24h
Early warning
Submit an initial early warning to your CSIRT or competent authority, indicating whether the incident is suspected to be caused by unlawful or malicious acts, or could have cross-border impact.
Incident reporting
When a significant incident occurs, the countdown starts. Entities must notify their CSIRT or competent authority in escalating stages — missing a deadline is itself a compliance failure.
24h
Submit an initial early warning to your CSIRT or competent authority, indicating whether the incident is suspected to be caused by unlawful or malicious acts, or could have cross-border impact.
72h
Update the early warning with an initial assessment — the severity and impact, and any indicators of compromise identified so far.
1 month
Within one month of the incident notification, submit a detailed report: the root cause, the mitigation applied and ongoing, and the full nature and impact of the incident.
Intermediate progress reports may be requested at any time, and the one-month clock for the final report runs from the 72-hour incident notification — not from the incident itself.
An incident is significant if it has caused, or is capable of causing:
Commission Implementing Regulation (EU) 2024/2690 sets quantitative thresholds for specific digital sectors, and national guidance may add further criteria.
Your national CSIRT, or the competent authority named in your transposition law. The CSIRT provides a response and, where relevant, coordinates across borders. Where appropriate, you must also inform the recipients of your services about a significant incident and the measures or remedies they can take.
A 24h / 72h / one-month process with clear owners is step five of the roadmap.
See the roadmap →