You have 24 hours. That is how long the law gives you to notify DNSC after discovering a significant incident.
The full timeline required by NIS2 (GEO 155/2024) is:
- 24 hours — initial warning
- 72 hours — detailed notification, with an impact assessment
- 30 days — final report
The uncomfortable question: if tomorrow morning you find your files encrypted, who in your company knows what happened, how serious it is and how to report it — all within 24 hours? For most small companies, the honest answer is "nobody".
That is exactly why the outsourced NIS officer exists: someone who takes over the reporting procedure while you deal with the real emergency — getting the company back on its feet.
Sources
This article was generated with AI assistance.