Chapter 2 of 5
From Legal Interpretation to Significant-Incident Decisions
When does disruption, compromise or unauthorized access cross the legal line into a significant incident? This chapter connects the final interpretive recitals to Articles 1–16 and applies both horizontal and service-specific thresholds across the full range of covered providers.
1. The legal map: from interpretation to a decision
The instrument and its purpose
Commission Implementing Regulation (EU) 2024/2690 specifies significant incidents and cybersecurity risk-management requirements for listed digital and trust-service entities.
Read recitals and Articles differently
Recitals explain and commonly use should. Articles state operative rules and may use mandatory shall. Preserve the wording and the legal label.
The decision sequence
Apply Article 3 horizontal criteria, Article 4 recurring-incident criteria, then the provider-specific Article 5 to 14 criteria. Apply Article 3(2)'s maintenance exclusion.
Exhaustive criteria
Recital (30): "the criteria set out in this Regulation should be considered exhaustive, without prejudice to Article 5 of Directive (EU) 2022/2555".
2. Article 2: risk-appropriate security and documented judgement
Article 2(1)
The Annex contains the technical and methodological requirements for the Article 21(2)(a) to (j) cybersecurity risk-management measures.
Mandatory risk standard
Article 2(2): "The relevant entities shall ensure a level of security of network and information systems appropriate to the risks posed".
Factors that must be considered
Take due account of risk exposure, size, likelihood and severity of incidents, including their societal and economic impact.
Qualified Annex requirements
For a requirement expressed as `where appropriate`, `where applicable`, or `to the extent feasible`, a decision not to apply it requires comprehensible documented reasoning.
3. Recitals (30)-(35): awareness, affected users, maintenance, and timing
Awareness is not mere suspicion
After timely initial assessment, awareness arises when the entity has a reasonable degree of certainty that a significant incident has occurred.
Count the relevant population
Count contractual customers and associated persons using the systems or services. For trust services, consider relying parties where applicable.
Use a maximum estimate if necessary
If the entity cannot calculate impacted users, its estimate of the possible maximum affected users should be considered for the total affected-user calculation.
Maintenance is conditional
Limited availability or unavailability should not be significant when it occurs according to a scheduled maintenance operation. The scheduling condition matters.
Measure availability consistently
Measure disruption to recovery. If the start is unknown, use detection or the earliest relevant log/data record; complete unavailability ends at restoration to the prior level.
4. Recitals (36)-(40): harm, money, access, and recurrence
Direct financial losses
Incident-caused replacement, staff, contractual, redress, revenue, communication, legal, forensic, and remediation costs may be included.
What does not count in recital (36)
Administrative fines, ordinary operations, general maintenance, routine skills updating, enhancements, upgrades, risk initiatives, and insurance premiums should not count.
Human harm and limited availability
Consider severe injuries and ill-health without collecting inaccessible information. Limited availability can mean severe slowness or missing functionality.
Hostile access and recurrence
Suspectedly malicious unauthorised access capable of severe disruption matters. Individually non-significant incidents may collectively matter when linked by root cause.
5. Article 3: the horizontal significant-incident gateway
One criterion is enough
Article 3(1) applies where one or more criteria are fulfilled. A financial, human-harm, access, recurrence, or service-specific route can independently qualify.
Financial-loss threshold
The loss must exceed EUR 500 000 or 5% of preceding-financial-year turnover, whichever figure is lower. "Exceeds" means equality alone is not enough.
Other horizontal routes
Trade-secret exfiltration, death, considerable health damage, and successful suspectedly malicious unauthorised access capable of severe disruption are separate routes.
Article 3(2) and 3(3)
Scheduled interruptions and planned maintenance consequences shall not be significant. Article 3(3) prescribes user counting for Articles 7 and 9 to 14.
6. Decision drill: recurring incidents and the financial threshold
Apply Article 4 step by step
A managed service provider has three short outages. Each outage, viewed alone, does not meet Article 3's significance criteria. The outages occurred on 10 January, 2 March, and 18 May. An investigation identifies the same apparent root cause: a faulty change in a shared configuration-management process. The combined direct financial loss is EUR 320,000. The provider's total annual turnover in the preceding financial year was EUR 5 million.
