Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Incident reporting (reporting obligations)

Also known as: Security incident reporting, Reporting obligations

German: Incident Reporting (Meldepflichten)

In cybersecurity regulation, incident reporting is the obligation of an organization to notify authorities, CSIRTs or affected parties of significant security incidents or actively exploited vulnerabilities within set deadlines. In the EU, such obligations follow for example from the NIS 2 Directive and the Cyber Resilience Act.

  • OT security

In one sentence

Incident reporting obligations require organizations to notify authorities of significant security incidents or exploited vulnerabilities within set deadlines.

Example

When ransomware stopped production, the manufacturer, an important entity under NIS 2, sent an early warning to the national CSIRT within 24 hours and a fuller incident notification within 72 hours.

How it applies

  • Operation: Under the NIS 2 Directive, essential and important entities must report significant incidents in stages: an early warning within 24 hours of becoming aware, an incident notification within 72 hours and a final report within one month. National transposition laws set the details.
  • Product development: Since September 11, 2026, manufacturers under the Cyber Resilience Act (CRA) must report actively exploited vulnerabilities and severe incidents affecting the security of their products, starting with an early warning within 24 hours.
  • Organization: Reporting requires prepared roles, contacts, templates and criteria for "significant", because the clock starts running during the incident itself.
  • Documentation: Keep incident records, timelines and decisions in controlled form so that reports can be completed and later audited. Product documentation should name the channel through which customers report suspected vulnerabilities.

Incident reporting vs. vulnerability disclosure

Incident reporting informs authorities about incidents or exploited vulnerabilities. Coordinated vulnerability disclosure (CVD) is the process of receiving, fixing and publishing vulnerabilities together with the reporter and affected parties.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on Directive (EU) 2022/2555 (NIS 2) and Regulation (EU) 2024/2847 (CRA)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!