The European Commission has extended the mandatory incident reporting deadline under the NIS2 Directive, moving the window for reporting critical cybersecurity incidents from 24 hours to 72 hours. The change applies to operators of essential services across finance, healthcare, energy, transportation, and digital infrastructure sectors.
NIS2 came into force across EU member states in late 2024 and significantly expanded the scope of organizations covered compared to the original NIS Directive. The stricter obligations include incident notification requirements, supply chain security measures, and board-level accountability for cybersecurity governance.
The extended deadline reflects feedback from operators that 24 hours was insufficient to gather accurate, actionable information about an incident — particularly in complex, multi-system breaches where attribution and scope take time to establish. A poorly characterized report filed too quickly can misdirect response efforts and create regulatory complications.
The practical implication hasn’t changed: you need to detect incidents fast enough to have time to investigate and report within 72 hours. That means your logging pipeline, alerting, and incident response playbooks all need to be in place before an incident happens, not during one. If you’re serving EU customers and haven’t mapped your current detection-to-report timeline against NIS2 requirements, now is the right moment.