When does the clock actually start

Record detection, awareness and classification separately. They may coincide, but they describe different facts. The internal procedure should implement the applicable legal test; it cannot redefine awareness as the moment a preferred manager finally reads an email.

NIS2 recital 101 explains awareness through reasonable certainty following an initial assessment. Implementing Regulation 2024/2690 adds rules for the digital entities it covers. Under DORA, apply the incident and major-incident classification framework and preserve the assessment trail.

Consider an illustrative sequence: an alert at 02:14, escalation at 06:40 and management briefing at 09:15. Which information was available at each stage? What made the incident significant or major? An answer needs evidence, not a convenient choice among those timestamps.

External reports can come from customers, suppliers or incident response teams. Arrange monitored channels and escalation outside office hours. An unread shared mailbox is an operational weakness, not a reliable way to postpone awareness.

Who classifies, and against what criteria

Classification is a decision with legal effect. It needs an owner, a deputy, and criteria that were written before the night in question.

Under DORA, the criteria are set out in Delegated Regulation (EU) 2024/1772: clients, counterparts and transactions affected; reputational impact; duration and service downtime; geographical spread; data losses; economic impact; and the criticality of the services affected. It is close to a threshold test, which is a genuine advantage — but somebody still has to apply it, at the time, and record when they did.

Under NIS2, Article 23(3) is coarser: an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. "Capable of causing" is doing a lot of work in that sentence, and it is a judgement call made with incomplete information.

Under Article 5(2) of Regulation 2025/301, if classification as major happens more than 24 hours after awareness, the initial notification is due within four hours of that classification. This exception matters; it does not justify delaying assessment or suppressing known facts.

The two clocks are not interchangeable

The following table is a working summary. Apply the exact legal rules and your competent authority’s submission instructions.

Stage NIS2 significant incident DORA major ICT-related incident
First report Early warning without undue delay, within 24 hours of awareness As soon as possible, within 4 hours of major classification and within 24 hours of awareness; late-classification exception under Article 5(2)
Next report Notification without undue delay, within 72 hours of awareness; trust service providers: 24 hours Intermediate report within 72 hours of initial notification; updated report without undue delay when normal activities are restored
Final report Within 1 month of notification; for an ongoing incident, progress report then final within 1 month after handling ends Within 1 month of the intermediate or latest updated intermediate report
Recipient Designated CSIRT or authority; verify the Bulgarian СЕРИКС route Competent authority and prescribed reporting channel

The 72-hour periods start from different events. In an illustrative DORA case, initial notification at hour 20 sets the ordinary intermediate deadline at hour 92. That does not remove earlier update duties or permit postponing a first report that is already due.

Weekends under DORA. Article 5(4) can move a deadline to noon on the next working day. Article 5(5) excludes initial and intermediate reports of credit institutions, central counterparties, trading venue operators and entities identified as essential or important under NIS2. That exclusion does not itself cover their final reports. The competent authority can also exclude other entities under Article 5(6). Check the entity, report type and applicable authority decision before using an extension.

For the relationship between the regimes, see DORA or NIS2. A group can contain entities with different obligations; do not infer the reporting route from the group name.

The first hour goes to a question nobody plans for

An ambiguous alert consumes investigation time before anyone has a complete account of the incident. Plan for that uncertainty: identify the first evidence sources, give the on-call role escalation authority and prepare reporting in parallel when the facts indicate a reporting obligation. Do not wait for an arbitrary fourth hour or a complete forensic report.

A preliminary notification should distinguish confirmed facts, estimates and unknowns. Update it through the required process as the picture changes. The deadlines are outer limits; “without undue delay” and “as soon as possible” still matter.

Decision authority and deputies turn this into a practical exercise. The research publication on incident time management provides the bibliographic connection to this theme; the recommendations here are an operational application, not a claim of measured performance in your organisation.

Decisions that cannot be made at three in the morning

Each of these takes five minutes on a quiet afternoon and consumes an hour in the middle of an incident.

Who can take a production system offline. Name the role, name the deputy, and state the threshold above which it escalates. Without that, the decision defaults to whoever is most senior and awake, and in practice the cable stays connected for another two hours while people look for someone to authorise pulling it.

Who speaks to customers, and what the first message says. Write the holding statement now, while you can think, and have it approved now. Under NIS2 you may also owe your service recipients a notification where a significant incident is likely to affect the services you provide to them.

Who speaks to the regulator. One voice, and preferably not the person running the technical response. Someone answering a supervisory question at hour 20 cannot also be tracing lateral movement.

When external help is called, and on what terms. Sign the agreement before you need it. An incident is a poor moment to negotiate a contract, a data processing agreement and a rate card, and the retainer should state a response time in hours rather than "best effort". Check your insurance policy in the same sitting: cyber policies commonly require notification of the insurer within a stated period and restrict which forensic firms you may engage. Discovering that clause at hour six is expensive.

Where the contact list lives when the network is compromised. Printed, off-domain, and physically with the people who need it. Telephone numbers, not chat handles on the platform that may be down or hostile. Agree an out-of-band channel in advance, and make sure it is not your own email. Encrypting exactly this — the identity directory, the file shares, the wiki with the escalation tree — is standard practice for the groups described in our note on how ransomware operators actually get in.

What to do first

  1. Write the awareness definition into the incident procedure this week, in one sentence, and add a mandatory timestamp field to the ticket template.
  2. Name the person who classifies, name the deputy, and attach the criteria — 2024/1772 if DORA applies to you, Article 23(3) if NIS2 does.
  3. Build the report templates now, with the mandatory fields already in them, so the first 24 hours are spent gathering facts rather than discovering what is being asked.
  4. Print the contact list, put it somewhere physical, and call one number on it to check that it is current.
  5. Run a 60-minute exercise with exactly one question: at what minute did we become aware, and who decided? Do not rehearse the malware. Rehearse the clock.

The boundary

Other duties can run in parallel. Under GDPR Article 33, a controller reports a personal data breach without undue delay and, where feasible, within 72 hours of awareness, unless it is unlikely to result in a risk to people’s rights and freedoms. A processor informs the controller without undue delay. Client contracts may require earlier communication. Record the assessment for each regime separately; the regulatory reference helps identify the instruments.

If you want the awareness definition, the classification criteria, the report templates and the contact list to exist before you need them, that is the work described on our practical improvements page.

Note. This is general information, not legal advice. Applicability depends on the specific entity, activity, licence, size, group structure and national implementation.