Skip to Content

NIS2: You Have 24 Hours, and the Clock Starts Without You

The incident notification procedure, step by step
September 18, 2026 by
NIS2: You Have 24 Hours, and the Clock Starts Without You

Sunday, 10:40 p.m. An alert hits the system administrator's phone: files are being encrypted on a file server. He isolates the server within twenty minutes. Good reflex.

Then the real questions arrive, and none of them are technical. Is this a "significant" incident under NIS2? Who decides, on a Sunday night? Who holds the credentials for the CCB portal? And at exactly what time did the company "become aware" of the incident?

Monday, 9 a.m., everyone is around the table. Thirty-four hours have passed. The first legal deadline expired ten hours ago.

What is a "significant" incident?

The directive sets two criteria, and either one is enough. An incident is significant if it has caused or is capable of causing severe operational disruption of services or financial loss for the entity, or if it has affected or is capable of affecting other persons by causing considerable material or non-material damage.

Two words deserve attention. "Capable of" first: you do not wait for the damage to materialise. And "considerable" second: that is a judgement call, which means it must be prepared in cold blood, not improvised at 11 p.m. on a Sunday by tired people afraid of triggering a procedure for nothing.

The three deadlines

  1. Early warning — 24 hours. A short signal, indicating in particular whether the incident is suspected of being caused by malicious acts and whether it could have cross-border impact. It is not a report: it is a flag. It requires neither root cause nor full scope.
  2. Incident notification — 72 hours. It updates the early warning and adds an initial assessment: severity, impact, and indicators of compromise where available.
  3. Final report — one month after the notification. Detailed description, threat type or root cause, mitigation measures applied and ongoing, cross-border impact where relevant. If the incident is still ongoing at that point, a progress report is submitted and the final report follows within a month of the handling being completed.

Between the first two deadlines, the competent authority or CSIRT may request an intermediate report. Depending on the case, you may also have to inform the recipients of your services.

The trap: the clock starts at awareness

This is the point almost everyone gets wrong. The 24 hours do not start at the beginning of the attack, nor at Monday's crisis meeting. They start when the entity became aware of the incident.

Which moves the problem somewhere nobody was looking: at what time is your organisation deemed to have known? If an alert reached an administrator's phone at 10:40 p.m., the default answer is 10:40 p.m. The only way to control that timestamp is to record it yourself, in a register, at the moment it happens.

The five things that make you miss the deadline

  1. No written qualification criteria. Nobody wants to decide alone that an incident is "significant", so everyone waits for a meeting.
  2. No designated owner out of hours. Incidents land on a Friday evening two times out of three, and that is not a coincidence.
  3. No access to the notification portal. Registration with the CCB and access credentials are prepared in quiet times, not during the crisis.
  4. No reliable timestamping. Without a register, you can neither prove you notified in time nor date your own awareness.
  5. No notification template. Drafting the company's first official communication under stress, from a blank page, costs hours.

What you need ready: one page

The good news is that preparation does not require a project. It fits on one page, posted where people will find it, answering six questions: who qualifies the incident, against which criteria, who notifies, through which channel and with which credentials, where the register lives, and who informs the board.

A company with that page holds the 24 hours. A company without it will hold them by luck, once.

How Prism GRC structures the response inside Odoo

Prism GRC is a native Odoo module. The incident log is not one more spreadsheet: it is connected to the assets, risks and controls already mapped. Concretely:

  • Timestamped incident capture at the moment of awareness, with its author, which fixes and documents the start of the clock.
  • Qualification criteria built into the form, so the "significant or not" decision is guided and traced rather than left to the mood of the moment.
  • The 24h / 72h / one-month deadlines computed automatically, with an owner and reminders, so nobody has to remember the calendar during a crisis.
  • Root cause analysis and corrective actions attached to the incident, feeding the final report directly.
  • The link to affected assets, which surfaces recurrence: three incidents on the same asset in six months is a control that does not hold.
  • The Odoo chatter keeping the full chronology of exchanges and decisions, which is exactly what an auditor will ask for afterwards.

Frequently asked questions

Do you have to notify an incident that ended up having no impact?

The criterion includes what is capable of causing severe disruption. A blocked attempt generally falls outside scope, while a narrowly contained compromise may fall inside. That is exactly why criteria must be written in advance: the decision has to be explainable after the fact.

Who has to notify in Belgium?

Essential and important entities under the Belgian law transposing NIS2, which must also be registered with the CCB. If you do not know your classification, that is the first thing to settle, before the incident procedure.

Does cyber insurance replace notification?

No. They are two separate obligations, with two counterparties and two calendars. Your insurer also has its own reporting deadlines, often short: prepare both circuits together.

Take action

Prism Technology is an official Odoo partner in Belgium, based in Walloon Brabant. We built Prism GRC, a native Odoo module for managing risks, controls, incidents and compliance. In 30 minutes, we walk through your notification procedure as it stands today and identify what would push you past the 24-hour mark.

👉 Book your 30-minute demo — Contact us

CyFun: The Framework Belgium Chose for NIS2
Small, Basic, Important, Essential: which level applies to you