NIS 2: common 24h/72h/1‑month templates — what ILR expects
On 26 May 2026, the EU adopted common incident reporting templates (24h/72h/1 month). In Luxembourg, ILR confirms this sequencing and sets out the expected content for entities.
The facts
On 26 May 2026, the European Commission announced that the NIS Cooperation Group (Member States, Commission, ENISA) adopted common incident reporting templates under Article 23 NIS 2: a preliminary alert within 24 hours, a notification within 72 hours, and a final report within one month. Aim: harmonise who/what/when of reporting across the EU and reduce compliance burden. Official source: NIS2 Cooperation Group adopts common templates for incident reporting.
In Luxembourg, the NIS 2 competent authority, ILR, confirms on its “Incident notification” page that, under the Law of 5 May 2026, essential and important entities must: send a preliminary alert within 24 hours, submit a notification with initial assessment within 72 hours, and deliver a final report within one month. See ILR — Incident notification (EN) and (FR). For local context, see our page NIS 2 in Luxembourg and ILR.
Legal reasoning
The framework is set by Directive (EU) 2022/2555 (“NIS 2”), Article 23 (“Reporting obligations”). It requires: a preliminary alert within 24h from the moment the entity “becomes aware” of a significant incident, a detailed notification within 72h, and a final report no later than one month after the notification. See NIS 2 Article 23 (EUR‑Lex) and the dedicated Article 23 page. A quick primer is also available on our NIS 2 directive page.
Two clarifications further shape this framework:
- “Significant” incidents for digital providers. Implementing Regulation (EU) 2024/2690 of 17 October 2024, based on Articles 21(5) and 23(11) NIS 2, lays down concrete criteria (operational severity, trade secret exfiltration, sectoral thresholds) and also covers “recurrent” incidents. References: EUR‑Lex — 2024/2690 (EN) and FR version.
- Cross‑regime articulation. The Commission’s guidelines on Article 4 NIS 2 (OJ C 328 of 18.9.2023) clarify interplay with other regimes (eIDAS, DORA, EECC, CER, etc.) and recall the need for at least “equivalent” effect. See the Commission Communication – Article 4.
Finally, the 26 May 2026 announcement on common templates operationalises Article 23 by harmonising the three stages (24h/72h/1 month) EU‑wide, easing exchanges with CSIRTs/competent authorities and EU‑CyCLONe. See the official announcement.
What this changes in practice
- EU/ILR‑aligned incident playbook. Stop reinventing forms; align your playbook with the common templates and ILR’s expected content. You know what to include at 24h (preliminary alert), 72h (initial assessment), and 1 month (root causes, fixes, lessons learned). A fractional CISO can help orchestrate this.
- Clear “significant” thresholds. Digital entities (cloud, data centres, MSP/MSSP, CDNs, marketplaces, search engines, social platforms, TLD/DNS, trust service providers) get precise thresholds. Example: an incident “capable of causing” trade secret exfiltration may already trigger reporting. See EUR‑Lex 2024/2690.
- Single gateway in Luxembourg. ILR centralises NIS 2 reporting and expects strict timelines. The content showcased (notifier contact, incident references, sector/sub‑sector mapping) mirrors what the templates require. See ILR — Incident notification.
- Coherence with GDPR/DORA/eIDAS. EU‑level harmonisation eases alignment with other regimes (e.g., GDPR’s 72h). For privacy ramifications and cross‑filings, consult our overview of GDPR obligations.
Common pitfalls
- Confusing “detection” with “awareness”. The 24h clock starts when the entity can reasonably conclude a significant incident has occurred. Waiting for perfect forensics is risky (see NIS 2 Article 23).
- Underestimating recurrent incidents. Regulation 2024/2690 aggregates minor events sharing the same cause; together they may be reportable. See 2024/2690.
- Forgetting cross‑regime coherence. One incident may also involve personal data (GDPR) or critical providers (DORA). The Article 4 Communication encourages authority cooperation.
- Empty 24h alert. The templates define minimal fields (entity category, scope, impact, immediate actions). Too little substance prompts callbacks and strains the 72h stage. See the Commission note.
- Overlooking trade secrets and availability. Regulation 2024/2690 explicitly cites potential trade secret exfiltration and severe operational disruption; do not focus solely on personal data.
Official sources
- Commission — Common reporting templates (26 May 2026)
- ILR — Incident notification (EN) / (FR)
- EUR‑Lex — Directive (EU) 2022/2555 (NIS 2) — Article 23
- EUR‑Lex — Implementing Regulation (EU) 2024/2690 (EN) / (FR)
- Commission — First NIS 2 implementing rules (17 Oct 2024)
- ENISA — NIS2 Technical Implementation Guidance (2025)
In short
Adopt the EU 24h/72h/1‑month templates now, map your “significant” criteria under 2024/2690, and align your ILR/CSIRT packs to report without stress — and to evidence an operational NIS 2 governance.
Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →