Law / European Union

Commission Implementing Regulation (EU) 2024/2690, Significant Incidents under NIS2 Article 23

Regulation (EU) 2024/2690, Arts. 3 to 14

In force since .

A vulnerability and incident reporting rule binding public and private bodies.

Obligation class
Reporting

As of .

What it requires

  • This duty reaches you if you declare that you are an essential or important entity under Article 3 of Directive (EU) 2022/2555 and provide a service Article 1 names: a DNS service provider, top-level domain (TLD) name registry, cloud computing service provider, data centre service provider, content delivery network provider, managed service provider, managed security service provider, provider of an online marketplace, online search engine or social networking services platform, or trust service provider. Under Article 2 of that Directive you are in scope if you are a medium-sized enterprise or larger, or, whatever your size, if you are a trust service provider, a TLD name registry or a DNS service provider, or if Article 2(2), points (b) to (e), applies to you.
  • Treat an incident as significant, and notify it under Article 23 of Directive (EU) 2022/2555, where it fulfils one or more of the criteria of Article 3(1): direct financial loss, caused or capable of being caused, that exceeds EUR 500,000 or 5 percent of your total annual turnover in the preceding financial year, whichever is lower; the exfiltration of your trade secrets; the death of a natural person or considerable damage to a natural person's health; a successful, suspectedly malicious and unauthorised access to your network and information systems that is capable of causing severe operational disruption; or the recurring-incident rule or a criterion for your class of entity.
  • Apply the criteria that Articles 5 to 14 set for your class of entity: Article 5 for DNS service providers, Article 6 for TLD name registries, Article 7 for cloud computing service providers, Article 8 for data centre service providers, Article 9 for content delivery network providers, Article 10 for managed service providers and managed security service providers, Articles 11 to 13 for providers of online marketplaces, online search engines and social networking services platforms, and Article 14 for trust service providers.
  • Treat incidents that are individually not significant as one significant incident where they occurred at least twice within 6 months, have the same apparent root cause, and collectively meet the financial loss criterion of Article 3(1), point (a) (Article 4).
  • Treat yourself as aware of a significant incident, for the clock Article 23(4) of Directive (EU) 2022/2555 sets, when after your initial assessment you have a reasonable degree of certainty that a significant incident has occurred (recital 31).
  • Do not treat scheduled interruptions of service or the planned consequences of scheduled maintenance operations carried out by or on your behalf as significant incidents (Article 3(2)).
  • When you calculate the number of users impacted by an incident under Articles 7 and 9 to 14, consider the number of customers that have a contract with you granting access to your network and information systems or services, and the number of natural and legal persons associated with business customers that use them (Article 3(3)).

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Article 34(4) of Directive (EU) 2022/2555: where an essential entity infringes Article 21 or 23, it is subject to an administrative fine of a maximum of at least EUR 10,000,000 or at least 2 percent of total worldwide annual turnover, whichever is higher. Article 34(5) sets a lower tier for an important entity, a maximum of at least EUR 7,000,000 or at least 1.4 percent of turnover, whichever is higher. The fine tiers that apply to an infringement of the notification duty whose significant-incident cases this Regulation specifies under Article 23(3) are those of Article 34. The figures are the floor each Member State's own transposing law must set as its statutory maximum, not a cap the Union applies directly.

Rule
Higher of
As of
Currency
EUR
Fixed cap
10,000,000
Turnover percentage cap
2

Who enforces it

Enforcement body

The competent authority designated or established by each EU Member State under Article 8 of Directive (EU) 2022/2555, which supervises compliance and applies the Chapter VII enforcement measures, with incident notifications received by the CSIRT designated under Article 10 or, where applicable, by the competent authority, and coordination at Union level through the NIS Cooperation Group and the CSIRTs network.

Settledness

As of

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Article 3(1) makes an incident significant, for the purposes of Article 23(3) of Directive (EU) 2022/2555 and with regard to the relevant entities, where one or more of the criteria in points (a) to (g) are fulfilled. Point (a) is direct financial loss, caused or capable of being caused, that exceeds EUR 500,000 or 5 percent of the entity's total annual turnover in the preceding financial year, whichever is lower.

Points (b) to (d) cover an incident that has caused or is capable of causing the exfiltration of trade secrets, the death of a natural person, or considerable damage to a natural person's health, and point (e) covers a successful, suspectedly malicious and unauthorised access to network and information systems that is capable of causing severe operational disruption. Points (f) and (g) bring in the recurring incidents of Article 4 and the criteria of Articles 5 to 14 for each class of entity.

