Llei 22/2022, Incident Handling and Notification Obligation
Llei 22/2022, del 9 de juny, arts. 14 i 15
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 23 June 2022.
A vulnerability and incident reporting rule binding public and private bodies.
As of 18 September 2026.
What it requires
- This duty reaches your service under the same essential- or important-entity thresholds as this Law's risk-management obligations: 50 or more employees, or annual turnover or annual balance sheet total over ten million euros, within an Annex I or Annex II sector, which for Annex II includes Andorra's online marketplace, online search engine and social networking services platform providers.
- Manage and resolve any security incident affecting the critical infrastructure, networks or information systems you use to provide your essential or important service, including by ensuring any external provider of those systems applies the necessary security measures, and request the CSIRT-AD's opinion or specialised support where needed; the CSIRT-AD's indications to mitigate effects and restore affected systems are binding on you.
- Notify the CSIRT-AD, without delay and in any event within 72 hours of becoming aware of it, of any incident that has or may have significant effects on your essential or important service, including information on any cross-border effects; where you cannot yet establish that effect, you may omit it if you send a justificatory report within 72 hours of the notification explaining why.
- Where appropriate, notify the recipients of your service, without undue delay, that a significant incident is likely to affect them and what measures or remedies they can take in response.
- Notify the competent authority, through the CSIRT-AD and without delay, of a significant cyber threat to your essential or important service that you believe could result in a significant incident, once the threshold for that duty is further specified by regulation.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Article 34.2(c) classifies a repeated failure, from the second instance, to notify a significantly disruptive incident under Article 15 as a very serious violation, and Article 34.2(d) classifies a failure to resolve an incident under Article 14 that has a significant disruptive effect as a very serious violation; each carries a fine of 30,001 to 100,000 euros under Article 36.1(a). Article 34.4(b) classifies an incomplete Article 15.1 incident notification, failing to complete the required information or failing to send the justificatory report, as a minor violation, a warning or a fine of 500 to 15,000 euros under Article 36.1(c); a first, non-repeated notification shortfall or another Article 14 or 15 shortfall not otherwise classified falls to the serious tier, 15,001 to 30,000 euros, under Article 34.3(a) and Article 36.1(b).
- Rule
- Fixed only
- As of
- 18 September 2026
- Minimum
- 500
- Currency
- EUR
- Fixed cap
- 100,000
Who enforces it
Enforcement body
The Agència Nacional de Ciberseguretat del Principat d'Andorra (ANC-AD, Andorra's National Cybersecurity Agency) holds the sanctioning power under Article 30, including over entities supervised by the Autoritat Financera Andorrana (AFA, the Andorran Financial Authority), at AFA's request. AFA is itself the competent national authority, coordinating with ANC-AD, for the banking and financial-market-infrastructure sectors.
Settledness
- As of
- 18 September 2026
- Open questions
- Has the regulatory instrument that Article 15.1 defers to, defining which incidents have 'significant effects' on an essential or important service, been adopted, or does the significance threshold currently rest on the competent national authority's own case-by-case reading?
- Does 'significant effects' under Article 15.1 track the same materiality test Article 34.2(c)-(d) uses for a very serious violation, or a different, lower threshold for triggering the duty to notify at all?
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 14 of Llei 22/2022, del 9 de juny, de mesures per a la seguretat de les xarxes i dels sistemes d'informació requires an essential or important entity to manage and resolve any security incident affecting the critical infrastructure, networks or information systems it uses to provide its essential or important service, including by ensuring that an external provider of those infrastructures, networks or systems applies the necessary security measures.
Article 15 requires the entity to notify the CSIRT-AD, without delay and in any event within seventy-two hours of detection, of any incident that has or may have significant effects on that service, together with any information letting the competent authority or CSIRT-AD determine the incident's cross-border effects.
Where the entity cannot yet establish that effect at the time of notifying, it may omit that information, provided it sends the CSIRT-AD a justificatory report within seventy-two hours of the notification explaining why. Where appropriate, the entity must also notify, without undue delay, the recipients of its services whom the incident may affect, together with the measures or remedies they can take in response.
A repeated failure to notify a significantly disruptive incident under Article 15, from the second such failure, and a failure to resolve an incident under Article 14 that has a significant disruptive effect on an essential or important service in Andorra or abroad, are each classified as a very serious violation.
When LexLint raises it
operates_social_platform