The notification duty under the Cyberbeveiligingswet: 24 hours, 72 hours, one month
Published · Updated
The notification duty requires essential and important entities to report a significant incident in three stages: an early warning within 24 hours, a notification within 72 hours and a final report within one month of the notification. The duty is set out in articles 25 to 29 of the Cyberbeveiligingswet (Cbw) and has applied since 15 August 2026.
The misunderstanding that comes up most often is that the duty has a single 24-hour deadline. Those 24 hours are only the first of three stages. This article explains when you have to report, what each stage contains and where the report goes.
When is an incident significant?
Not every incident has to be reported, only a significant one. The Act defines it by its effect, not its cause. An incident is significant if it causes or can cause severe operational disruption of your services or financial loss for your organisation, or if it has affected or can affect other organisations by causing considerable material or non-material damage.
That definition is in article 25 of the Act and is worked out in article 23 of the Cyberbeveiligingsbesluit. Concrete thresholds per sector are set in ministerial regulations, and according to the NCSC they differ by sector. Some of them are still being worked out. For the digital sector the thresholds are already fixed in an EU implementing regulation. Until your sector's regulation exists, you assess yourself whether an incident meets the definition.
Stage 1: early warning, within 24 hours
As soon as possible, and in any event within 24 hours of becoming aware of the significant incident, you issue an early warning. It does not need to give the full picture yet. It states whether the incident is suspected to have been caused by an unlawful or malicious act, and whether it could have cross-border consequences.
Stage 2: notification, within 72 hours
Within 72 hours the notification itself follows. In it you update the early warning and give an initial assessment of the severity and impact of the incident and, where available, the indicators of compromise. Trust service providers have a shorter deadline: if the incident affects their trust service, they submit this notification within 24 hours.
Interim report, on request
The CSIRT or the supervisor can ask for a report on the state of affairs in between. It is not a fixed stage, but expect the request to arrive while you are still in the middle of handling the incident.
Stage 3: final report, within one month
No later than one month after the stage 2 notification you submit a final report. It describes the incident, its severity and impact, the likely root cause and the measures you have taken to limit its consequences.
Where do you report?
You report through one portal: mijn.ncsc.nl. A report there reaches your sector CSIRT and your supervisor at the same time; you do not need to inform them separately. Which CSIRT that is depends on your sector. As a rule it is the NCSC; for healthcare it is Z-CERT, for the water authorities and waste water CERT-WM, and for municipalities the IBD.
The reporting portal belongs to the same environment in which you register in the national entity register. That registration is a maintained record, not a one-off form: you report any change, such as new contact details, IP ranges or domain names, within two weeks. If your registration is out of date, the CSIRT may reach the wrong person during an incident, exactly when every hour counts.
Three misunderstandings
- A single 24-hour deadline. There are three stages: 24 hours, 72 hours and one month after the notification.
- Reporting separately to the supervisor. One report through mijn.ncsc.nl reaches the CSIRT and the supervisor together.
- Reporting only once everything is known. The early warning is meant for the moment when you do not yet know everything.
What has to be ready before something goes wrong
The notification duty is hard to improvise. A 24-hour deadline leaves no room to work out during an incident who decides and who has access to the portal. Incident handling is therefore itself one of the ten elements of the duty of care, element (b) of article 21, worked out in article 8 of the Cyberbeveiligingsbesluit.
- Documented procedures for detection, analysis, notification and recovery.
- A recorded decision on who assesses whether an incident is significant, and on what basis.
- Access to mijn.ncsc.nl for the people who report, and a deputy for each of them.
- A log that records from the first signal what was established when, so the deadlines can be shown to have been met.
- An exercise, so the first real report is not also the first attempt.
What is at stake
Failing to meet the notification duty falls in the same, highest fine band as the duty of care. For an essential entity the maximum fine is EUR 10 million or 2% of the worldwide annual turnover of the undertaking it belongs to, for an important entity EUR 7 million or 1.4%, whichever is higher. What usually weighs more than the fine is the question the supervisor asks after an incident: can you show that you reported on time and in full?
Read alsoDoes the Cyberbeveiligingswet apply to your organisation?
Reporting is one of three duties
Registration, the duty of care and the notification duty belong together. See how we set them up and keep the evidence current.
See how we set up the duty of care