NIS2 doesn't require essential and important entities to report every disruption, failed login or blocked phishing email to their CSIRT. It requires them to correctly identify which incidents are "significant" and get that judgement right within a clock that starts ticking the moment they become aware of it. Article 23(3) of the Directive sets out exactly how that call is made, and it's a narrower, more specific test than most organisations assume.