Skip to main content
Free resource · NIS2, DORA & GDPR

Incident Reporting Toolkit for NIS2, DORA & GDPR

One incident. Three reporting obligations. One practical reference for deciding who to notify, and by when.

  • Cross-regulation reporting cheat sheet
  • Worked reporting example
  • Practical reporting workflow
  • Editable Incident Report Template (Word)
— 01 · Incident reporting decision flow

Reporting obligations are separate

One incident can trigger more than one reporting duty.

One incident
NIS2

Impacts essential services

DORA

Disrupts ICT services in the financial sector

GDPR

Exposes personal data

One notification does not automatically cover the others.

Each regulation has its own trigger, deadline, authority, and documentation expectations.

Before you decide what to report, confirm four things first

Scope

Whether your organization is in scope for NIS2, DORA, GDPR, or more than one.

Threshold

Whether the incident meets the reporting threshold.

Authority

Which authority must receive the notification.

Ownership

Who owns the decision internally.

— 02 · The cheat sheet

Cross-regulation incident reporting cheat sheet

NIS2, DORA, and GDPR each use different triggers, timelines, and authorities. This is the comparison the toolkit walks through in full.

Reporting requirement
NIS2
DORA
GDPR
Reporting trigger
Significant cybersecurity incident affecting covered services
Major ICT-related incident
Personal data breach creating risk to individuals
First notification
Early warning within 24 hours
4 hours from classification, 24h backstop from detection
Notify the supervisory authority within 72 hours
Final report
Within 1 month
Within 1 month
No formal final report required
Notify
National CSIRT or Competent Authority
Financial supervisory authority
National Data Protection Authority

Treat NIS2, DORA, and GDPR as separate reporting decisions — the same incident facts can support more than one notification.

Worked example: one incident, three reporting tracks

A regional bank suffers a ransomware attack. Online banking is unavailable for four hours, internal systems are encrypted, and customer personal data may have been accessed.

The toolkit walks through this scenario end to end — starting from the incident facts, not the regulation, and assessing NIS2, DORA, and GDPR independently before deciding which notifications are required.

— 03 · Inside the toolkit

What's inside the Incident Reporting Toolkit

Reporting cheat sheet

A side-by-side comparison of reporting triggers, timelines, follow-up reports, and supervisory authorities under NIS2, DORA, and GDPR.

Worked reporting example

A ransomware scenario assessed step by step, showing how one incident can trigger reporting obligations under all three regulations at once.

Practical reporting workflow

A step-by-step process for determining applicable regulations, recording deadlines, and assigning ownership before an incident is closed.

Ownership & deadline tracker

A simple table for assigning incident investigation, regulatory notifications, executive approval, and evidence collection to named owners.

Editable Incident Report Template

A Word template for documenting incident details, applicable regulations, reporting deadlines, ownership, and supporting evidence.

Don't decide reporting obligations mid-incident

Download the toolkit and know which authority to notify, and by when, before the next incident lands.

Download the Incident Reporting Toolkit
— 04 · Why it works

Why incident response teams use this toolkit

One reference for three regulations

Stop switching between the NIS2 directive, DORA technical standards, and GDPR guidance mid-incident — the comparison is already done.

Don't miss a deadline or an authority

NIS2, DORA, and GDPR each notify a different authority on a different clock. The cheat sheet keeps all three visible at once.

Assign ownership before an incident hits

Investigation, notifications, executive approval, and evidence collection each need a named owner — decide who, in advance.

An editable template, ready to use

The Word template documents incident details, applicable regulations, deadlines, and evidence in one consistent structure every time.

— 05 · FAQ

Frequently asked questions

How are NIS2, DORA, and GDPR reporting obligations different?

They ask different questions about the same incident. NIS2 looks at whether the incident affected the security or continuity of an essential or important service. DORA looks at whether an ICT incident affected a regulated financial entity. GDPR looks at whether personal data was exposed. Each has its own trigger, timeline, and authority.

Can one incident require reporting under more than one regulation?

Yes. A ransomware attack, for example, can disrupt services, affect ICT operations, and expose personal data at the same time — which is why the toolkit treats each regulation as a separate reporting decision rather than a single yes/no question.

What's in the editable Incident Report Template?

An incident details worksheet, an applicable-regulation assessment covering NIS2, DORA, and GDPR, a reporting deadline tracker, a notification ownership table, and an evidence checklist — all in an editable Word file.

Who is this toolkit for?

Incident response, security, legal, and compliance teams who need to decide — quickly and correctly — which regulators to notify after a cybersecurity incident, and by when.

Does this toolkit replace legal advice?

No. It's a practical reference for triaging reporting obligations during an incident. For a specific reporting decision, or to prepare your process in advance, Q-Sec can walk through your obligations with you.

— 06 · Beyond the toolkit

Unsure which reporting obligations apply to you?

Q-Sec helps organizations assess regulatory reporting requirements during cybersecurity incidents and prepare incident response processes before supervisory authorities become involved.

Request a readiness review