Incident Reporting Mechanisms

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Incident Reporting Mechanisms

Member States need to establish incident reporting mechanisms and ensure that essential and important entities report significant incidents without undue delay to their CSIRTs or, where applicable, to the competent authorities, as defined in NIS2. This includes incidents that have a major impact on the provision of their services. If necessary, these entities must also notify their service users about incidents that are likely to adversely affect the delivery of services. Member States must also ensure that entities provide sufficient information to help the CSIRT or competent authorities assess the potential cross-border impact of the incident. In addition, if an entity reports a significant incident to the competent authority, the Member State must ensure that the authority forwards the notification to the CSIRT without delay.

In the case of cross-border or cross-sector incidents, Member States must ensure that their single points of contact receive the relevant information in a timely manner.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

National incident reporting and CSIRT assistance mechanism, including mandatory NIS2 notification: Belgium operates a national cyber-incident reporting mechanism through the CCB, which acts as the national CSIRT. Essential and important entities covered by the Belgian NIS2 Law must notify significant incidents affecting covered services. The staged procedure requires an early warning within 24 hours of awareness, an incident notification within 72 hours, or 24 hours for trust-service providers, an intermediate report when requested, and a final report within one month of the incident notification. The same CCB reporting environment also supports organisations and citizens outside the NIS2 framework that wish to report a cyberattack or request assistance. The CCB reporting page distinguishes between NIS2 entities, other organisations and citizens. Organisations experiencing an incident may contact the national CSIRT by email; reports receive an automatic acknowledgement and unique reference number, while further assistance depends on incident severity and available capacity.

Sources: https://notif.safeonweb.be/
https://ccb.belgium.be/cert/incident-handling-cert-general-conditions
https://ccb.belgium.be/cert/report-incident/nis2-notifications-howto
https://ccb.belgium.be/cert/report-incident
https://ccb.belgium.be/regulation/nis2
https://ccb.belgium.be/news/notification-nis2-incidents

Electronic communications security incident notification: Belgian electronic communications operators must notify BIPT of a particular and significant threat to a public network or publicly available service and must inform potentially affected users. They must also notify incidents having a significant impact on network or service operation. The applicable thresholds and notification arrangements are set out in BIPT’s Decision of 14 December 2017. For NIS2 incident notification, the BIPT NetSec website now directs operators to the central Safeonweb notification portal, guaranteeing operational coordination between sectoral supervision and the national reporting channel.

Sources: https://notif.safeonweb.be/
https://www.bipt.be/operators/telecommunications/security/practical-information

DORA major ICT-related incident reporting through OneGate: Financial entities supervised by the National Bank of Belgium use the OneGate DOR domain to report major ICT-related incidents and may voluntarily notify significant cyber threats under DORA. The NBB’s 2026 circular covers specified categories including Belgian credit institutions, stockbroking firms, payment and electronic-money institutions, insurance and reinsurance undertakings, central securities depositories, central counterparties, and certain crypto-asset service providers and issuers supervised by the NBB. The NBB states that a fallback solution applies when OneGate is unavailable, but entities must subsequently submit the report through OneGate once able to do so.

Sources: https://extidm-idp.nbb.be/my.policy
https://www.nbb.be/en/financial-supervision-and-resolution/cross-cutting-and-international-aspects/news-and/circular-49

Personal data breach notification through the Belgian DPA portal: A controller must notify a personal-data breach to the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to create a risk to individuals’ rights and freedoms. Notifications to the Belgian Data Protection Authority must be submitted through its portal; the DPA expressly states that notifications sent by email will not be processed. Access uses an organisation account through which the controller can submit and manage the breach case. The DPA also warns that specific federal supervisory bodies are competent in certain domains, such as the Supervisory Body for Police Information for police services, so the filer must first verify which authority has jurisdiction, given that Belgium has different data protection authorities.

Sources: https://www.autoriteprotectiondonnees.be/professionnel/actions/violation-de-donnees-personnelles;Dutch
https://www.gegevensbeschermingsautoriteit.be/professioneel/acties/gegevensinbreuk

Croatia flag
Croatia

Public National CERT incident reporting: National CERT states coordinates incidents where at least one party is under the .hr domain or Croatian IP address space. Incident reports must include logs, description, time zone, target/source IP or computer name and other potential files. 

