Where to Report a NIS2 Incident in 24 Hours: CSIRT Portals, Logins, and Required Fields for 8 EU Countries
Most NIS2 guidance stops at the deadline: 24 hours for the early warning, 72 hours for the incident notification, one month for the final report. What it doesn’t tell you is where you actually submit that report — and in eight of the largest EU markets, that answer involves a specific portal, a specific login method, and a specific set of fields you need ready before the clock starts. Get the portal wrong, and the 24-hour window can burn on account setup instead of incident response.
This guide is the missing operational layer under our Article 23 notification-timeline guide: which CSIRT or competent authority receives your report in Germany, France, the Netherlands, Belgium, Poland, Italy, Spain, and Ireland, what credential you need to log in, and what the form on the other side actually asks for. If your organisation operates in more than one of these markets, treat this as a pre-incident checklist — not something to read for the first time while an incident is live.
Who Has to Use These Portals
Article 23 of the NIS2 Directive obliges “essential” and “important” entities — the two tiers defined by sector and size under Annex I and II — to notify a “significant incident” to their national CSIRT or, where the Member State designates it that way, to a competent authority that forwards the notification to the CSIRT [1]. If you haven’t confirmed which tier your organisation falls into, that determination happens before any of this matters — see our full essential/important entity scope test before anything below.
What doesn’t vary by country is the trigger: a “significant incident” under Article 23(3) is one that has caused, or is capable of causing, severe operational disruption or financial loss, or has affected other natural or legal persons by causing considerable damage. What varies enormously is what happens in the next 24 hours once you’ve made that call.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
| Reader | What matters to you here |
|---|---|
| Compliance Officer / Legal | Exact deadlines, which authority is correct for each jurisdiction, and documentation for an audit trail |
| CISO / IT Security Manager | Login/access mechanics (ELSTER, eHerkenning, SPID/CIE) that block submission if not set up in advance |
| Board / Group Compliance | Which entities in a multi-country group need separate registrations, and the Article 34 exposure for missing one |
The 24-Hour / 72-Hour / 30-Day Timeline Every Country Shares
Every Member State’s transposition runs the same three-report structure, because Article 23(4) sets it directly rather than leaving it to national discretion [1]:
| Stage | Deadline | Purpose |
|---|---|---|
| Early warning | 24 hours from awareness | Flags the incident, indicates suspected unlawful/malicious cause, notes possible cross-border impact |
| Incident notification | 72 hours from awareness | Updates the early warning with an initial severity/impact assessment and compromise indicators, where available |
| Final report | 1 month after the incident notification | Full description, root cause, mitigation taken, and cross-border impact where relevant |
Trust service providers get a stricter clock: instead of the standard 72-hour window, they must report significant incidents within 24 hours [1]. And the obligation runs both ways — the receiving authority must give you initial feedback “without undue delay and where possible within 24 hours” of the early warning, including guidance on how to respond [1]. If your national portal doesn’t acknowledge submission, that’s worth escalating, not assuming is normal.
Why “Report to the CSIRT” Means Something Different in Every Country
Article 23 leaves one structural choice to each Member State: whether incidents go directly to the national CSIRT, or to a sector-specific competent authority that relays them to the CSIRT [1]. That single design choice cascades into everything downstream — which login credential you need, which government agency’s IT stack you’re dealing with, and how many separate accounts a multi-country operator has to maintain.
At one end, Belgium and the Netherlands route almost everything through one national body (the CCB and NCSC-NL respectively) with a single portal. At the other end, Spain splits notification three ways by the notifying entity’s legal status, not its sector — a private hospital and a public health authority report to two different CSIRTs for the same type of incident, a distinction covered in full in our Spain competent-authority guide. Germany sits in between: one authority (BSI), but an access process that assumes you registered weeks in advance. None of this is documented consistently across NIS2 explainer content, which is exactly the gap this directory closes.
CSIRT Portal Directory: 8 Countries, Access, and Where Things Stand
Verified directly against each country’s official cybersecurity authority. Portal names and access requirements change as national transposition laws mature — re-confirm before your first submission, and don’t wait for an incident to find out your registration is incomplete.
