Glossary · NIS2

Significant Incident

An incident that has caused, or could cause, severe operational disruption, financial loss, or considerable damage to others.

Explained in depth: NIS2 incident reporting timeline

Under Article 23(3), an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Only significant incidents trigger the mandatory three-stage reporting timeline. For certain digital-sector entities (DNS providers, cloud providers, data centres, managed service providers, and others), Implementing Regulation (EU) 2024/2690 sets concrete quantitative thresholds for when an incident counts as significant. For other sectors, entities must define and document their own classification criteria as part of incident handling under Article 21(b).

Why it matters

The significance assessment must happen fast: the 24-hour early warning clock starts when you become aware of the significant incident. A written classification procedure with clear thresholds is the difference between a defensible report and a missed deadline.

Used in

See also

← All glossary terms