Mahope tools: EUComply Clean Copy DeskUptime Transmute BugBottle All tools
FREE TOOL

NIS2 Incident Report Generator

Article 23 requires an early warning within 24 hours, a notification within 72 hours and a final report within one month of a significant incident. Fill in what you know — get a structured draft.

1. The reporting entity
2. Timeline
Deadlines are calculated when you fill in this field: early warning due within 24 hours, notification within 72 hours, final report within 1 month — all counted from the moment of awareness.
3. The incident
4. Receiving authority

Submit through your national reporting portal. In Denmark: cfcs.dk. The generator only produces the document — submission happens on the official portal.

The three Article 23 deadlines

  • Early warning — 24 hours. A short notice stating whether the incident is suspected to be caused by unlawful or malicious acts, whether it could have cross-border impact, and whether it may cause malicious exploitation. You do not need all the facts yet.
  • Incident notification — 72 hours. An update with an initial assessment of severity and impact, including indicators of compromise where available.
  • Final report — 1 month. A detailed description including the likely cause, mitigation measures already applied and planned, and cross-border effects. If the incident is still ongoing, a status report is submitted first.

Honest limitation: Member State implementations vary in portal, format and extra fields. This generator follows the Annex I requirements of the directive text; always check your national CSIRT's own guidance before submitting.

Related: free NIS2 gap assessment · self-assessment · NIS2 readiness guide · incident report checklist