Your task
Before revealing the answer, test all three Article 4 conditions:
- Did the incidents occur at least twice within 6 months?
- Do they have the same apparent root cause?
- Do they collectively meet Article 3(1)(a)?
For condition 3, calculate 5% of EUR 5 million. Compare that figure with EUR 500,000, then select whichever is lower. Finally, decide whether EUR 320,000 exceeds that lower threshold.
Model answer
Article 4 applies only where incidents individually are not significant and all three conditions are met. Here, the first condition is met: there were at least two incidents within 6 months. The second is met: they have the same apparent root cause. Five percent of EUR 5 million is EUR 250,000; that is lower than EUR 500,000. Since EUR 320,000 exceeds EUR 250,000, the third condition is also met.
Therefore, Article 4 requires the incidents to be considered collectively as one significant incident. Article 4's exact conditions include "they have occurred at least twice within 6 months" and "they have the same apparent root cause". Do not treat recurrence alone as enough: the collective financial-loss criterion is also necessary.
7. Articles 5-6: DNS service providers and TLD name registries
Article 5: complete DNS outage
For DNS providers, complete unavailability of recursive or authoritative resolution becomes significant only when it lasts more than 30 minutes.
Article 5: DNS delay
The average DNS-request response time must be more than 10 seconds for a period of more than one hour.
Article 5: authoritative data compromise
The narrow misconfiguration exception requires both fewer than 1,000 incorrect names and no more than 1% of managed names.
Article 6 is not identical
For a TLD registry, complete authoritative-resolution unavailability has no stated duration threshold; technical-operation data compromise also qualifies.
8. Articles 7-10: cloud, data-centre, CDN, and managed services
The shared pattern
Articles 7, 9, and 10 combine: complete unavailability over 30 minutes; large-scale limited availability over one hour; and specified data-compromise routes.
Smaller number controls
For the affected-user tests, compare 5% of Union users with 1 million Union users. The lower number is the applicable threshold.
Cloud example
Article 7 requires more than the lower user threshold and a duration of more than one hour for limited availability. Both the scale and duration conditions matter.
Data centres differ
Article 8 has no stated duration for complete unavailability and no user threshold for limited availability over one hour. Compromised physical access independently qualifies.
Managed and managed security services
Article 10 expressly applies to both service types. Complete unavailability for more than 30 minutes is one of its independent criteria.
9. Articles 11-16: online services, trust services, repeal, and application
Online marketplace, search, and social platforms
Articles 11 to 13 use a 5%-or-1-million Union-user threshold, whichever is smaller, for complete unavailability, limited availability, and impact-based data compromise.
No duration term in Articles 11 to 13
Unlike the cloud/CDN/managed-service limited-availability tests, Articles 11 to 13 do not state a duration condition for their availability criteria.
Trust services: faster complete-outage threshold
Article 14 treats complete trust-service unavailability for more than 20 minutes as significant and separately counts weekly unavailability to users or relying parties.
Trust-service data scale
The data-compromise threshold is more than 0.1% or more than 100 users or relying parties, whichever number is smaller.
Closing provisions
Article 15 repeals Commission Implementing Regulation (EU) 2018/151. Article 16 provides entry into force and direct applicability in all Member States.
10. Quiz: identify the correct legal route
Scenario
A cloud computing service is limited for 75 minutes. It affects 900,000 users in the Union. The service has 30 million users in the Union. No scheduled maintenance was planned.
Which statement is correct under Article 7(b)?
Which statement is correct under Article 7(b)?
- The incident is significant because 900,000 users exceed 5% of 30 million users.
- The incident is not significant under Article 7(b), because the applicable lower threshold is 1 million users and 900,000 does not exceed it.
- The incident is significant because it lasted more than 30 minutes.
- The incident is not significant because limited availability must last more than 24 hours.
Show Answer
Answer: B) The incident is not significant under Article 7(b), because the applicable lower threshold is 1 million users and 900,000 does not exceed it.
