Lesson 5.1 · 7 min
When an incident is significant
Open in the coursewith narrated slides, a checklist to tick off and a quiz
At a glance
- Severe disruption, severe loss, harm to others. An incident is significant if it has caused or can cause severe disruption or financial loss, or considerable damage to others.
- Nine fixed criteria in the NISV. For example a direct loss above €500,000 or five per cent of turnover, leaked trade secrets, or a service disrupted in a federal state for more than 24 hours.
- Recovery plan activated: significant. If the incident leads to activating crisis management or a disaster recovery plan, it is significant in any case.
- Planned maintenance doesn't count. Planned outages and planned effects of maintenance work are not significant incidents.
- Recurring incidents count together. Two or more incidents within six months with the same cause and effect count together as significant if together they reach the loss threshold.
In detail
Incident and significant incident
A cyber security incident is an event that compromises the availability, authenticity, integrity or confidentiality of data or services § 3 no. 30 NISG 2026. You only have to report significant incidents. An incident is significant if it § 35(1) NISG 2026:
- has caused or can cause severe disruption of the entity's services or severe financial loss for it;
- has affected or can affect other natural or legal persons by causing considerable material or non-material damage.
The assessment takes into account, among other things, how far other sectors depend on your service, possible effects on the environment, safety and health, your market share, the area affected, the systems affected and how serious the threat is § 35(2) NISG 2026.
The NISV 2026's nine criteria
An incident is significant in any case if any one of these is met § 5(1) NISV 2026:
- a direct financial loss of more than €500,000 or 5% of the previous year's turnover, whichever is lower, has occurred or can occur;
- trade secrets or information that must be kept secret have leaked or can leak;
- a person has died or can die;
- serious harm to a person's health has occurred or can occur;
- there has been a successful, suspected malicious and unauthorised access to systems that is likely to cause severe disruption;
- the criteria for recurring incidents are met (§ 7);
- a service has been unavailable or limited for more than 100,000 users or 10% of users, whichever is lower, for more than 24 hours, or this can happen;
- a service has been unavailable or limited for users in at least one federal state for more than 24 hours, or this can happen;
- the incident has led to activating crisis management or disaster recovery plans.
"Can cause" means, according to the explanatory notes, that in the ordinary course of things the effect is to be expected soon. For no. 5 it isn't enough that disruption is possible; there must be more reasons for severe disruption than against. Direct losses include replacing hardware and software, staff and overtime, contractual penalties, compensation, lost revenue, communications, legal advice and forensics; they don't include fines, routine maintenance, routine training, improvements after the incident or insurance premiums. If the loss can't be determined exactly, it is estimated (notes on the NISV 2026).
What doesn't count, and what adds up
- Planned outages and planned effects of planned maintenance are not significant incidents § 6 NISV 2026.
- Incidents that aren't significant on their own count together as one significant incident if they occurred at least twice within six months, have the same apparent cause and effect and together reach the loss threshold of no. 1 § 7 NISV 2026. The EU catalogue requires checking for this every quarter (Implementing Regulation (EU) 2024/2690, Annex point 3.4.2(b)).
- For DNS, TLD registries, cloud, data centres, content delivery, managed service providers, managed security service providers, online marketplaces, search engines, social networks and trust services, the Implementing Regulation's own thresholds apply (Art. 3 to 14); the NISV leaves them untouched (notes on the NISV 2026).
Incidents that aren't significant may still be reported
Incidents, cyber threats and near misses can be reported voluntarily § 37(1) NISG 2026, even without giving your identity § 37(3). Other reporting duties, such as for personal data breaches under the GDPR, are not affected (Federal Office, reporting duty and deadlines).
Checklist
- Our incident playbook includes the NISV 2026's nine criteria.
- We know our loss threshold: €500,000 or 5% of our annual turnover, whichever is lower.
- We know when we activate crisis management, and that the incident is then significant.
- Every quarter we check whether incidents with the same cause are recurring.
- Who decides whether an incident is significant is settled, with a deputy.
Quiz
An attack leads to activating the disaster recovery plan; the damage is below €500,000. Is the incident significant?
- Yes, activating disaster recovery plans makes it significant in any case
- Only if customers are affected
- No, the loss threshold isn't reached
- Only if the CSIRT says so
Show the answer
The answer is A: Yes, activating disaster recovery plans makes it significant in any case. § 5(1) no. 9 NISV 2026: each of the nine criteria is enough on its own.
Sources
This lesson's statements rest on:
- Network and Information System Security Act 2026 (NISG 2026) § 3, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 35, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Act 2026 (NISG 2026) § 37, Federal Legal Information System (RIS), in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 5, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 6, RIS, in German, version of 6 October 2026
- Network and Information System Security Regulation (NISV 2026) § 7, RIS, in German, version of 6 October 2026
- Implementing Regulation (EU) 2024/2690, Art. 2 and Annex, EUR-Lex (also in English)
- Explanatory notes to the NISV 2026, PDF, in German
- Federal Office for Cyber Security: reporting duty and deadlines, in German (read on 6 October 2026)
Not legal advice. What counts is the NISG 2026 and the NISV 2026 in the Federal Legal Information System and Implementing Regulation (EU) 2024/2690 (read on 6 October 2026). Not covered are the special rules for banks and financial entities (DORA), for critical entities under the RKE Act, for domain name registration services and for the public administration. Not an offer of the Federal Office for Cyber Security, a CERT or the Chamber of Commerce.