Further clarification of the reporting obligation under the Cybersecurity Act for the digital infrastructure sector
On 21 July 2026, the regulation of the State Secretary for Economic Affairs and Climate Policy (staatssecretaris van Economische Zaken en Klimaat; the “State Secretary”), laying down rules for essential and important entities in the Economic Affairs and Climate Policy sectors (the “Regulation EZK”), was published. This Regulation EZK sets out further details of the Cybersecurity Act (Cyberbeveiligingswet; “Cbw”) and the Cybersecurity Decree (Cyberbeveiligingsbesluit; “Cbb”), both of which come into force on 15 August 2026.
Our previous blog post of 25 November 2025 focused on the duty of care under the consultation version of the Regulation EZK. This post focuses on another key obligation, namely the duty to report.
To whom does the Regulation EZK apply?
The Regulation EZK applies to the sectors of digital infrastructure, ICT service management, space, manufacturing, and postal and courier services. This blog is limited to the detailed rules relating to the reporting obligation for the digital infrastructure sector. Within the digital infrastructure sector, the Regulation EZK applies to the following three types of entities:
- Providers of public electronic communications networks;
- Providers of public electronic communications services; and
- Providers of internet exchange points.
For other entities within the digital infrastructure sector that fall under the Cbw, the obligations regarding the duty of care and the reporting obligation are governed directly by Implementing Regulation (EU) 2024/2690. These include DNS service providers, top-level domain name registries, cloud computing service providers, data centre service providers, content delivery network providers and trust service providers. The same applies to managed security service providers and digital service providers, such as online marketplaces, online search engines and social networking platforms.
When is an incident considered significant?
Under the Cbw, essential and important entities are required to report significant incidents to their Computer Security Incident Response Team (“CSIRT”) and the competent authority. To this end, the Minister of Justice and Security is establishing a single central reporting point.
The statutory threshold is set out in Article 25(2) of the Cbw. Under this article, an incident is considered significant if it:
- Causes or is likely to cause a serious operational disruption to the services or financial losses for the entity concerned; or
- Has affected or may affect other entities by causing significant material or immaterial damage.
These standards are open-ended. Article 23(1) of the Cbb therefore empowers the relevant minister to lay down further criteria, differentiated by (sub)sector, by regulation.
General criteria
Article 7 of the Regulation EZK contains general criteria that apply to all sectors covered by the regulation. Pursuant to this article, an incident is in any event significant if:
a) It causes or is likely to cause the death of one or more persons; or
b) It has caused, or is likely to cause, significant harm to the health of one or more persons.
It is important to note that anticipated consequences of planned maintenance, such as a temporary interruption to the service, do not, in principle, constitute a significant incident. As regards the timing of the report, an entity must report the incident as soon as it becomes aware of it, even if the consequences only become clear at a later stage. Entities are not required to gather information to which they do not reasonably have access.
Further criteria for public electronic communications networks and services
Article 8 of the Regulation EZK stipulates that an incident involving providers of public electronic communications networks and services is, in any event, significant if:
a) In the event of an outage, at least 50,000 users are affected for four hours or longer;
b) The integrity, confidentiality or authenticity of data processed in connection with the provision of the service has been compromised, affecting at least 1 per cent of users, with a minimum of 10,000 users; or
c) The emergency number is unavailable.
Following consultation, the thresholds have been set to strike a balance between impact and regulatory burden. The four-hour threshold and the minimum threshold prevent every short-term disruption or minor impairment from triggering a reporting obligation. The term ‘users’ refers to any natural or legal person who uses the service, even without a subscription.
The term ‘service’ refers not only to the public electronic communications network or public electronic communications service offered, but also to the supporting services or network and information systems of the entity that are necessary for providing them.
Under point (c), an incident is only subject to the reporting obligation if it occurs within the 112 chain at or under the responsibility of the provider of the public electronic communications network or the public electronic communications service.
Further criteria for internet exchange points
Pursuant to Article 9 of the Regulation EZK, an incident is in any event considered significant for providers of internet exchange points if:
a) At least 25 per cent of the current total traffic (in bits per second) has been disrupted for at least 30 minutes; or
b) The integrity, confidentiality or authenticity of data processed in connection with the provision of the service has been compromised, affecting more than 5 per cent of users.
The 5% threshold has been deliberately aligned with the existing reporting criteria set out in Implementing Regulation (EU) 2024/2690, so that providers are subject to recognisable, consistent rules.
The safety net
The reporting criteria in the Regulation EZK are not exhaustive. The criteria set out determine when an incident is, in any event, considered a significant incident. If an incident meets one or more of these criteria, it must be reported. The statutory criteria of Article 25(2) of the Cbw remain fully applicable as a safety net. The assessment therefore takes place in two stages. The criteria in the Regulation EZK form the primary framework. If an incident does not fall within this framework, an assessment must still be carried out on the basis of the open criteria to determine whether a significant incident has occurred.
Concluding remarks
The explanatory notes to the Regulation EZK emphasise that the reporting obligation is not limited to incidents resulting from malicious acts or unauthorised access; incidents resulting from human error are also covered. According to the explanatory notes, examples of this include the inadvertent disclosure of confidential data or the incorrect execution of a system update, as a result of which the network and information systems no longer function properly.
Do you have any questions about the Cbw or the Regulation EZK? Please contact Machteld Robichon, Bente van Kan or Lucas de Vet.
With thanks to Daan Zwinkels
