NIS2 guideNIS2 significant incidents

A significant incident under NIS2 is a decision you need to support with facts.

Teams often ask whether an incident is significant only after the situation becomes stressful. A better approach is to define the signals, evidence, owners, and decision path before the first serious incident arrives.

IncidentAIUpdated August 2026
Key points

What to remember before you act.

  • Significance is not the same as inconvenience or every alert.
  • The assessment should be based on impact, evidence, and uncertainty, not guesswork.
  • Early escalation is useful when facts are incomplete but potential impact is material.
  • A decision log helps explain why the team reported, did not report, or escalated for legal review.
  • IncidentAI can help maintain the facts, but accountable people decide significance.

Why the word significant matters

NIS2 reporting duties are tied to significant incidents. That does not mean every security event, blocked phishing email, failed login, or low-risk vulnerability automatically becomes a regulatory incident report.

It does mean the organization needs a structured way to ask whether an incident could materially affect services, customers, users, finances, operations, or other organizations. The first answer may be uncertain, so the process should support escalation and review.

Signals that may point to significance

The exact legal assessment depends on national law and facts, but incident teams can prepare common triage signals.

  • Critical service unavailable or materially degraded.
  • Incident affects multiple customers, locations, countries, or business units.
  • Potential financial loss or material operational disruption.
  • Potential harm to people, customers, suppliers, or other organizations.
  • Sensitive systems, regulated data, or privileged access may be involved.
  • Supplier incident affects a service your organization depends on.
  • Malicious activity is suspected and impact is not yet contained.
  • Recovery, containment, or communication requires management decisions.

Build a significance assessment into triage

Assessment areaQuestion to ask
Service impactWhich service is affected, how badly, and for how long?
Customer impactAre customers, users, suppliers, or partners affected or potentially affected?
Operational impactIs normal work disrupted, delayed, or unsafe?
Financial impactIs there actual or potential financial loss?
Data and accessAre sensitive systems, personal data, or privileged accounts involved?
GeographyCould the incident affect more than one country or authority?
EvidenceWhich logs, alerts, messages, tickets, and decisions support the assessment?

Keep a decision log

The significance decision may change. A low-information early signal can become more serious after investigation, or an alarming alert can be contained with no material impact. That is why the record should show what the team knew at each decision point.

Keep the decision log factual: who reviewed it, what evidence was available, what assumptions were made, what was escalated, and what changed later.

Where IncidentAI helps

IncidentAI can help capture affected assets, timeline entries, owner updates, actions taken, evidence links, and summaries. It can also flag missing context for severity and impact review.

It should not decide legal reportability by itself. The right use is to give legal, management, privacy, and security owners a clearer incident record for review.

Quick FAQ

What is a significant incident under NIS2?

It is generally an incident with actual or potential severe operational disruption, financial loss, or material or non-material damage. The exact assessment depends on national law and facts.

Is every cyber alert a significant incident?

No. Many alerts are investigated and closed without becoming significant incidents. The team should assess impact, evidence, and uncertainty.

Who should decide whether an incident is significant?

Security, legal, privacy, management, and service owners may all be needed depending on the facts. The decision should not sit with an unsupported analyst alone.

What evidence supports a significance decision?

Useful evidence includes timelines, service impact, affected users, logs, alerts, containment actions, decision notes, supplier updates, and management communications.

Official sources used

These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.

IncidentAI

Give significance decisions a clearer incident record.

IncidentAI helps teams keep triage, impact, evidence, owners, decisions, and timelines in one place for human review.