 Sources: https://www.cert.hr/en/report_incident/ 

PiXi national platform: The PiXi platform is intended for: Key entities and important entities subject to the Croatian Cybersecurity Act (Zakon o kibernetičkoj sigurnosti, ZKS), which transposes NIS2 into Croatian law. Entities subject to DORA (Regulation (EU) 2022/2554 on digital operational resilience for the financial sector). Competent authorities responsible for implementing cybersecurity requirements. Competent authorities responsible for sector-specific legislation. Competent CSIRTs. Croatia’s Single Point of Contact for cybersecurity matters.  To access the Pixi Platform service, it is necessary to obtain access rights from a legally authoriSed person for representing a business entity through e-Authorisations. Access to the e-Authorisation and Pixi platform service requires at least a significant level of security from the List of Accepted Credentials. 

Sources: https://pixi.carnet.hr/ 
https://narodne-novine.nn.hr/clanci/sluzbeni/2024_02_14_254.html 
https://www.carnet.hr/usluga/pixi-platforma/ 
https://e-ovlastnja.gov.hr/ 
https://gov.hr/hr/lista-prihvacenih-verodajnica/1792 

GDPR personal-data breach notification to AZOP: AZOP states that controllers must notify personal-data breaches without undue delay and, where feasible, within 72 hours, unless unlikely to pose risk. Incidents such as ransomware, unauthorised access, data loss or loss of access can be personal-data breaches. The report with the signature of the responsible person and the seal of the controller, if applicable, should be submitted to the Personal Data Protection Agency, Ulica Metela Ožegovića 16, 10000 Zagreb, and scanned to the e-mail address. 

 Sources: https://azop.hr/izvjescivanje-o-povredi-osobnih-podataka/ 
https://azop.hr/wp-content/uploads/2025/05/izvjesce_o_povredi_osobnih_podataka.rtfnn 

Denmark flag
Denmark

National incident reporting: The Danish Resilience Agency (SAMSIK) provides the main operational channel for reporting serious cyber incidents under NIS 2, GDPR, DORA, CER and future reporting schemes under legislation like the AI Act. Accessible via the national self-service portal for companies, Virk.dk, it supports mandatory and voluntary reporting under all of the regulations mentioned, and reports are then routed automatically to the relevant supervisory authority as well as the national CSIRT, when applicable.  Under Denmark's NIS 2 transposition, essential and important entities must notify significant incidents to the competent authorities and the national CSIRT within the required timeline: 24 hour early warning, 72 hour notification and a final report within one month.

Sources: https://virk.dk/myndigheder/stat/SAMSIK/selvbetjening/Indberetning_af_brud_paa_sikkerhed/

Estonia flag
Estonia

raport.cert.ee reporting environment: Estonia uses raport.cert.ee as its national channel for reporting cyber incidents to RIA. Individuals can send a basic notification by email, while authorities and service providers can submit a structured report through the online form. CERT-EE operates around the clock, assesses each report and coordinates support according to the severity of the incident.

Sources: https://raport.cert.ee/
https://www.ria.ee/en/cyber-security/handling-cyber-incidents-cert-ee/reporting-cyber-incident
https://www.ria.ee/kuberturvalisus/kuberintsidentide-kasitlemine-cert-ee/kuberintsidendist-teavitamine

Staged NIS2 / KüTS incident notification (KüTS §8): The amended Cybersecurity Act requires regulated entities to report significant cyber incidents to RIA through raport.cert.ee. They must submit an initial warning within 24 hours, a more detailed notification within 72 hours and a final report within one month. Trust service providers must submit the detailed notification within 24 hours. 

Sources: https://www.riigiteataja.ee/akt/130122025015
https://www.riigiteataja.ee/akt/K%C3%BCTS
https://ria.ee/uudised/uuenes-kuberintsidendist-teavitamise-vorm

Finland flag
Finland

National Cyber Security Centre Finland (NCSC-FI) incident reporting: The NCSC-FI, operating within Traficom, is Finland's national CSIRT. Individuals, businesses and organisations can report actual or attempted information-security incidents through an online form or by e-mail. The centre investigates violations affecting network, communications and value-added services.

