The gist: Mid-sized enterprises must now report security incidents to authorities within 24 hours under the NIS2 Directive.
The incident notification obligation for cybersecurity incidents under the NIS2 Directive is now active for medium-sized enterprises. Affected organizations must now report security incidents within 24 hours of discovery to the relevant authorities.
The NIS2 Directive (Network and Information Security 2) has reached its implementation phase for medium-sized enterprises. The new regulation requires affected organizations to report security incidents to the relevant national authorities within 24 hours of discovery. This applies to mid-sized enterprises in critical sectors as well as providers of essential digital services.
For CISOs, this represents a significant tightening of incident reporting discipline. The 24-hour deadline requires established incident response processes and immediate escalation channels. Organizations must coordinate their incident detection systems and communication with authorities in advance to meet the deadline. Delays in reporting can lead to penalty proceedings.
Enterprises should review their incident management procedures and ensure that responsible parties and authority contacts are clearly defined. Preparation of standardized incident report templates and training of incident response teams are central to ensuring both compliance with the deadline and the quality of the report.
Source: news.google.com · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.