It requires NIS2 organizations to report significant incidents to the Computer Security Incident Response Team (CSIRT) and the regulator. There is a phased reporting requirement. The first report is an early warning that occurs as soon as possible, but at least within 24 hours of observing the incident.

Download the new infosheet here.
Source: National Cyber Security Center