Sources: https://www.kyberturvallisuuskeskus.fi/en/contact-us/e-services/report-information-security-incident
https://www.kyberturvallisuuskeskus.fi/en/report
https://www.kyberturvallisuuskeskus.fi/en

Germany flag
Germany

BSI-Portal: It is the official digital reporting desk launched by Germany’s Federal Office for Information Security to enforce NIS2 directive. Among its two main functions, it serves as an emergency incident reporting platform. When a cyberattack occurs, essential and important entities must use the portal to submit a preliminary report within 24 hours of discovering the incident, followed by a more detailed update within 72 hours. The portal also allows non-regulated companies to report voluntarily and to submit vulnerabilities anonymously

Sources: https://portal.bsi.bund.de 
https://www.bsi.bund.de/dok/nis-2-meldepflicht 
https://www.bsi.bund.de/EN/IT-Sicherheitsvorfall/Kritische-Infrastrukturen-und-meldepflichtige-Unternehmen/Ich-muss-oder-moechte-einen-IT-Sicherheitsvorfall-melden/ich-muss-oder-moechte-einen-it-sicherheitsvorfall-melden.html 
https://portal.bsi.bund.de/ 

CERT-Bund: The Computer Emergency Response Team for Germany's federal authorities, is the central point of contact for preventive and reactive measures related to security-relevant incidents in computer systems.  It runs a 24/7 standby service together with the National IT Situation Centre (Nationales IT-Lagezentrum), analyses incidents, issues warnings through its Warning and Information Service (WID) and coordinates the response with affected operators and authorities.

Sources: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Reaktion/CERT-Bund/cert-bund_node.html 

Hungary flag
Hungary

National cybersecurity incident and vulnerability reporting, including NIS2-related national CSIRT reporting: Hungary’s incident reporting framework is centred on the Special Service for National Security (SNSS), which is designated by Government Decree 418/2024 as the national cybersecurity incident handling centre and operates through the National Cyber Security Centre of Hungary (NCSC HU).  NCSC HU allows cybersecurity incidents and vulnerabilities to be reported through its incident portal, including by customers and anonymous reporters. Reports may also be submitted by e-mail or telephone. The framework sets staged reporting obligations, including an initial report within 24 hours, the submission of indicators of compromise where available, an event report within 72 hours, interim reports upon request, and a final report. These requirements sit within the wider NIS2 transposition framework under Act LXIX and its implementing measures.

Sources: https://en.nki.gov.hu/
https://incidens.nki.gov.hu/
https://nki.gov.hu/intezet/tartalom/incidens-bejelentes/
https://nki.gov.hu/intezet/tartalom/kapcsolat/
https://net.jogtar.hu/getpdf?docid=A2400418.KOR&targetdate=20260911&printTitle=418/2024.%20%28XII.%2023.%29%20Korm.%20rendelet
https://nki.gov.hu/hatosag/tartalom/jogszabalyok/

Financial-sector DORA ICT incident and threat reporting: Institutions under Regulation (EU) 2022/2554 must report major incidents to their supervisory authority and may report significant threats voluntarily. MNB created a certificate-based ERA service named “DORA Incident Reporting”. The service is accessed through the ERA portal and supports incident creation, initial/interim/final reports, threat reports and delegated sender administration. Pre-registration is required to: MNB Registration Database. Depending on the registration service electronic signing certificate or customer portal registration is required.

Sources: https://era.mnb.hu/ERA.WEB/
https://www.mnb.hu/felugyelet/felugyeleti-keretrendszer/felugyeleti-hirek/hirek-ujdonsagok/tajekoztatas-a-dora-szerinti-incidens-bejelentesi-adatszolgaltatasi-feluletre-valo-regisztracio-megkezdeserol
https://era.mnb.hu/ERA.WEB/Home/GetFile/DORA_IR_Felhasznaloi_kezikonyv_publikus_felulet_v1.0.pdf/mnb

General personal data breach notification to the Hungarian data protection authority: Data controllers must report personal data breaches likely to pose a risk to natural persons’ rights and freedoms without undue delay and, where feasible, within 72 hours after becoming aware. The National Authority for Data Protection and Freedom of Information (NAIH) provides a dedicated online “NAIH Incident Reporting System” and alternative submission routes, including e-Papír, postal and personal delivery. Breach notifications can be sent by post or electronic mail and through the dedicated portal.

