Protect//NIS2 guide
NIS2 incident reporting: 24 hours, 72 hours, one month
When an incident becomes significant, what you send to DNSC at each stage and what to prepare before anything happens.
Updated: 02.10.2026 · ~6 min read
Essential and important entities must report significant incidents to DNSC in three stages with fixed deadlines. The rules come from GEO 155/2024, as amended by Law 124/2025, which transposes art. 23 of the NIS2 Directive. Not every antivirus alert or phishing email has to be reported, so the first step is knowing what “significant” means.
When an incident is significant
Following the amendments made by Law 124/2025, an incident is significant if it meets at least one of these conditions:
- it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity;
- it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
The conditions are alternative, not cumulative. The wording “capable of causing” matters: you do not wait for the full impact to show before you start reporting. The criteria and thresholds for the level of disruption of a service are set out in DNSC Order 2/2025.
The three stages
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours from becoming aware | Flagging the incident and, if it can already be said, whether it appears to be caused by unlawful or malicious acts or could have a cross-border impact |
| Incident notification | 72 hours from becoming aware | An update of the early warning, with an initial assessment of severity and impact and, where available, indicators of compromise |
| Final report | One month at most after the notification | A detailed description of the incident, the type of threat or likely root cause, the measures taken and any cross-border impact |
If the incident is still ongoing after one month, the NIS2 Directive requires a progress report at that point and the final report within one month of the incident being handled. DNSC may also request intermediate reports along the way.
When the 24 hours start
The deadline runs from the moment the organization becomes aware of the incident, not from the moment the attack began. In practice, this is when someone in the company has enough information to consider the incident significant. That is why it matters who monitors the systems and how quickly the information reaches the NIS officer.
What to prepare in advance
There is no time to build the process during the first incident. Before it is needed, the company should have:
- a written incident management procedure, approved by management;
- internal criteria for when an event becomes a significant incident, aligned with DNSC Order 2/2025;
- a person appointed to decide on and send the reports, plus a deputy;
- access credentials for the DNSC reporting channel, checked in advance;
- an incident register that also records events that were not reported, with the reason;
- logs from the key systems kept long enough to be analysed after an incident.
A one- or two-hour tabletop exercise with management and the IT team quickly shows where the process gets stuck: who does not know they must be informed, which passwords are missing, who has the final say.
NIS2 reporting and GDPR notification
If the incident also affects personal data, in addition to reporting to DNSC there may be a duty to notify ANSPDCP, the Romanian data protection authority, within 72 hours under art. 33 GDPR. These are two separate obligations, to different authorities, with different content. The internal procedure should cover both, so that neither gets lost in the rush of an incident.
Reporting deadlines are only one of the time-bound obligations; the rest are in the guide NIS2 deadlines in Romania. For an incident procedure tailored to your company, request a free assessment.
Request a free NIS2 assessment
Find out if your organization falls under NIS2 and what steps you need to take. The first consultation is free.
Request free assessment