- Meaning
- A threat with a high potential for harm
- What makes it special
- Has not yet materialised
- Possible consequence
- A duty to inform users
- Related
- Significant incident, vulnerability management
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is a significant cyber threat?
A significant cyber threat is a danger that would have serious consequences for systems, services or the people affected if it were exploited. The decisive point: it does not have to have materialised yet. NIS2 therefore catches not only the harm itself but the serious risk – an actively exploited critical vulnerability in a widely used system, for instance, or a targeted attack campaign against a whole industry.
Threat vs incident
NIS2 draws the line deliberately: a significant threat is an impending danger, whereas a significant incident has already materialised and triggers the three-stage Reporting obligations (24 h / 72 h / one month). The threat on its own does not set that chain in motion – but it does call for acting ahead, before the danger turns into harm.
The duty to inform
Where significant threats have been identified, it can be called for to inform the customers or users affected – about protective steps they can take themselves, for instance, or about the recommendation to install a patch at once. The competent authority can also expressly require such notification in an individual case.
A practical example
A typical case: a software manufacturer learns that an actively exploited zero-day is circulating for a library used in its product. None of its own systems has been compromised – so there is no significant incident. Because the potential for harm to its customers is high, it treats the situation as a significant cyber threat, informs them proactively about a patch and increases monitoring for the relevant attack patterns.
Acting ahead
Spotting significant threats early is part of Risk management under NIS2 – it means Vulnerability management and watching IoCs , assessing the threat situation and reacting before damage arises that would have to be reported.
Further reading: ENISA – the EU agency for cybersecurity and threat landscape reports
Frequently asked questions
What is a significant cyber threat?
A significant cyber threat is a danger with a high potential for harm to systems, services or the people affected, one that would have serious consequences if it were exploited. The decisive point is that it does not have to have materialised yet. NIS2 therefore catches the serious risk as such – an actively exploited critical vulnerability in a widely used system, for instance, or a targeted attack campaign against a whole industry.
How does it differ from a significant incident?
The significant cyber threat is an impending danger that has not yet caused harm, whereas the significant incident has already materialised and triggers the three-stage NIS2 reporting chain of an early warning after 24 hours, an incident notification after 72 hours and a final report after one month. The threat on its own does not set that chain in motion, but it does call for acting ahead, before the danger turns into harm.
Do you have to inform users?
Where a significant cyber threat has been identified, informing the customers or users affected can be called for – about protective steps they can take themselves, for instance, or about the recommendation to install a patch at once. The competent authority can also expressly require such notification in an individual case. For a threat alone, however, there is no formal reporting duty of the kind that applies to a significant incident.