Sources: https://epapir.gov.hu/
https://www.naih.hu/adatvedelmi-incidensbejelento-rendszer
https://dbn-online.naih.hu/public/login
https://dbn-online.naih.hu/assets/files/UserManual.pdf

Liechtenstein flag
Liechtenstein

CSIRT.LI national cybersecurity incident reporting mechanism: CSIRT.LI provides Liechtenstein’s central operational channel for voluntary and mandatory cybersecurity incident reporting. Its primary submission route is the official incident reporting form; if that channel cannot be used, reports may be sent to the dedicated incident mailbox in plain text and should contain the same information requested by the form. CSIRT.LI coordinates and facilitates response but states that it does not itself perform technical remediation or compete with private providers. Its statutory constituency principally covers essential and important entities. These, according to the Act transposing NIS2 Directive (EU) 2022/2555 must register with the National Cyber Security Unit. The Act excludes certain public-administration activities relating to national security, public security, defence and law enforcement from the reporting duties.

Sources: https://www.llv.li/de/landesverwaltung/stabsstelle-cybersicherheit/it-sicherheitsvorfall-melden
https://www.llv.li/de/landesverwaltung/stabsstelle-cybersicherheit/csirt

DORA reporting through the e-Service Portal: The Financial Market Authority operates a sector-specific electronic mechanism for serious ICT-related incidents affecting regulated financial entities. Following the implementation of DORA in Liechtenstein, a new incident-related report became available in the FMA e-Service Portal. Serious ICT incidents meeting the applicable classification criteria are reported to the FMA, while significant cyber threats may also be reported voluntarily. In the first implementation stage, regulated entities submit the prescribed European Supervisory Authorities’ Excel templates through an event-related report in the portal; the templates must be used unchanged. The FMA also states that the DORA form is used by financial intermediaries covered by FMA Guideline 2021/3 for serious or disruptive ICT incidents, although DORA classification criteria and deadlines do not apply to that separate category.

Sources: https://www.fma-li.li/en/supervision-regulation/dora/dora-reporting
https://www.fma-li.li/en/news/dora-in-force-new-event-related-notification-1091
https://www.fma-li.li/en/supervision-regulation/dora/faqs

Personal-data breach notification to the Datenschutzstelle: Liechtenstein’s Data Protection Authority provides an electronic form for controllers to notify qualifying personal data breaches. The notification is generally required within 72 hours after the controller becomes aware of the breach. A preliminary notification may be filed to preserve the deadline where investigation of the relevant facts is still incomplete, and the same official form supports preliminary and complete notifications. Where a risk to the rights and freedoms of affected persons is considered unlikely, notification is not required, but the breach must still be documented internally. This mechanism is distinct from reporting a general cybersecurity incident to CSIRT.LI: an incident involving personal data may therefore engage both channels.

Sources: https://www.datenschutzstelle.li/datenschutz/themen-z/meldung-von-datenschutzverletzungen-art-33-dsgvo
https://www.datenschutzstelle.li/services-und-downloads/formulare
https://formulare.llv.li/formserver_DSS/start.do?generalid=DSS_BF#
https://www.datenschutzstelle.li/datenschutz/themen-z/meldung-von-datenschutzverletzungen-art-33-dsgvo;%20Datenschutzstelle%20services%20page.%20%5bdatenschutzstelle.li%5d,%20%5bdatenschutzstelle.li%5d,%20%5bdatenschutzstelle.li%5d

Malta flag
Malta

Information on CSIRT Malta: Malta's cyber incident reporting framework is overseen by CSIRTMalta, the national cybersecurity incident response authority responsible for coordinating incident response, providing support to affected organisations, issuing alerts and warnings, and maintaining national cyber situational awareness. The framework is supported by Malta's broader cybersecurity governance structure under the National Cybersecurity Strategy 2023–2026. While the national authority and strategic framework are clearly established, there is no publicly available evidence of a dedicated online cyber incident reporting form or portal. As a result, the detailed reporting process, required notification fields, and any NIS2-specific reporting workflow are not publicly documented and may be managed through controlled communication channels with the competent authority. 