| Country | CSIRT / Authority | Portal | Access Requirement |
|---|---|---|---|
| Germany | BSI | BSI-Portal / Melde- und Informationsportal (MIP) [2] | Strong authentication, standard route is an ELSTER organisation certificate [3] |
| France | ANSSI / CERT-FR | MonEspaceNIS2 (registration) + CERT-FR declaration channel [4] | Entity account via MonEspaceNIS2 |
| Netherlands | NCSC-NL | MyNCSC (mijn.ncsc.nl) [5] | eHerkenning or SSO-Rijk login for registered organisations; unauthenticated web form for voluntary reports |
| Belgium | CCB | Safeonweb@Work [6] | Registration through a legal representative |
| Poland | CSIRT NASK | incydent.cert.pl [7] | Confirm current login method directly — access process has changed as the national law matured through 2026 |
| Italy | ACN | Portale Segnalazioni, via portale.acn.gov.it [8] | Personal digital identity login for the legal representative or a designated contact (multiple secondary sources describe SPID/CIE; confirm current method directly with ACN) |
| Spain | INCIBE-CERT / CCN-CERT / ESPDEF-CERT | Three separate channels, routed by entity legal status — see our Spain guide | Varies by CSIRT; private-sector entities use INCIBE-CERT’s dedicated notification channel |
| Ireland | NCSC-IE | Not yet operational as of this writing [9] | N/A — contact NIS2Queries@ncsc.gov.ie in the interim |
Three of these deserve a closer look, because the access requirement is the part most compliance teams underestimate.
Germany’s ELSTER requirement is the one most likely to blow your 24-hour window if you haven’t planned ahead. The BSI portal’s standard authentication route is an ELSTER organisation certificate, applied for through Mein Unternehmenskonto and requiring a German tax number for the entity. In practice, processing takes two to three weeks, and the certificate arrives by post in two separate pieces — the certificate itself and a PIN letter [3]. Without it, portal access is described as available only “in exceptional cases” via delegation. An organisation that waits until it has an incident to start this process will likely miss the 24-hour deadline on process alone, regardless of how fast its security team moves.
Spain doesn’t have one portal — it has three, and the routing rule is about who you are, not what happened. Private-sector entities in any NIS2 sector report to INCIBE-CERT; public-sector entities and administrations report to CCN-CERT; the armed forces and defence-related systems report to ESPDEF-CERT. A national unified platform (LUCIA) has been referenced as the eventual single system, but was not yet operational at the time of this writing. Groups with both a private operating company and public-sector contracts in Spain should map this now, not during an incident.
Ireland is the reminder that “check the portal” only works once the portal exists. As of this writing, Ireland’s transposition legislation has not been finalised, and NCSC-IE states plainly that both the registration portal and the incident-reporting portal will only become available once the legislation is implemented [9]. Entities already designated under the older NIS1 framework continue using that legacy process in the meantime. If your organisation operates in Ireland, the practical move is to register interest via NIS2Queries@ncsc.gov.ie now, so you’re not starting from zero once the portal opens.
Inside a Real Early-Warning Form: What the Netherlands Actually Asks
Most NIS2 content describes reporting obligations in the abstract. Here’s what one live, documented national form actually collects — the Netherlands’ MyNCSC portal, which publishes its field structure in detail [5]:
- Organisation details: company name, Chamber of Commerce number, address, sector
- Notifier details: name, job title, email, phone number, and availability window
- Classification: voluntary or significant-incident status, and current incident phase (under investigation, unresolved, or resolved)
- Cross-border impact indicator: a flag your organisation must actively assess, not leave blank
- Incident specifics: discovery date and time, incident type, detailed description, visible and expected impact, root-cause analysis where known, customer-notification status, expected recovery timeframe, and whether police have been notified
- Attachments: supporting evidence, capped at five files and 10 MB total, in doc, docx, xlsx, pdf, txt, or ppt format
Notice what this list demands that a generic “incident summary” doesn’t: a Chamber of Commerce number pulled from corporate records, a named notifier with an actual phone number reachable during the incident, and an explicit cross-border-impact judgement call — not a technical field, but a legal one your incident commander needs to be ready to make inside the first 24 hours. Every country’s early-warning form asks some version of these same categories; the Netherlands’ is simply the one that documents its exact structure publicly.
How the 72-Hour and Final Reports Build on the First
Germany’s BSI documents its three-stage content requirements explicitly, and the pattern generalises well across the countries in this directory [2]:
| Report | Adds to the previous stage |
|---|---|
| 24h early warning | Incident classification, preliminary description, expected duration, notifier contact |
| 72h notification | Detailed root-cause update, law-enforcement coordination status, mitigation measures taken and planned |
| 30-day final report | Full incident description, confirmed severity, remediation completed, cross-border impact assessment |
BSI states the operating principle directly: “speed before completeness” — an incomplete 24-hour report is explicitly acceptable, and expected [2]. That’s a genuinely useful piece of psychological permission most compliance teams don’t realise applies: the early warning is not the moment to have every fact confirmed. It’s the moment to get the clock-stopping notification filed with what you actually know, then use the 72-hour window to fill in the rest.
Five Mistakes That Turn a Missed Portal Into a Penalty Exposure
Every mistake below is a process failure, not a technical one — which is precisely why it’s avoidable with pre-incident preparation rather than better security tooling.
- Treating portal access as something you set up during the incident. Germany’s ELSTER certificate alone can take two to three weeks. If your first attempt to log in happens after an incident starts, you’ve already lost the 24-hour window on administrative delay, not investigation time.
