d) final report, or a progress report under 4(e) if the incident is ongoing | Open the corrective action register the next ad hoc audit will ask for | CISO + management body |
Three Mistakes That Turn a Bad Week Into an Enforcement File
1. Freezing the audit while you handle the incident. The instinct to tell the inspector “we will come back to you once this is contained” is understandable and costly. Article 32(7)(h) makes the level of cooperation an express factor, and Article 32(7)(b) prices delay as duration. Ask for revised dates in writing with reasons rather than going quiet.
2. Leaving overtaken audit answers on the record. Covered above, and it is the single cheapest thing on this list to fix. A dated written correction costs an hour. Article 32(7)(a)(v) is the alternative.
3. Running two narratives. The incident report says the backup was air-gapped; the audit response filed last week said backups were replicated continuously. Both were written in good faith by different teams. Under Article 31(3) the file may also reach the data protection authority, so the inconsistency gets read twice. One chronology, one owner, one version of the facts – see our notes on audit preparation and what to expect in a first NIS2 audit.
Frequently Asked Questions
Does an ongoing audit extend the 24-hour early warning deadline?
No. Article 23(4)(a) measures the deadline from becoming aware of the significant incident. The Directive contains no provision suspending or extending reporting deadlines during supervisory activity.
Does telling the on-site inspector count as notification?
Treat it as insufficient. Article 23(1) requires notification to the CSIRT or, where applicable, the competent authority “in accordance with paragraph 4”, which is a staged submission through the designated reporting channel. Inform the audit team as well, in writing, but file through the proper route.
Does the Article 23(1) liability protection cover what I hand over to the auditor?
No. It addresses “the mere act of notification”. Documents produced under Article 32(2)(f) or (g) are obtained through a separate supervisory power and carry no equivalent protection.
Can the authority order us to do something specific about the incident itself?
For essential entities, yes. Article 32(4)(b) covers binding instructions on measures necessary to prevent or remedy an incident, including time-limits and reporting on implementation. Article 33(4)(b), which applies to important entities, is drafted without that incident limb.
Will a mid-audit incident automatically trigger a fine?
No. Article 34(3) requires the Article 32(7) elements to be weighed in every case, and several of them – measures taken to mitigate damage, cooperation, absence of intent – can run in your favour. Fine ceilings under Article 34(4) and (5) are maximums, not tariffs.
We are an important entity. Does any of this change?
The reporting obligations are identical. Supervision is ex post under Article 33 and, on the text of Article 33(1), presupposes evidence or information of alleged non-compliance. The Article 32(7) factors apply through Article 33(5), but Article 32(5) – suspension and the temporary ban on managerial functions – does not.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555 (NIS2), full text – EUR-Lex
- Article 23 – Reporting obligations
- Article 31 – General aspects concerning supervision and enforcement
- Article 32 – Supervisory and enforcement measures in relation to essential entities
- Article 33 – Supervisory and enforcement measures in relation to important entities
- Article 34 – General conditions for imposing administrative fines
- NIS2 FAQ – National Cyber Security Centre, Ireland
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