Sources: https://maltacip.gov.mt/en/the-department/csirtmalta/ 

Malta Gaming Authority information security incident reporting: Under Articles 37(2)(c) and (d) of the Gaming Authorisations and Compliance Directive (Directive 3 of 2018), licensees must notify the Malta Gaming Authority forthwith, and in any case no later than three working days after, of any breach of the licensee’s information security that adversely affects the confidentiality of information relating to players, or that precludes players from accessing their accounts for a period exceeding twelve hours. Incident Reports are submitted through the Technical - Information Security Incident instrument available on the Licensee Portal, and are subsequently reviewed by the Authority. Licensees are also advised to remain mindful of obligations arising under the General Data Protection Regulation. 

Sources: https://www.mga.org.mt/update-to-the-incident-reporting-requirements/ 

Netherlands flag
Netherlands

Cyberbeveiligingswet (Cbw) mandatory incident notification via MijnNCSC: The Cyber Security Act establishes a single national process for reporting significant cyber incidents. Essential and important entities must submit an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month through MijnNCSC. The same reports reach NCSC-NL and the competent sector supervisor, which connects operational response with regulatory oversight. 

Source: https://www.ncsc.nl/cyberbeveiligingswet-nis2/meldplicht 
https://www.ncsc.nl/cyberbeveiligingswet-nis2/over-de-cbw 

Sectoral CSIRT for healthcare (Z-CERT): Z-CERT provides healthcare organisations with a sector-specific route for reporting cyber incidents. It performs the initial assessment and supports the affected organisation, while serious or cross-sector incidents are coordinated with NCSC-NL. This arrangement combines healthcare expertise with access to the national response system. 

Source: https://z-cert.nl/ 

Poland flag
Poland

Integrated national reporting framework: Cyber.gov.pl, CERT Polska and S46 Cyber Hub: Poland operates an integrated national reporting structure combining a public routing gateway, a general system for incident submission and a protected connection for regulated entities. Cyber.gov.pl asks whether the reporter is a citizen, business or KSC entity (namely, the Act on the National Cybersecurity System) and directs the report to the appropriate system. CERT Polska operates the CSIRT NASK online form, which distinguishes natural persons or other entities from key and important entities. Email submission is also available. For entities in the National Cybersecurity System, S46 Cyber Hub supports cybersecurity communication and incident reporting. Under the amended KSC framework, qualifying entities must enter the KSC register, connect to S46 and implement incident-management and CSIRT-reporting obligations.

Sources: https://www.gov.pl/web/baza-wiedzy/zglaszanie-incydentow
https://cyber.gov.pl/zg%C5%82o%C5%9B-incydent
https://pa.s46.gov.pl/
https://www.gov.pl/web/system-s46/logowanie
https://incydent.cert.pl/#!/lang=en

Simplified public reporting of suspicious SMS, email and websites: CERT Polska provides simplified public-facing channels for reporting suspected phishing, fraudulent communications and potentially harmful websites. Suspicious SMS messages can be forwarded in their original form to the short number 8080, including messages with or without hyperlinks. The official guidance asks users not to remove the link or other content. Suspicious email messages and websites can instead be reported through the CERT Polska form or by email. These channels contribute to CERT Polska’s detection and analysis of cyber threats and offer citizens an accessible alternative to regulated-entity reporting infrastructure. The 8080 service is a specialised public reporting mechanism and does not replace mandatory incident notification by key, important or otherwise regulated entities under KSC, DORA or sector-specific requirements.

Sources: https://www.gov.pl/web/baza-wiedzy/dostales-niepokojacy-sms-albo-email-zglos-go-do-cert-polska-csirt-nask

National governmental and defence reporting: CSIRT GOV and CSIRT MON: Poland’s national-level CSIRT structure includes dedicated teams for incidents falling within the governmental and national-defence spheres. Cyber.gov.pl publishes direct telephone, email, website and postal contact details for CSIRT GOV and CSIRT MON alongside those of CSIRT NASK. Where a reporter already knows the competent team, these contacts provide a direct route; otherwise, the Cyber.gov.pl gateway can be used to navigate to the appropriate system. CSIRT GOV is the national level CSIRT for the government sphere, while CSIRT MON is the dedicated for the national-defence sphere; precise statutory allocation should be checked against the reporter’s legal status and the current KSC Act.

