What counts as a significant incident, the reporting ladder (early warning within 24 hours, incident notification within 72 hours, final report within one month), recipient authorities, and when service recipients must be informed.
The reporting obligations are triggered by a significant incident. An incident meets that threshold when it has caused, or is capable of causing, severe operational disruption to services or financial loss for the entity, or when it has affected, or is capable of affecting, other natural or legal persons by causing considerable material or non-material damage 32022L2555 Article 23@2022-12-27. Both prongs are framed in terms of capability, not just realised harm — an incident that could have caused severe disruption but was caught early still qualifies.
Entities that identify a significant incident must move through a structured sequence of notifications. The starting clock is awareness, not discovery of the root cause.
Without undue delay, and at the latest 24 hours after becoming aware of a significant incident, the entity must file an early warning with its national CSIRT (or, where applicable, the competent authority). The early warning must flag, where applicable, whether the incident is suspected of being caused by unlawful or malicious acts and whether it could have a cross-border impact 32022L2555 Article 23@2022-12-27. At this stage, detail is not required; the purpose is to put the authority on notice quickly enough to coordinate.
The CSIRT or competent authority shall provide, without undue delay and where possible within 24 hours of receiving the early warning, a response to the notifying entity, including initial feedback and, on request, guidance or operational advice on mitigation measures. If the incident appears criminal, the CSIRT or competent authority shall also provide guidance on reporting to law enforcement 32022L2555 Article 23@2022-12-27.
Within 72 hours of awareness, the entity must file a fuller incident notification. This document updates the early warning and adds an initial assessment of the incident's severity and impact, together with indicators of compromise where those are available 32022L2555 Article 23@2022-12-27.
Exception for trust service providers: trust service providers face a compressed timetable. For significant incidents affecting their trust services, the incident notification must reach the CSIRT or competent authority within 24 hours of awareness — not 72 32022L2555 Article 23@2022-12-27.
During an ongoing incident, the CSIRT or competent authority may at any point request intermediate status reports; entities must comply 32022L2555 Article 23@2022-12-27.
No later than one month after the incident notification, the entity must submit a final report. The report must include: a detailed description of the incident, its severity and impact; the type of threat or root cause likely to have triggered it; mitigation measures applied and still in progress; and, where relevant, an assessment of cross-border impact 32022L2555 Article 23@2022-12-27.
If the incident remains ongoing at the one-month mark, the entity submits a progress report at that time and then a final report within one month of closing the incident 32022L2555 Article 23@2022-12-27.
The primary addressee is the national CSIRT. Where the initial notification is received by the competent authority instead, that authority must forward it to the CSIRT without delay 32022L2555 Article 23@2022-12-27. For cross-border or cross-sectoral incidents, the national single point of contact must be supplied with the relevant information in due time 32022L2555 Article 23@2022-12-27. Where appropriate, and in particular where the significant incident concerns two or more Member States, the CSIRT, competent authority, or single point of contact must inform the other affected Member States and ENISA without undue delay, while preserving the reporting entity's security and commercial interests and the confidentiality of the information 32022L2555 Article 23@2022-12-27. Aggregated, anonymised data on significant incidents, incidents, cyber threats and near misses is also forwarded to ENISA by single points of contact on a quarterly basis 32022L2555 Article 23@2022-12-27.
Where appropriate, entities must notify the recipients of their services, without undue delay, of any significant incident that is likely to adversely affect the provision of those services 32022L2555 Article 23@2022-12-27. The threshold here is likelihood of adverse effect on service delivery — not mere possibility.
A parallel but distinct obligation covers significant cyber threats that have not yet materialised into incidents: where applicable, where a significant cyber threat could affect service recipients, the entity must communicate without undue delay to those recipients the measures or remedies they can take in response, and where appropriate must also inform them of the threat itself 32022L2555 Article 23@2022-12-27.
Notification does not expose the reporting entity to increased liability as a result of the act of notifying 32022L2555 Article 23@2022-12-27. This protection is explicit and is intended to remove a legal disincentive to timely disclosure.
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
No recent cases are cached for this topic.
1. An entity discovers a cyberattack that was intercepted before any service disruption occurred. Does the incident potentially qualify as "significant" for reporting purposes?
The lesson states both prongs are "framed in terms of capability, not just realised harm," so an incident caught early still qualifies. 32022L2555 Article 23@2022-12-27
2. What specific information must an early warning include, where applicable?
The lesson lists exactly those two items — suspected malicious cause and potential cross-border impact — as what the early warning must flag. 32022L2555 Article 23@2022-12-27
3. Within what deadline must a trust service provider submit its incident notification after becoming aware of a significant incident?
The lesson explicitly states that trust service providers face a "compressed timetable" of 24 hours for the incident notification rather than the standard 72 hours. 32022L2555 Article 23@2022-12-27
4. An incident is still unresolved when the one-month final-report deadline arrives. What must the entity do?
The lesson states that when an incident remains ongoing at the one-month mark the entity submits a progress report then, followed by a final report within one month of closing. 32022L2555 Article 23@2022-12-27
5. What is the threshold that triggers an entity's obligation to notify service recipients about a significant incident?
The lesson specifies the threshold is "likelihood of adverse effect on service delivery — not mere possibility," drawing a deliberate contrast with a lower possibility standard. 32022L2555 Article 23@2022-12-27