For the provider types named in Regulation (EU) 2024/2690, an incident is significant if any horizontal criterion or applicable provider-specific criterion is met. Horizontal triggers include direct financial loss above EUR 500,000 or 5% of the preceding financial year's total turnover, whichever is lower; actual or capable exfiltration of the entity's trade secrets; actual or capable death or considerable health damage; and successful, suspectedly malicious unauthorised access capable of causing severe operational disruption.
Calculate direct financial loss from incident costs such as replacement or relocation, extra staff and overtime, contractual redress, compensation, forgone revenue, communications, legal advice, forensics, and remediation. Do not include administrative fines, ordinary operating costs, general maintenance, insurance premiums, or post-incident improvements. Use available data and estimate where the actual amount is not yet known.
The Regulation also aggregates recurring incidents when they occur at least twice within six months, share the same apparent root cause, and collectively meet the financial-loss criterion. Provider-specific examples include complete unavailability for more than 30 minutes for a cloud, CDN, managed, or managed-security service; limited availability for more than one hour affecting more than 5% of Union users or more than 1 million Union users, whichever is smaller, for those services; and complete unavailability of a trust service for more than 20 minutes. Scheduled interruptions and planned consequences of scheduled maintenance are excluded from its significance criteria. Other sectors must use Article 23, applicable national law, and any sector-specific thresholds; they should not import the Regulation's numeric tests as universal NIS2 rules.