← All guides

NIS2 tabletop exercise: rehearsing the 24-hour, 72-hour and one-month deadlines

October 7, 2026 · 4 min read · Also in Spanish

What NIS2 asks for (Articles 20, 21 and 23), how to build an exercise around the reporting deadlines, and what evidence to keep.

A NIS2 tabletop exercise rehearses, with the people who would have to make the calls, a significant incident under the directive's clock: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month of that notification. It is the cheapest way to find out whether your team can meet those deadlines before a real incident tests it.

This guide explains what NIS2 asks for, how to build a scenario around the deadlines, and what to keep as evidence. It is not legal advice: NIS2 is a directive, so the exact obligations come from your country's transposing law and your competent authority.

What NIS2 asks of an organization

Three parts of the directive (EU) 2022/2555 matter for an exercise:

  • Article 21: risk-management measures. They include incident handling, business continuity and crisis management (backups and disaster recovery among them), and policies to assess whether the measures work.
  • Article 23: reporting obligations. For a significant incident: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, an intermediate report if the CSIRT or authority asks, and a final report no later than one month after the incident notification.
  • Article 20: governance. Management bodies approve the measures, oversee them and can be held liable for infringements; their members are required to follow training.

NIS2 doesn't use the word "tabletop". But an exercise is the most direct way to show that incident handling and crisis management work in practice, and that your leadership has been trained to make the calls.

What counts as a significant incident

Article 23(3) defines it as one that has caused, or can cause, severe operational disruption or financial loss for the entity, or considerable material or non-material damage to others. Deciding whether an incident crosses that line is itself one of the hardest calls, and a good exercise makes the team make it on the clock.

Building the scenario around the clock

A NIS2 exercise works best when each event lands at a deadline:

  1. Hour 0 to 24: awareness and the early warning. The SOC sees something odd; an hour later, a supplier reports the same. Is it significant? Who decides? Does the early warning go out, and does it say whether the cause may be malicious or cross-border, as the directive asks?
  2. Hour 24 to 72: the incident notification. The picture is clearer: systems affected, an estimate of the impact, indicators of compromise. Who drafts the notification, who approves it, and does legal agree with security on the severity?
  3. Day 3 to one month: the final report. Root cause, mitigation, cross-border impact. Who owns it, and what has changed since day 3?

Add pressure that real incidents bring: a journalist calls, a key customer asks for a statement, the CEO is travelling. Ransomware, a supplier compromise and a DDoS with extortion all fit well. See the ransomware tabletop for the board for a ready scenario you can map to these deadlines.

Who should take part

NIS2 puts the management body on the hook, so the exercise should too:

  • CEO or general manager: owns the business decisions and, under Article 20, the oversight.
  • CISO: the technical picture and the significance assessment.
  • Legal / compliance: the notification content and the national authority.
  • Communications: customers, press and the public statement.
  • Finance / operations: the cost of stopping, and of not stopping.

If one of them can't attend, decide in advance who covers, and test that too.

What to keep as evidence

After the exercise you should be able to show:

  • The decision log, with times: when the incident was judged significant, when each notification would have gone out, who approved it.
  • Missed or late decisions, especially against the 24h and 72h marks.
  • Who attended, including management body members (useful for Article 20).
  • Gaps and an action plan, each with an owner and a date.

Your auditor or authority decides what meets a requirement; the exercise gives them something concrete to look at.

Frequently asked questions

Does NIS2 require a tabletop exercise?

Not by name. It requires incident handling, business continuity and crisis management measures, a way to assess their effectiveness, and training for management bodies. A documented exercise is a common way to evidence all of them.

How often should we run one?

At least once a year is a sensible baseline, plus after major changes or a real incident. Your national law or authority may set more specific expectations.

Is it different from a DORA exercise?

The idea is the same, but the deadlines and the scope differ. Financial entities under DORA have their own reporting timeline and an explicit yearly testing duty; see the DORA scenario testing guide.


Critios runs NIS2-style exercises with your leadership team: private, timed decisions per role, escalations that follow what the team chose, and a report with the decision log, attendance and control coverage, including a NIS2 view. Try the demo or simulate your crises with us.

Run this exercise with your team, free.

We facilitate the first session with your executives and send you the report.