An Edge Built on Knowledge and Experience
NIS2 / BSIG § 32

NIS2 Reporting Obligations: Security Incidents to the BSI

Which incidents must be reported to the BSI, when, and with what content? We explain the three-stage reporting obligation under § 32 BSIG.

Technical & Legal Expertise Experience From Numerous NIS2 Projects Based in Sindelfingen
§ 32 BSIG

When Does a Reporting Obligation Arise?

Not every security event triggers a reporting obligation. Only significant security incidents within the meaning of § 2 No. 11 BSIG must be reported — events that have caused or could cause significant operational disruption or damage.

Not a Significant Incident

No reporting obligation, but internal documentation is recommended:

  • Spam email with no harmful effect
  • A single failed login attempt
  • Technical errors with no security relevance

Potentially Significant Incident

Assess immediately, check the reporting obligation:

  • Unknown software discovered on systems
  • Unusual data movements
  • Compromised access credentials

Significant Incident — Reportable

Reporting obligation triggered, deadlines start immediately:

  • Ransomware with system encryption
  • Data exfiltration with service outage
  • Attack with demonstrable operational disruption
Three-Stage Reporting Obligation

The Reporting Deadlines Under § 32 BSIG

The reporting obligation has three stages. Crucially, the clock starts the moment the entity becomes aware of a significant incident — not once the internal investigation is complete.

Stage 1 — 24 Hours
Early Warning
Initial notification to the BSI: incident confirmed, preliminary assessment, impact as far as known.
Stage 2 — 72 Hours
Detailed Notification
Updated information: cause, extent, countermeasures taken.
Stage 3 — 1 Month
Final Report
Complete analysis, root cause investigation, lessons learned, preventive measures.

A critical mistake in practice: Many companies wait to submit the initial notification until everything has been internally clarified. This breaches the 24-hour deadline. The early warning must be submitted even with incomplete information — missing details are not grounds for delay.

What the Notification Must Contain

Content of an NIS2-Compliant Incident Notification

Note: Many significant security incidents are simultaneously reportable data breaches under the GDPR. Both reporting paths must be served in parallel — which is why the data protection officer should be part of the incident team from the outset.

Related Topics

Further NIS2 Topics

Build Legally Sound Reporting Processes

We set up your internal reporting channels, train your incident team, and make sure you can meet all deadlines in a real incident.

Request Consultation Now
Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com