Sources:  https://csirt.gov.pl/
https://csirt-mon.wp.mil.pl/en/contact-2019-08-23-c/

Sector-specific reporting mechanisms: CSIRT KNF and CSIRT Cyfra: Poland supplements its national CSIRTs with sectoral teams that receive notifications and support incident handling within defined industries. CSIRT KNF serves the financial market, accepts major-incident reports, supports covered entities, analyses incidents and coordinates with the national CSIRTs. Its also addresses reporting by financial entities classified as key or important and ICT reporting under DORA. CSIRT Cyfra was established in 2026 for key and important entities in digital infrastructure, including data centres, DNS services, domain registries, internet exchange points and content delivery networks. Its stated functions include receiving early warnings, incident notifications, intermediate and final reports, and potential-event notifications.

Sources:  https://www.knf.gov.pl/en/MARKET/CSIRT_KNF
https://www.gov.pl/web/cyfryzacja/csirt-cyfra--nowy-zespol-cyberbezpieczenstwa-w-ministerstwie-cyfryzacji

Portugal flag
Portugal

CERT.PT incident-reporting and notification mechanism: CERT.PT, the incident-response service of the Portuguese National Cybersecurity Centre (CNCS), provides the main operational channel for reporting cyber incidents affecting national interest. Under the Cybersecurity Legal Framework, public bodies, essential and important entities are required to notify incidents to the CNCS, which coordinates response and national cybersecurity oversight. 

Sources: https://www.cncs.gov.pt/en/certpt/ 
https://cncs.gov.pt/en/notificacao-incidentes/ 

Slovakia flag
Slovakia

Cybersecurity incident reporting: The cybersecurity incident reporting framework is centralised under the authority of the National Security Authority (NBÚ). Mandatory cybersecurity incident notifications are submitted through the Unified Information System for Cybersecurity (JISKB), which serves as the national reporting platform. Operational incident coordination is performed by the National Cybersecurity Centre by division SK-CERT, which acts as Slovakia's national CSIRT. In parallel, Slovakia maintains additional accredited CSIRT teams, including CSIRT.SK, which provide cybersecurity services, alerts and incident response support for their respective constituencies. However, the existence of multiple CSIRTs does not alter the centralised nature of the national reporting mechanism. The reporting obligations differ depending which type of entity is reporting.

Sources: https://www.nbu.gov.sk/cybersecurity-incidents-reporting/

Cybersecurity incident reporting for operators of essential services

Operators of essential services entities must report every significant cybersecurity incident through the Unified Information System for Cybersecurity, (JISKB). Significance is evaluated according to criteria such as: number of affected users; duration of the incident; geographic spread; level of disruption; impact on social and economic activities of the state. If the incident is ongoing and all information is not available, an incomplete report may be submitted; a completed report must be submitted after restoration of normal operations.

Sources: https://jiskb.nbu.gov.sk/

Cybersecurity incident reporting for digital operators: Operators of digital services must report every cybersecurity incident having significant impact. Additionally, if they have information relevant to identifying a significant impact, they must report immediately after becoming aware of it. They should submit reports through the published online form or in case of impossibility to access it, contact the email address. Plus, where a DSP provides services relied upon by an OES, the DSP must also report significant incidents affecting those services.

Sources: https://www.sk-cert.sk/en/tips-and-tricks/report-an-incident-form/index.html

Slovenia flag
Slovenia

SI-CERT (national CSIRT): SI-CERT, operating within the public institute Arnes, performs the national CSIRT role assigned by ZInfV-1 for its statutory constituency and accepts voluntary notifications. It monitors and analyses incidents, issues alerts and supports incident response. 

Sources: https://www.cert.si/en/ 

https://www.cert.si/en/incident-reporting/ 

SIGOV-CERT (governmental CSIRT): SIGOV-CERT, operating within URSIV, handles information-security incidents for its public-administration constituency and state trust-service providers as assigned by ZInfV-1. It also accepts voluntary notifications within its area of competence. 