Recital 30 states that the criteria in the Regulation should be considered exhaustive, without prejudice to Article 5 of Directive (EU) 2022/2555. Recital 31 states that an entity is regarded as aware of a significant incident when, after its initial assessment, it has a reasonable degree of certainty that a significant incident has occurred.

Article 3(2) excludes scheduled interruptions of service and the planned consequences of scheduled maintenance operations carried out by or on behalf of the entities.

For the user-based criteria of Articles 7 and 9 to 14, Article 3(3) requires an entity calculating the number of users impacted to consider the number of customers that have a contract giving them access to its network and information systems or services, and the number of natural and legal persons associated with business customers that use them.

Article 4 treats incidents that are individually not significant as one significant incident where they occurred at least twice within 6 months, have the same apparent root cause, and collectively meet the financial loss criterion of Article 3(1), point (a).

Article 5 makes an incident significant for a DNS service provider where a recursive or authoritative domain name resolution service is completely unavailable for more than 30 minutes, where for more than one hour the average response time of such a service to DNS requests is more than 10 seconds, or where the integrity, confidentiality or authenticity of data related to the authoritative resolution service is compromised, except where the data of fewer than 1,000 domain names, amounting to no more than 1 percent of the domain names the provider manages, are not correct because of misconfiguration.

Article 6 makes an incident significant for a top-level domain (TLD) name registry where an authoritative domain name resolution service is completely unavailable, where for more than one hour the average response time of such a service to DNS requests is more than 10 seconds, or where the integrity, confidentiality or authenticity of data related to the technical operation of the TLD is compromised.

Article 7 makes an incident significant for a cloud computing service provider where a cloud computing service is completely unavailable for more than 30 minutes, where its availability is limited for more than one hour for more than 5 percent of its users in the Union or for more than 1 million of them, whichever number is smaller, where the integrity, confidentiality or authenticity of related data is compromised as a result of a suspectedly malicious action, or where it is compromised with an impact on more than 5 percent of its users in the Union or on more than 1 million of them, whichever number is smaller.

Article 8 makes an incident significant for a data centre service provider where a data centre service of a data centre it operates is completely unavailable, where its availability is limited for more than one hour, where the integrity, confidentiality or authenticity of related data is compromised as a result of a suspectedly malicious action, or where physical access to a data centre it operates is compromised.

Article 9 makes an incident significant for a content delivery network provider where a content delivery network is completely unavailable for more than 30 minutes, where its availability is limited for more than one hour for more than 5 percent of its users in the Union or for more than 1 million of them, whichever number is smaller, where the integrity, confidentiality or authenticity of related data is compromised as a result of a suspectedly malicious action, or where it is compromised with an impact on more than 5 percent of its users in the Union or on more than 1 million of them, whichever number is smaller.

Article 10 applies to managed service providers and managed security service providers the same four criteria and figures as Article 9, measured against the users of the managed service or managed security service in the Union.

Article 11 makes an incident significant for a provider of an online marketplace where the marketplace is completely unavailable for more than 5 percent of its users in the Union or for more than 1 million of them, whichever number is smaller, where more than 5 percent of its users in the Union, or more than 1 million of them, whichever number is smaller, are impacted by its limited availability, where the integrity, confidentiality or authenticity of related data is compromised as a result of a suspectedly malicious action, or where it is compromised with an impact on more than 5 percent of its users in the Union or on more than 1 million of them, whichever number is smaller.

Article 12 applies the same four criteria and figures as Article 11 to a provider of an online search engine, measured against its users in the Union. Article 13 applies the same four criteria and figures as Article 11 to a provider of a social networking services platform, measured against its users in the Union.

Article 14 makes an incident significant for a trust service provider where a trust service is completely unavailable for more than 20 minutes, where it is unavailable to users or relying parties for more than one hour calculated on a calendar week basis, where more than 1 percent of the users or relying parties in the Union, or more than 200,000 of them, whichever number is smaller, are impacted by its limited availability, where physical access to an area where network and information systems are located and to which access is restricted to trusted personnel of the provider, or the protection of that access, is compromised, or where the integrity, confidentiality or authenticity of related data is compromised with an impact on more than 0.1 percent of users or relying parties, or more than 100 of them, whichever number is smaller.

When LexLint raises it

When your app profile says your app operates a social platform or runs an essential service.

Back to the example  ·  Lint your app