- Assuming one login works everywhere. A group with entities in Germany, Belgium, and Spain needs three separate access paths, potentially registered by three different legal representatives. Centralising this in a single owner (usually the compliance officer, not IT) prevents a scramble to find “who has the login” mid-incident.
- Skipping the cross-border impact field. Several national forms, including the Netherlands’, require an explicit judgement on whether the incident affects other Member States. Leaving it blank or defaulting to “no” without checking is the kind of gap that surfaces in a later Article 32/33 supervisory review.
- Confusing “portal not live yet” with “no obligation.” Ireland’s incident-reporting portal is not yet operational, but that doesn’t suspend the underlying duty once national transposition takes effect — it shifts the practical channel to direct contact with the authority in the interim.
- Reporting to the wrong CSIRT in a split-routing country. Spain’s three-way split by legal status, not sector, means the same incident type can have two correct answers depending on whether the affected entity is public or private. Getting this wrong doesn’t stop the clock — it just means the correct authority finds out later than 24 hours after you were aware.
These aren’t hypothetical. Article 34 ties penalties directly to Article 21 and Article 23 infringements [10]:
| Entity tier | Maximum fine | Triggered by |
|---|---|---|
| Essential | EUR 10,000,000 or 2% of worldwide annual turnover, whichever is higher | Article 21 or Article 23 infringements |
| Important | EUR 7,000,000 or 1.4% of worldwide annual turnover, whichever is higher | Article 21 or Article 23 infringements |
A missed notification deadline caused by an unregistered ELSTER account is still a missed notification deadline.
Before Your First Incident: A Pre-Registration Checklist
Pair this with the workflow steps in our NIS2 incident reporting hub if you haven’t yet mapped your organisation’s full notification process end to end.
| Step | Effort | Owner |
|---|---|---|
| Confirm your entity tier (essential/important) and which country’s CSIRT has jurisdiction | Low | Compliance Officer / Legal |
| Identify the correct portal and authority for each country you operate in (use the directory above as a starting point, verify current status directly) | Low | Compliance Officer |
| Start any multi-week credential process now — Germany’s ELSTER certificate is the clearest example | Medium | IT / Compliance Officer |
| Pre-register the entity where the portal requires it (Belgium, Netherlands, Italy) | Low | Legal representative |
| Name a primary and backup notifier with direct phone availability | Low | CISO / Compliance Officer |
| Draft a 24-hour early-warning template pre-filled with the static fields (org details, notifier contact) so only incident-specific fields need completing live | Medium | CISO |
Frequently Asked Questions
Do I report to the CSIRT or the competent authority?
It depends on the Member State. Article 23 allows either design, and where a competent authority receives the report, it’s obliged to forward it to the CSIRT. Check the directory above for which model your operating country uses, and confirm directly with the authority if your entity spans sectors with different routing rules.
What if my country’s portal isn’t listed here or has changed?
National transposition is still moving in several Member States — Ireland’s portal wasn’t operational at the time of writing, and access processes elsewhere continue to be refined through 2026. Treat this directory as a verified starting point, not a substitute for checking your national authority’s current guidance before your first submission.
Does the 24-hour clock stop if the portal is down or I can’t get credentials in time?
No. The deadlines in Article 23 run from when you become aware of the incident, not from when your access issue is resolved. This is precisely why pre-registration and credential setup need to happen before an incident, not during one.
Can one person handle notification for a group operating in multiple countries?
Not cleanly. Each country’s access method is typically tied to a specific legal representative or registered account per entity, so a group with subsidiaries in Germany, Belgium, and Spain needs coordinated (not necessarily identical) access set up in each jurisdiction, ideally owned centrally by one compliance function that knows where every credential lives.
Sources
- [1] NIS2 Directive (EU) 2022/2555, Article 23 — nis-2-directive.com
- [2] BSI (Germany) — NIS-2-Meldepflicht — bsi.bund.de
- [3] “BSI reporting portal: registration and incident notification under §32 and §33 BSIG” — nisd2.eu
- [4] ANSSI (France) — MesServicesCyber, Directive NIS 2 — messervices.cyber.gouv.fr
- [5] NCSC-NL (Netherlands) — Report an incident to NCSC-NL — ncsc.nl
- [6] CCB (Belgium) transposition summary — nis-2-directive.com
- [7] CERT Polska / CSIRT NASK — incident report portal — incydent.cert.pl (single-page portal, no deeper URL path)
- [8] ACN (Italy) — FAQ, security measures and incident notification — acn.gov.it
- [9] NCSC-IE (Ireland) — NIS2 — ncsc.gov.ie
- [10] NIS2 Directive (EU) 2022/2555, Article 34 — nis-2-directive.com
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
