Incident reporting mechanisms

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

Incident reporting mechanisms

Member States need to establish incident reporting mechanisms and ensure that essential and important entities report significant incidents without undue delay to their CSIRTs or, where applicable, to the competent authorities, as defined in NIS2. This includes incidents that have a major impact on the provision of their services. If necessary, these entities must also notify their service users about incidents that are likely to adversely affect the delivery of services. Member States must also ensure that entities provide sufficient information to help the CSIRT or competent authorities assess the potential cross-border impact of the incident. In addition, if an entity reports a significant incident to the competent authority, the Member State must ensure that the authority forwards the notification to the CSIRT without delay.

In the case of cross-border or cross-sector incidents, Member States must ensure that their single points of contact receive the relevant information in a timely manner.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Croatia flag
Croatia

Public National CERT incident reporting: National CERT states coordinates incidents where at least one party is under the .hr domain or Croatian IP address space. Incident reports must include logs, description, time zone, target/source IP or computer name and other potential files. 

 Sources: https://www.cert.hr/en/report_incident/ 

PiXi national platform: The PiXi platform is intended for: Key entities and important entities subject to the Croatian Cybersecurity Act (Zakon o kibernetičkoj sigurnosti, ZKS), which transposes NIS2 into Croatian law. Entities subject to DORA (Regulation (EU) 2022/2554 on digital operational resilience for the financial sector). Competent authorities responsible for implementing cybersecurity requirements. Competent authorities responsible for sector-specific legislation. Competent CSIRTs. Croatia’s Single Point of Contact for cybersecurity matters.  To access the Pixi Platform service, it is necessary to obtain access rights from a legally authoriSed person for representing a business entity through e-Authorisations. Access to the e-Authorisation and Pixi platform service requires at least a significant level of security from the List of Accepted Credentials. 

Sources: https://pixi.carnet.hr/ 
https://narodne-novine.nn.hr/clanci/sluzbeni/2024_02_14_254.html 
https://www.carnet.hr/usluga/pixi-platforma/ 
https://e-ovlastnja.gov.hr/ 
https://gov.hr/hr/lista-prihvacenih-verodajnica/1792 

GDPR personal-data breach notification to AZOP: AZOP states that controllers must notify personal-data breaches without undue delay and, where feasible, within 72 hours, unless unlikely to pose risk. Incidents such as ransomware, unauthorised access, data loss or loss of access can be personal-data breaches. The report with the signature of the responsible person and the seal of the controller, if applicable, should be submitted to the Personal Data Protection Agency, Ulica Metela Ožegovića 16, 10000 Zagreb, and scanned to the e-mail address. 

 Sources: https://azop.hr/izvjescivanje-o-povredi-osobnih-podataka/ 
https://azop.hr/wp-content/uploads/2025/05/izvjesce_o_povredi_osobnih_podataka.rtfnn 

Denmark flag
Denmark

National incident reporting: The Danish Resilience Agency (SAMSIK) provides the main operational channel for reporting serious cyber incidents under NIS 2, GDPR, DORA, CER and future reporting schemes under legislation like the AI Act. Accessible via the national self-service portal for companies, Virk.dk, it supports mandatory and voluntary reporting under all of the regulations mentioned, and reports are then routed automatically to the relevant supervisory authority as well as the national CSIRT, when applicable.  Under Denmark's NIS 2 transposition, essential and important entities must notify significant incidents to the competent authorities and the national CSIRT within the required timeline: 24 hour early warning, 72 hour notification and a final report within one month.

Sources: https://virk.dk/myndigheder/stat/SAMSIK/selvbetjening/Indberetning_af_brud_paa_sikkerhed/

Hungary flag
Hungary

National cybersecurity incident and vulnerability reporting, including NIS2-related national CSIRT reporting: Hungary’s incident reporting framework is centred on the Special Service for National Security (SNSS), which is designated by Government Decree 418/2024 as the national cybersecurity incident handling centre and operates through the National Cyber Security Centre of Hungary (NCSC HU).  NCSC HU allows cybersecurity incidents and vulnerabilities to be reported through its incident portal, including by customers and anonymous reporters. Reports may also be submitted by e-mail or telephone. The framework sets staged reporting obligations, including an initial report within 24 hours, the submission of indicators of compromise where available, an event report within 72 hours, interim reports upon request, and a final report. These requirements sit within the wider NIS2 transposition framework under Act LXIX and its implementing measures.

Sources: https://en.nki.gov.hu/
https://incidens.nki.gov.hu/
https://nki.gov.hu/intezet/tartalom/incidens-bejelentes/
https://nki.gov.hu/intezet/tartalom/kapcsolat/
https://net.jogtar.hu/getpdf?docid=A2400418.KOR&targetdate=20260911&printTitle=418/2024.%20%28XII.%2023.%29%20Korm.%20rendelet
https://nki.gov.hu/hatosag/tartalom/jogszabalyok/

Financial-sector DORA ICT incident and threat reporting: Institutions under Regulation (EU) 2022/2554 must report major incidents to their supervisory authority and may report significant threats voluntarily. MNB created a certificate-based ERA service named “DORA Incident Reporting”. The service is accessed through the ERA portal and supports incident creation, initial/interim/final reports, threat reports and delegated sender administration. Pre-registration is required to: MNB Registration Database. Depending on the registration service electronic signing certificate or customer portal registration is required.

Sources: https://era.mnb.hu/ERA.WEB/
https://www.mnb.hu/felugyelet/felugyeleti-keretrendszer/felugyeleti-hirek/hirek-ujdonsagok/tajekoztatas-a-dora-szerinti-incidens-bejelentesi-adatszolgaltatasi-feluletre-valo-regisztracio-megkezdeserol
https://era.mnb.hu/ERA.WEB/Home/GetFile/DORA_IR_Felhasznaloi_kezikonyv_publikus_felulet_v1.0.pdf/mnb

General personal data breach notification to the Hungarian data protection authority: Data controllers must report personal data breaches likely to pose a risk to natural persons’ rights and freedoms without undue delay and, where feasible, within 72 hours after becoming aware. The National Authority for Data Protection and Freedom of Information (NAIH) provides a dedicated online “NAIH Incident Reporting System” and alternative submission routes, including e-Papír, postal and personal delivery. Breach notifications can be sent by post or electronic mail and through the dedicated portal.

Sources: https://epapir.gov.hu/
https://www.naih.hu/adatvedelmi-incidensbejelento-rendszer
https://dbn-online.naih.hu/public/login
https://dbn-online.naih.hu/assets/files/UserManual.pdf

Netherlands flag
Netherlands

Cyberbeveiligingswet (Cbw) mandatory incident notification via MijnNCSC: The Cyber Security Act establishes a single national process for reporting significant cyber incidents. Essential and important entities must submit an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month through MijnNCSC. The same reports reach NCSC-NL and the competent sector supervisor, which connects operational response with regulatory oversight. 

Source: https://www.ncsc.nl/cyberbeveiligingswet-nis2/meldplicht 
https://www.ncsc.nl/cyberbeveiligingswet-nis2/over-de-cbw 

Sectoral CSIRT for healthcare (Z-CERT): Z-CERT provides healthcare organisations with a sector-specific route for reporting cyber incidents. It performs the initial assessment and supports the affected organisation, while serious or cross-sector incidents are coordinated with NCSC-NL. This arrangement combines healthcare expertise with access to the national response system. 

Source: https://z-cert.nl/