The NIS2 Directive introduces a key concept: not all cyber incidents are the same. Some must be reported because they fall into the category of significant incidents.
According to ENISA (Reg. 2690/2024), the security manager’s ‘impression’ is not enough to determine this: nine regulatory criteria must be applied, each with precise thresholds.
The main criteria include:
significant economic damage (≥ £500,000 or 5% of turnover)
exfiltration of trade secrets
CIA compromise caused by malicious action
serious operational disruption
duration of unavailability beyond sector thresholds
degradation of response time
impact on health
percentage of users affected
recurrence in the last 6 months
Each criterion requires specific information, comprehensive data and an objective approach. Performing the assessment ‘by hand’ increases the risk of error, with potential consequences in an increasingly stringent regulatory environment.
👉 Would you like to see a practical example of applied assessment?
Watch the video demo of the NIS2 Incident Significance Manager software.






