The clock runs from the moment of awareness, not from the attack — and it runs at night, on holiday and at the weekend. Four addressees need four different contents: the BSI, the data-protection authority, the customers, the management board. Teams that sort this out only during the incident lose the first hours to the question of who is even allowed to file.
Set the clock and test significance
The Incident Commander fixes the moment of awareness and derives every deadline from it as an absolute date-time. Both limbs of Art. 23(3) NIS2 are assessed separately — a one-sentence verdict, with the criterion that carries it.
Five notifications in parallel, each to its addressee
The early warning and the 72-hour notification to the BSI, the GDPR report to the supervisory authority, the customer notification under § 35 BSIG and the one-page board briefing under § 38 BSIG are drafted at the same time — each section headed with its legal basis.
Open stays open — and the release stays human
Every draft carries an explicit section on what is not yet established at this hour. The 24-hour early warning legally does not require a completed assessment. Filing and release are done by the entity, not by the platform.
Grounded in Directive (EU) 2022/2555 and its German transposition: BSIG 2025 (NIS2UmsuCG, in force since 06.12.2025) — §§ 28, 30–35, 38, 65 — plus GDPR Art. 33/34. Drafting support, not legal advice: reporting and release are the responsibility of the entity.
See it on your own use case.
30 minutes, scoped to your industry, frameworks and integrations. You leave with a concrete scenario — not a sales loop.