Skip to content
CyberNIS2

Glossary

Incident Notification

A legal obligation under NIS 2 to report any significant cyberattack to ANSSI on a strict timeline: early warning within 24h, full notification within 72h, final report within one month.

Incident notification is a legal obligation imposed by NIS 2 to report any security breach or cyberattack with a significant impact on service continuity to ANSSI. The process follows a very strict timeline: an initial early warning within 24 hours, followed by a full, detailed report within 72 hours.

Regulatory timeline

StepDeadlineContent
Early warning24h after detectionBrief initial notification: nature of the incident, estimated impact
Initial notification72h after detectionDetailed description, initial measures taken, severity assessment
Intermediate reportOn ANSSI's requestUpdated analysis and ongoing measures
Final report1 month after resolutionFull root-cause analysis, impacts, permanent corrective measures

What counts as a "significant" incident?

An incident is considered significant if it meets at least one of the following criteria:

  • It causes or is likely to cause severe service disruption.
  • It affects other entities or sectors (cascading effect).
  • It involves a large-scale data breach.
  • It is caused by a malicious actor (deliberate cyberattack).

Consequences of non-compliance

Failing to notify within the deadlines is a standalone, sanctionable offence, regardless of the nature of the incident itself. ANSSI can impose periodic penalty payments and administrative fines.