The NIS2 Directive establishes specific criteria to determine what constitutes a “significant incident” that triggers reporting obligations for entities falling within its scope. If you want to understand how these obligations translate into a concrete compliance path, our NIS2 Directive compliance service offers structured support from the initial assessment to the implementation of the required measures.
Below is an analysis based on the provided source:
Article 23, Paragraph 3 of the Directive outlines the criteria for classifying an incident as “significant,” requiring a two-level assessment:
- Impact on the Entity’s Operations: The incident must have “caused or be capable of causing a significant operational disruption of the services or a significant financial loss for the entity concerned.” This criterion focuses on the direct impact on the entity reporting the incident.
- Impact on Third Parties: The incident must have “affected or be capable of affecting other natural or legal persons by causing considerable material or non-material damage.” This criterion broadens the scope to include potential consequences for customers, users, partners, or other stakeholders.
Further Clarification on “Significant Disruption”:
- Article 16 of the Commission Communication: Provides further context for interpreting “significant operational disruption of services,” suggesting that such classification should be determined based on an initial assessment by the affected entity. This assessment should consider:
- The criticality of the networks and information systems involved in providing the entity’s services.
- The severity and technical nature of the cyber threat.
- The vulnerabilities exploited.
- The entity’s previous experience with similar incidents.
- Factors to Consider: The Commission Communication also highlights specific indicators relevant to assessing the severity of the disruption:
- Extent of Impact on Services: How significantly has the incident compromised the entity’s ability to provide its services?
- Duration of the Incident: Is the disruption still ongoing, and if so, how long has it lasted?
- Number of Users Affected: How many people or organizations that depend on the entity’s services have been affected?
Delegated Acts for Specific Sectors:
- Article 23, Paragraph 11 (second subparagraph): Grants the Commission the authority to adopt delegated acts to further specify the circumstances in which an incident must be considered “significant.” These acts may provide sector-specific guidelines. For example, the Commission is tasked with adopting delegated acts for entities such as:
- DNS service providers
- Top-level domain name registries
- Cloud computing service providers
- Data center service providers
- Content Delivery Networks (CDNs)
- And others
Key Considerations in Incident Assessment:
- Potential for Damage: It is important to remember that the Directive’s definition focuses on both actual and potential damage. An incident does not necessarily have to have already caused significant disruption or damage to trigger reporting obligations, provided there is a reasonable probability that it could lead to such consequences.
- Timely Assessment: The obligation for an early warning within 24 hours of becoming aware of a potential significant incident highlights the importance of timely and continuous assessment. Entities should have internal processes to quickly evaluate incidents and determine if they meet the “significant” criteria. These processes include the designation of the CSIRT contact person, a role required by the regulation to manage the notification flow to the competent authorities.
In summary, a “significant incident” under the NIS2 Directive is an event that has caused or could cause substantial disruption or damage, affecting the reporting entity or third parties. The assessment of the level of significance must be based on a combination of factors, and sector-specific guidelines may be provided through delegated acts. To delve deeper into the overall regulatory framework, you can also consult what the main objective of the NIS2 Directive is.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
