Glossary · Term

Significant incident explained

A significant incident is a security incident with serious impact on services, operations or the people affected – and it may have to be reported.

At a glance
Meaning
An incident with serious impact
Consequence
Triggers the NIS2 reporting obligations
Criteria
Severity, duration, users affected
Related
Incident, reporting obligations
Updated
June 2026
Editorial team
Compliance Compass

What is a significant incident?

A significant incident is an Incident, one with serious consequences – longer outages, a large data leak or many affected users, for example. It is that severity which makes an incident reportable at all. The term is therefore the threshold, the point that decides whether the NIS2 reporting chain is triggered or not: an ordinary incident stays an internal matter, a significant incident becomes a duty towards the authority.

When an incident is “significant”

What counts includes the duration of the disruption, the number of people or customers affected, possible financial damage, the leaking of sensitive data and the effect on other entities or on public supply. Because NIS2 prescribes no rigid score and leaves it to your entity to judge significance from the circumstances, you should translate these factors into your own documented thresholds before the first real case – otherwise valuable minutes are lost to internal debate inside a 24-hour deadline that is tight enough already.

Decision checklist: is the incident significant?

One clear yes is usually enough to trigger the reporting chain. When in doubt: report.

Consequence: the reporting obligations

Where a significant incident has occurred, the three-stage Reporting obligations apply, with an early warning (24 h), an incident notification (72 h) and a final report (one month). An incident that has actually occurred has to be kept apart from a significant cyber threat, which is a danger that has not yet caused harm.

Two cases, one threshold

A scenario: an online retailer notices that customer data from around 40,000 accounts has leaked through a vulnerability. Data leak plus many people affected – two clear yeses on the checklist. The team classifies the incident as significant within minutes and starts the reporting chain. A brief load spike in the web shop the day before, by contrast, stayed below every threshold, affected no customer and was merely logged internally. The same yardstick, two opposite results.

What you actually have to do

As soon as the checklist shows a yes, every minute counts. These steps belong in the sequence:

Hesitate here and you risk fines: Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover (essential entities) and EUR 7 million or 1.4 % (important entities), and Member States may set higher amounts. Clear criteria save exactly that time spent debating.

Further reading: Directive (EU) 2022/2555, criteria for significant incidents (Article 23)

Frequently asked questions

What is a significant incident?

A significant incident is a security incident with serious impact on the availability, confidentiality or integrity of services – through longer outages, a large data leak, financial damage or many affected users, for instance. It is that severity which makes an incident reportable at all and sets it apart from an ordinary incident. The term is therefore the threshold that decides whether the three-stage NIS2 reporting chain is triggered.

What happens after a significant incident?

After a significant incident the three-stage NIS2 reporting chain applies, filed through the national channel your Member State provides: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The internal containment and recovery measures run alongside it. Missing the deadlines risks fines, for which Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities.

Who decides whether an incident is significant?

The entity concerned decides for itself whether an incident is significant, judging it against criteria defined in advance such as the duration of the disruption, its reach, the number of users affected and the scale of the damage. NIS2 prescribes no rigid score; it leaves the assessment to the entity. Clear, documented thresholds make the classification fast and traceable for the authority – and save valuable time inside the tight 24-hour deadline.

Significance check

Significant or not? Settled in minutes

With your thresholds stored in advance, Compliance Compass walks your team through the yes/no assessment and starts the 24-hour early warning automatically on a hit.