A significant incident is an incident that meets the applicable threshold for formal escalation or reporting under the relevant NIS2 implementation rules.
The assessment may depend on factors such as:
- Number and type of affected users
- Duration or service disruption
- Operational, financial, or societal impact
- Data or service affected
- Cross-border or supplier effects
- Evidence of malicious activity
Organizations should record the facts, uncertainty, decisions, and communication times that support the assessment. The exact criteria, authority, and reporting process depend on the applicable country and entity type, so teams should use official guidance and qualified advice.