Five percent of 30 million is 1.5 million. Article 7(b) uses the smaller of 1.5 million and 1 million: therefore 1 million. The impact lasted more than one hour, but 900,000 does not exceed 1 million. The 30-minute rule applies to complete unavailability in Article 7(a), not limited availability in Article 7(b).
11. Quiz: maintenance and awareness
Scenario
At 02:00, a DNS provider begins a maintenance operation scheduled in advance. The planned consequence is 45 minutes of complete unavailability of an authoritative domain name resolution service. At 10:00 the same day, a third party reports suspicious activity. After a timely initial assessment at 11:00, the provider has a reasonable degree of certainty that a separate significant incident occurred.
Choose the most accurate answer.
Which answer correctly applies Article 3(2) and recital (31)?
- Both events are significant because any complete DNS outage longer than 30 minutes is always significant.
- The scheduled outage shall not be considered significant under Article 3(2); for the separate event, awareness occurs at 11:00 after the initial assessment provides reasonable certainty.
- The scheduled outage is significant, but awareness of the separate event began only after a final forensic report.
- Neither event can be significant because they occurred on the same day.
Show Answer
Answer: B) The scheduled outage shall not be considered significant under Article 3(2); for the separate event, awareness occurs at 11:00 after the initial assessment provides reasonable certainty.
Article 3(2) excludes scheduled interruptions and planned consequences of scheduled maintenance. Recital (31) says the entity is regarded as having become aware after initial assessment when it has a reasonable degree of certainty that a significant incident occurred. The facts place that point at 11:00 for the separate event.
12. Flashcards: thresholds and decision language
Consolidate the key legal triggers
Flip each card, then try to state the Article or recital that supports the answer. Pay particular attention to the difference between a threshold that requires both scale and duration and one that requires only the stated scale.
- When is a relevant entity 'aware' of a significant incident according to recital (31)?
- When, after the initial assessment, it has a reasonable degree of certainty that a significant incident has occurred.
- What is Article 3(1)(a)'s financial-loss threshold?
- Direct financial loss that exceeds EUR 500,000 or 5% of total annual turnover in the preceding financial year, whichever is lower.
- What three conditions must Article 4 recurring incidents meet?
- They occurred at least twice within 6 months; they have the same apparent root cause; and they collectively meet Article 3(1)(a).
- What is the Article 5 complete-unavailability threshold for DNS resolution?
- A recursive or authoritative domain name resolution service is completely unavailable for more than 30 minutes.
- What is the Article 7 cloud limited-availability test?
- More than 5% of Union users or more than 1 million Union users, whichever number is smaller, for more than one hour.
- What physical-security event independently qualifies under Article 8?
- Physical access to a data centre operated by the provider is compromised.
- What is the Article 14 complete-unavailability threshold for a trust service?
- A trust service is completely unavailable for more than 20 minutes.
- What Article 3(2) rule applies to planned maintenance?
- Scheduled interruptions of service and planned consequences of scheduled maintenance carried out by or on behalf of relevant entities shall not be considered significant incidents.
Key Terms
- relying parties
- Natural or legal persons that rely upon a trust service.
- relevant entities
- The DNS, TLD registry, cloud, data-centre, CDN, managed-service, managed-security-service, online marketplace, online search-engine, social-networking-platform, and trust-service providers listed in Article 1.
- limited availability
- As explained in recital (38), a service being considerably slower than average response time or having unavailable functionalities; the specific Article-based legal thresholds vary by provider type.
- significant incident
- An incident that fulfils one or more Article 3(1) criteria, including Article 4 recurring-incident criteria or one or more applicable entity-specific criteria in Articles 5 to 14.
- direct financial loss
- Incident-caused financial loss assessed under Article 3(1)(a), with recital (36) explaining inclusions, exclusions, and estimation where actual amounts cannot be determined.
- complete unavailability
- A service being fully unavailable to users; recital (35) explains that measurement ends when regular activities or operations are restored to the service level provided before the incident.
- same apparent root cause
- One of the cumulative Article 4 conditions for incidents that are individually not significant to be considered collectively as one significant incident.
- integrity confidentiality or authenticity
- The three protected data qualities used across Articles 5 to 14 when describing compromise of stored, transmitted, or processed data related to a covered service.