Glossary
Incident Notification
A legal obligation under NIS 2 to report any significant cyberattack to ANSSI on a strict timeline: early warning within 24h, full notification within 72h, final report within one month.
Incident notification is a legal obligation imposed by NIS 2 to report any security breach or cyberattack with a significant impact on service continuity to ANSSI. The process follows a very strict timeline: an initial early warning within 24 hours, followed by a full, detailed report within 72 hours.
Regulatory timeline
| Step | Deadline | Content |
|---|---|---|
| Early warning | 24h after detection | Brief initial notification: nature of the incident, estimated impact |
| Initial notification | 72h after detection | Detailed description, initial measures taken, severity assessment |
| Intermediate report | On ANSSI's request | Updated analysis and ongoing measures |
| Final report | 1 month after resolution | Full root-cause analysis, impacts, permanent corrective measures |
What counts as a "significant" incident?
An incident is considered significant if it meets at least one of the following criteria:
- It causes or is likely to cause severe service disruption.
- It affects other entities or sectors (cascading effect).
- It involves a large-scale data breach.
- It is caused by a malicious actor (deliberate cyberattack).
Consequences of non-compliance
Failing to notify within the deadlines is a standalone, sanctionable offence, regardless of the nature of the incident itself. ANSSI can impose periodic penalty payments and administrative fines.