Sources: https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/sigov-cert-division/  

Spain flag
Spain

INCIBE-CERT online cyber-incident notification and response service: INCIBE-CERT operates Spain’s principal reporting and technical-support route for cybersecurity incidents affecting citizens and entities governed by private law. Its web form accepts reports from citizens, companies, RedIRIS institutions, operators of essential services or critical infrastructure, and other affected organisations. The form requests a contact email, subject, description and, where available, technical information. INCIBE-CERT provides technical support, early detection and coordination with providers and other CERTs. It may transmit information to competent authorities, including the co-operation of the INCIBE-CERT by the Cybersecurity Coordination Office (OCC) of the Ministry of Interior for incidents involving critical operators. The portal’s legal basis still refers to the NIS1 implementing framework, including Royal Decree-Law 12/2018 and Royal Decree 43/2021, while also referencing NIS2. The scope for mandatory reporting should therefore be checked against the entity’s sector and the progress of Spain’s NIS2 legislation. 

Sources: https://www.incibe.es/ 
https://www.incibe.es/incibe-cert/incidentes/notificaciones 

https://occ.ses.mir.es/publico/occ/laOCC.html 

CCN-CERT incident reporting through LUCIA and encrypted email: Public-sector bodies in Spain report cybersecurity incidents to CCN-CERT. The reporting channel depends on the organisation and its applicable security framework. Entities subject to the Esquema Nacional de Seguridad can use LUCIA, CCN-CERT’s incident-reporting and coordination platform. Reports can also be sent by email and should explain what happened and provide an email address and telephone number for follow-up. CCN-CERT states that email communications should be encrypted and the sender authenticated through its published PGP/GPG key. Public administrations must notify certain incidents, but the obligation does not automatically apply to every event. The relevant CCN-STIC guidance helps organisations classify incidents and assess their severity, impact and priority. 

Sources: https://www.ccn-cert.cni.es/es/gestion-de-incidentes/notificacion-de-incidentes?format=html 
https://www.ccn-cert.cni.es/es/soluciones-seguridad/lucia.html 
https://angeles.ccn-cert.cni.es/index.php/es/docman/documentos-publicos/357-ciberconsejos-lucia-compartir-informacion-y-crear-comunidad/file 

AEPD personal-data breach notification form: The AEPD provides a dedicated electronic procedure for controllers to notify personal-data breaches under Article 33 GDPR. The updated form guides controllers through structured questions and supports either a new notification or modification of an earlier notification, allowing information to be supplied progressively when all relevant facts are not available within the GDPR period. The AEPD states that communications on the status of a notification and any subsequent requirements are delivered through the Dirección Electrónica Habilitada. The notification is distinct from general cyber-incident assistance: it concerns breaches of personal data and does not necessarily trigger an administrative procedure. A paper/PDF form, guidance and assessment tools are also available, but the “Asesora Brecha” tool only assists with decision-making and does not itself constitute notification. 

Sources: https://www.aepd.es/derechos-y-deberes/cumple-tus-deberes/medidas-de-cumplimiento/brechas-de-datos-personales-notificacion 
https://www.aepd.es/documento/formulario-brechas.pdf 
https://www.aepd.es/guias/guia-brechas-seguridad.pdf 
https://asesora.aepd.es/ 
https://comunica.aepd.es/ 

Banco de España DORA incident and significant cyber-threat reporting procedure: Banco de España’s electronic procedure receives mandatory reports of major ICT incidents and major operational or security incidents related to payment services, together with voluntary notifications of significant cyber threats. The stated scope includes credit institutions, payment institutions, exempt payment institutions, account-information service providers and electronic-money institutions, as well as third-party providers delegated to report. Entities must first enrol in the PIR electronic service, complete the relevant DORA template and send it through the Internet-ITW channel using the designated PIRI3R or PIRA4R process. The procedure provides for an initial report, one or more intermediate reports and a final report, with receipt and processing status available through ITQ. 

Sources: https://sedeelectronica.bde.es/sede/es/tramites/notificacion-incidentes-graves-ciberamenazas-importantes-p314.html 
https://sedeelectronica.bde.es/f/websede/INF/Comun/Relcionados/descargar/DORA_voluntary_threat_reporting_form.xlsx