The organization informs the Authority without undue delay about any incident that has a significant impact on the provision of its services (a "significant incident"). The Authority, upon receipt, forwards the notification to the national CSIRT.
A significant incident is one where at least one of the following occurs:- disruption may cause serious disruption in the operation of services or serious financial losses for the service provider
- disruption may cause significant material or immaterial damage to related people or other organizations
Notifications are to be made step-by-step according to the descriptions below.
Early warning (at the latest within 6 hours of becoming aware of the significant incident)
- is the cause suspected to be illegal activities;
- can the disruption have effects on other countries.
Incident notification (at the latest within 72 hours of becoming aware of the significant incident)
- update the information from the early warning;
- an initial assessment of the significant incident, including its severity and impact;
- possible evidence of the leakage is listed;
- for trust service providers, this notification must be made within 24 hours of becoming aware of the incident.
Interim reports- submitted upon request from the authority, providing relevant status updates on the incident.
Final report (at the latest within 1 month of submitting the incident notification)
- a detailed description of the incident, including its severity and its impact;
- type of threat or the root cause that is likely to have triggered the incident;
- applied and ongoing mitigation measures;
- potential impact on other countries.
Progress reports (for ongoing incidents)
- if an incident is ongoing at the time the final report is due, a progress report should be submitted instead;
- additional progress reports are required every 15 days until the final report can be submitted.