Incident reporting deadlines

A manager's dashboard that gathers every outstanding regulatory notification deadline across your incidents into one countdown list.

When a security incident may also be a reportable event under law, the clock starts at detection. NIS2 (a European cybersecurity law) expects an early warning within 24 hours, a fuller notification within 72 hours and a final report within a month. GDPR (the European data-protection law) expects a personal-data breach to reach the supervisory authority within 72 hours. DORA (the European rules for financial-sector operational resilience) adds initial, intermediate and final reports for major ICT incidents. The Incident Reporting Dashboard at /incidents/reporting collects those obligations and counts each one down.

This screen tracks. It does not log incidents and it sends no notifications: you record the incident, decide whether it is significant and mark a notification as sent on the incident itself — see Incidents. Here you watch all of those clocks at once and step into whichever one needs attention.

Who uses it

The route checks the INCIDENT_READ permission, then confirms the role is Manager or Admin; if either check fails you are redirected to the incident list rather than shown an error. The data also requires the Incidents module to be active for your organisation.

What's on this screen

The dashboard fills the main area to the right of the left menu. At the top, the heading Incident Reporting Dashboard sits above the sub-line Regulatory reporting obligations — NIS2 and GDPR deadline tracking, with a Back to Incidents link on the far right.

Below the heading are four summary cards, each a large number over a label: Overdue (red), Due within 24h (orange), On Track (green) and Total Active (blue). In the demonstration tenant captured below they read 3, 0, 0 and 3 — three obligations, all of them already past their date.

Under the cards is a row labelled Framework: with three buttons — All, NIS2 and GDPR — the selected one filled in indigo. Then comes the Active Deadlines panel: a table with the columns INCIDENT, FRAMEWORK, STAGE, DEADLINE and STATUS, plus an unlabelled final column holding a View link on every row. The incident name and the View link both open that incident's detail page.

In the capture the three rows all belong to one seeded incident, Vendor Audit Finding - 2026-02-07, and show its three NIS2 stages — Early Warning (24h), Incident Notification (72h) and Final Report (1 month) — each with a red overdue age such as 199 days 6 hours ago and a red Overdue chip. That is demonstration data, not a real backlog.

Nothing else is on the page: no export, no bulk action and no way to record a notification from here. A Completed Notifications panel appears below the table once at least one obligation has been fulfilled; there are none in this capture, so the page ends at the table.

Open the dashboard

  1. In the left menu, open the SECURITY INCIDENTS group and choose Reporting (or type /incidents/reporting straight into the address bar). The dashboard loads with the four summary cards, the framework buttons and the Active Deadlines table.
  2. Note that the separate REPORTING group further down the menu is for cross-module reports and board packs — this deadline view does not live there. See Reports for that group.
  3. Select the help ? in the top bar to open the in-app guidance for the screen you are on.
  4. Check the name in the top-right corner. Only a Manager or an Admin sees this page; a Viewer or Contributor has no Reporting entry in the menu and is returned to /incidents if they type the address.
The Incident Reporting Dashboard — summary cards, framework filter and the Active Deadlines table — /incidents/reporting.
The Incident Reporting Dashboard — summary cards, framework filter and the Active Deadlines table — /incidents/reporting.

Read the summary cards

The four cards answer the first question: how bad is it right now?

Card What the count means
Overdue Obligations whose date has passed with no notification recorded. Work these first.
Due within 24h Obligations falling due in the next 24 hours.
On Track Everything else — not overdue and more than 24 hours away.
Total Active Every outstanding obligation combined — the sum of the other three cards.

One incident can contribute several rows and several counts: an incident that is both a NIS2 significant incident and a GDPR breach produces a deadline for each framework and each stage — which is why one seeded incident fills all three rows above.

The cards and the row chips use different bands

The cards split into overdue, within 24 hours and everything else. The STATUS chip in each row is finer: Overdue, Urgent (within 24 hours), Due Soon (within 72 hours) and On Track (more than 72 hours away). A deadline two days out therefore counts towards the green On Track card while its row reads Due Soon. Read the row when you plan the work.

Filter by framework

  1. Select NIS2 to narrow the table to NIS2 obligations, or GDPR for the 72-hour authority notifications that follow a personal-data breach. The button you choose fills in indigo and the table redraws immediately.
  2. Select All to return to the combined view. If the chosen framework has no outstanding obligations, the panel shows a short "no deadlines" line in place of the table rather than an empty grid.

The filter changes the two tables only — the summary cards always count every active obligation. Only NIS2 and GDPR have buttons. DORA stages for major ICT incidents appear under All but cannot be isolated here; use DORA for that module's own view.

Work an overdue deadline

  1. Read the STATUS column and start at the top. The table is sorted by urgency, so the most pressing obligation is always the first row.
  2. Read STAGE and DEADLINE together to see which notification is due and by how far it is ahead or behind — for example Early Warning (24h) and 199 days 6 hours ago.
  3. Select the incident name, or the View link at the end of the row, to open that incident's detail page in the same tab.
  4. On the incident, record what actually happened: use the GDPR notification action for a data breach, or the NIS2 significance assessment and its stage actions for a NIS2 obligation. See Incidents for both flows.
  5. Return to the dashboard. Once a notification is recorded against the incident, that row leaves Active Deadlines and reappears under Completed Notifications.

Review completed notifications

The Completed Notifications panel is only rendered when at least one obligation has been fulfilled for the current framework filter, which is why it is absent from the capture above. When it is there, the header reads Completed Notifications followed by the count in brackets; select it to expand the panel. Each row lists the incident, the framework, the stage, Sent At, Sent To (a dash when no recipient was recorded) and a status of On Time or Late. Rows are ordered most recent first. This is the record to reach for when an auditor asks what was reported, to whom and when.

The deadline banner follows you around

Urgent deadlines are announced on every page

When an obligation is overdue or within 24 hours, Managers and Admins see a coloured banner at the top of every Aegis page, not only this one. It names the most urgent obligation and offers links to the affected incident and back to this dashboard. Dismissing it hides it for 30 minutes in that browser tab; it returns while the deadline is still open. Viewers and Contributors never see it.

The AI assist

This dashboard does no AI work of its own — it counts deadlines that already exist. The AI step happens earlier, on the incident: when you assess whether an incident is a NIS2 significant incident, Aegis can offer a likely-significant verdict with its reasoning and a confidence score. A person reviews that suggestion and decides. Recording the decision as significant is what creates the NIS2 deadlines you then see here. The AI never marks an incident significant on its own, and it never sends a notification.

Tips and limits

Where this connects