IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

Reading about the section 32 reporting cascade? An Indicium report documents who holds the key roles in your reporting chain, with dated sources and human final review.

NIS2 incident reporting: deadlines under section 32 BSIG

Section 32 BSIG sets three reporting deadlines for significant incidents: early warning in 24 hours, notification in 72 hours, final report in one month.

Under § 32 BSIG, a significant incident sets a three-step reporting cascade in motion: an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month. If the incident is still ongoing at the one-month mark, a progress report stands in until closure. The duty binds particularly important and important entities under § 28 BSIG, and every clock starts at the same legal moment: the point at which an employee of the organisation becomes aware.

What counts as a reportable incident under § 32 BSIG?

The statute ties the duty to the “significant incident”. It does not ask whether every anomaly is reportable; it asks the entity to assess significance under time pressure, because the first deadline runs from awareness, not from the end of an investigation. Two questions structure that assessment, and both belong in the first report: whether unlawful or malicious action is suspected, and whether the incident could have cross-border impact.

Whatever the entity concludes about significance, it must be able to show the assessment. § 30(1) sentence 3 BSIG requires the compliance of risk-management measures to be documented, and the BSI compares that duty to the accountability principle of the GDPR. An incident dismissed as minor leaves the same paper trail as one escalated to the reporting office, and a decision that exists only in memory is a decision that cannot be defended later.

The three deadlines: 24 hours, 72 hours, one month

Three reports of increasing depth, each with its own clock:

  • Early warning (§ 32(1) Nr. 1 BSIG), 24 hours: the first report after awareness. It must state whether unlawful or malicious action is suspected and whether cross-border impact is possible.
  • Incident notification (§ 32(1) Nr. 2 BSIG), 72 hours: confirms and updates the early warning, contains a first assessment of severity and impact, and lists indicators of compromise.
  • Final report (§ 32(1) Nr. 4 BSIG), one month: due one month after the notification. It describes the incident in detail, including severity, the root cause or type of threat, remediation measures and cross-border effects.

Two safety valves sit in the same provision. If the incident is still ongoing when the month ends, a progress report replaces the final report, which then follows after closure (§ 32(2)). The BSI can also request interim status reports at any time. Once a report arrives, the BSI confirms receipt promptly, at the latest within 24 hours of submission.

Who must report, and to which authority?

Both entity categories of the recast BSIG are covered: particularly important entities and important entities within the meaning of § 28 BSIG. Reports go to the joint reporting office of BSI and BBK. The duty applies at the earliest from the establishment of the reporting channel; in practice that point has arrived, because the BSI reporting portal has been open since 6 January 2026.

One carve-out matters for banks and insurers: entities fully regulated under DORA are exempt from the § 32 duty by § 28(6) BSIG, alongside §§ 30, 31, 35, 36, 38 and 39. Their incident reporting runs through the DORA framework instead. For everyone else, self-assessment under § 28 decides the question, and no authority notifies an entity that it is covered; the overview article on NIS2 in Germany covers scope and registration.

KRITIS operators carry an additional operational duty: their registered contact point must be reachable around the clock, and violations carry their own fine tier. The KRITIS regime sits alongside the BSIG; the sector logic is explained in What is KRITIS: sectors, thresholds, duties.

What happens if a deadline is missed

Lateness is the sanctionable defect, not incompleteness. A notification within 72 hours may be incomplete if the incompleteness is justified; what the law punishes is filing late. Violations of § 32 sit in the highest penalty tier of § 65 BSIG, the same tier as failures of the core risk-management duties.

The arithmetic also works against late filers. All deadlines run from awareness, not from the first report. An early warning filed on day two leaves less than the full window for the incident notification, because that clock keeps running from the original moment of awareness. The BSI states plainly that the maxima should not be exhausted. The practical conclusion: the reporting process must exist before the incident, with templates for each stage and a decision path that works under pressure.

The personnel angle: who sets the clock running

Every clock in § 32 starts with human awareness. The BSI’s guidance reads the deadlines from the point at which an employee gains knowledge within working hours, which means any staff member who notices an anomaly can legally start the cascade. A reporting chain that depends on a single specialist who happens to be on holiday is not a reporting chain.

Three duties of the BSIG speak directly to this. Basic training and awareness measures are a prescribed measure area of their own (§ 30(2) Nr. 7 BSIG): staff must be able to recognise what an incident looks like. Incident handling is a mandatory measure area as well, so triage and escalation belong in the documented concept. And § 30(2) Nr. 9 BSIG requires concepts for personnel security, which is where the reporting chain is staffed: the roles that carry escalation, triage and the 24-hour decision deserve proportionate screening before they are filled.

European law gives the citable basis. Recital (22) of Commission Implementing Regulation (EU) 2024/2690 states that reliability checks can include querying a person’s criminal record or reviewing past professional performance, where appropriate to the person’s tasks. In standards language, screening maps to A.6.1 of ISO/IEC 27001:2022. Operationally, this is structured, documented, reviewable verification of key personnel, drawing on registry data, sanctions lists, adverse media and employment history, with a human making the final call. Indicium provides this verification class as software reports with dated sources and human final review. What the personnel-security duty of § 30 BSIG requires in detail, from hiring through role changes to service providers, is covered in NIS2 Personnel Security: the duties under § 30 BSIG.

Frequently asked questions

What belongs in the early warning within 24 hours?

Above all two statements: whether unlawful or malicious action is suspected, and whether cross-border impact is possible (§ 32(1) Nr. 1 BSIG). The early warning is deliberately lean so that speed wins over completeness.

When does the 72-hour clock start: from knowledge or from the first report?

From knowledge. All three deadlines run from the moment the organisation becomes aware, not from the first report, so a late early warning shortens the remaining window for the full notification.

What applies if the incident is still ongoing after one month?

A progress report replaces the final report and describes the current status (§ 32(2) BSIG). The final report is due after the incident is closed. The BSI can additionally request interim status reports.

Is a justified incomplete notification after 72 hours permissible?

Yes. The notification may be incomplete if the incompleteness is justified; the sanctionable defect under § 32 BSIG is lateness. Violations nonetheless sit in the top penalty tier of § 65 BSIG.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built – from name to verdict in minutes, not weeks.

Book a demo See a sample report