Incident Reporting Toolkit for NIS2, DORA & GDPR
One incident. Three reporting obligations. One practical reference for deciding who to notify, and by when.
- Cross-regulation reporting cheat sheet
- Worked reporting example
- Practical reporting workflow
- Editable Incident Report Template (Word)
Reporting obligations are separate
One incident can trigger more than one reporting duty.
Impacts essential services
Disrupts ICT services in the financial sector
Exposes personal data
One notification does not automatically cover the others.
Each regulation has its own trigger, deadline, authority, and documentation expectations.
Before you decide what to report, confirm four things first
Scope
Whether your organization is in scope for NIS2, DORA, GDPR, or more than one.
Threshold
Whether the incident meets the reporting threshold.
Authority
Which authority must receive the notification.
Ownership
Who owns the decision internally.
Cross-regulation incident reporting cheat sheet
NIS2, DORA, and GDPR each use different triggers, timelines, and authorities. This is the comparison the toolkit walks through in full.
Treat NIS2, DORA, and GDPR as separate reporting decisions — the same incident facts can support more than one notification.
Worked example: one incident, three reporting tracks
A regional bank suffers a ransomware attack. Online banking is unavailable for four hours, internal systems are encrypted, and customer personal data may have been accessed.
The toolkit walks through this scenario end to end — starting from the incident facts, not the regulation, and assessing NIS2, DORA, and GDPR independently before deciding which notifications are required.
What's inside the Incident Reporting Toolkit
Reporting cheat sheet
A side-by-side comparison of reporting triggers, timelines, follow-up reports, and supervisory authorities under NIS2, DORA, and GDPR.
Worked reporting example
A ransomware scenario assessed step by step, showing how one incident can trigger reporting obligations under all three regulations at once.
Practical reporting workflow
A step-by-step process for determining applicable regulations, recording deadlines, and assigning ownership before an incident is closed.
Ownership & deadline tracker
A simple table for assigning incident investigation, regulatory notifications, executive approval, and evidence collection to named owners.
Editable Incident Report Template
A Word template for documenting incident details, applicable regulations, reporting deadlines, ownership, and supporting evidence.
Don't decide reporting obligations mid-incident
Download the toolkit and know which authority to notify, and by when, before the next incident lands.
Download the Incident Reporting ToolkitWhy incident response teams use this toolkit
One reference for three regulations
Stop switching between the NIS2 directive, DORA technical standards, and GDPR guidance mid-incident — the comparison is already done.
Don't miss a deadline or an authority
NIS2, DORA, and GDPR each notify a different authority on a different clock. The cheat sheet keeps all three visible at once.
Assign ownership before an incident hits
Investigation, notifications, executive approval, and evidence collection each need a named owner — decide who, in advance.
An editable template, ready to use
The Word template documents incident details, applicable regulations, deadlines, and evidence in one consistent structure every time.
Frequently asked questions
How are NIS2, DORA, and GDPR reporting obligations different?
They ask different questions about the same incident. NIS2 looks at whether the incident affected the security or continuity of an essential or important service. DORA looks at whether an ICT incident affected a regulated financial entity. GDPR looks at whether personal data was exposed. Each has its own trigger, timeline, and authority.
Can one incident require reporting under more than one regulation?
Yes. A ransomware attack, for example, can disrupt services, affect ICT operations, and expose personal data at the same time — which is why the toolkit treats each regulation as a separate reporting decision rather than a single yes/no question.
What's in the editable Incident Report Template?
An incident details worksheet, an applicable-regulation assessment covering NIS2, DORA, and GDPR, a reporting deadline tracker, a notification ownership table, and an evidence checklist — all in an editable Word file.
Who is this toolkit for?
Incident response, security, legal, and compliance teams who need to decide — quickly and correctly — which regulators to notify after a cybersecurity incident, and by when.
Does this toolkit replace legal advice?
No. It's a practical reference for triaging reporting obligations during an incident. For a specific reporting decision, or to prepare your process in advance, Q-Sec can walk through your obligations with you.
Unsure which reporting obligations apply to you?
Q-Sec helps organizations assess regulatory reporting requirements during cybersecurity incidents and prepare incident response processes before supervisory authorities become involved.