when must I report a cyber incident to the supervisory authority
Reporting follows a timeline with multiple moments
A reportable incident is not reported all at once, but in stages: first an early warning, then a more detailed report, and later a final report. This aligns with the nature of an incident — immediately after discovery, it is often still unclear exactly what has happened, while the supervisory authority wants to be informed quickly that something is occurring. The precise moments and the content expected at each stage are described on the NCSC website and in the Dutch Cybersecurity Act; these sources also indicate when an incident is considered "significant" enough to fall under the reporting obligation.
For those wondering whether this applies to them: the reporting obligation applies to essential and important entities, and that is a different question than how do I know if my company falls under NIS2. Which authority receives a report varies by sector — that follows from which supervisory authority oversees my sector under NIS2. If someone is informed by a client that a reporting obligation exists but is not themselves obligated, they usually do not receive this question directly from a supervisory authority, but indirectly through a security questionnaire from that client.
Where this comes from: Article 21 and the national law
The reporting obligation is linked to the risk management obligation in Article 21(2) of the NIS2 Directive: those required to manage risks are also required to report incidents that circumvent those measures. The Directive itself describes the principle; the precise moments, deadlines and format of the report are set out in the Dutch Cybersecurity Act and in guidance from the NCSC, which translates the legal text into a practical process. For the content of a report, it is useful to know which measures were already in place at the time of the incident — an overview of these should be part of which ten measures must I take according to NIS2.
What this is based on
- Directive (EU) 2022/2555 (NIS2), Article 21(2) — the ten measures
- Cybersecurity Act — the Dutch transposition of NIS2
- ISO/IEC 27001 — Annex A, the control measures
- NCSC — guidance on the security obligation and the reporting obligation
The Regulation itself is available on EUR-Lex. We provide references for each statement; you need not take our word for it.
What you concretely need to do
The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.
View the subscription First the free NIS2 checkThis is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.
Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.