The reporting obligation: 24 hours, 72 hours and one month
Three moments, and none of them is the reporting obligation within 24 hours that is usually referred to.
Three steps, none of them
When you report a significant incident, you do so three times. Within 24 hours an early warning: something serious has occurred, possibly malicious, possibly with cross-border consequences. More does not need to be included at that point, because at that moment you often do not yet know what is happening yourself.
Within 72 hours comes the actual report: the severity, the consequences and the indications you have about how it happened. And within one month the final report: what it was, what the cause was, what you did about it and what the cross-border consequences were.
When is an incident significant?
If it causes serious disruption of your service or financial losses, or if it can cause significant harm to others. That is deliberately broadly formulated. In practice the rule of thumb is: if you call it a crisis internally, it is significant.
The deadline runs from the moment you become aware of the incident, not from the moment it began. That difference can be days, and it is the reason that recording when you noticed something matters.
Who you report to
To the CSIRT or competent authority of your country. Each country has its own portal and its own login method.
That login method is precisely the reason we never report on your behalf. We keep the text ready, with the data from your file filled in, and you submit it yourself. That is not a limitation but a choice: your access to your regulator should not lie with a service provider.
Frequently asked questions
What if I report late?
Reporting late is itself a violation. When in doubt, an early warning that turns out to be unnecessary later is cheaper than a report that comes too late: the first step takes ten minutes.
Do I also need to inform my customers?
If the incident affects their service delivery, the regulator may require you to do so. Apart from that, the GDPR applies separately: if it involves personal data, there is also a reporting obligation to the Data Protection Authority.
Does this also apply if I am affected through the supply chain?
No. The reporting obligation applies only to organisations that are themselves subject to the law. Your contract with a regulated customer may however contain its own reporting arrangement.
This is explanation, not advice about your own situation. secria.eu does not assess your organization and does not provide assurance.