European Union (NIS) Regulations 2018, Incident Notification
S.I. No. 360/2018, Regs. 18 and 22
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 18 September 2018.
A vulnerability and incident reporting rule binding public and private bodies.
As of 12 September 2026.
What it requires
- This binds a relevant digital service provider (an online marketplace, online search engine or cloud computing service under Schedule 2) and a designated operator of essential services under Schedule 1; the operator-of-essential-services sector and designation class is not separately flagged here, for the reason given on this jurisdiction's companion security-requirements row.
- Notify the State's CSIRT without delay and in any event not later than 72 hours after becoming aware of an incident with a significant impact on the continuity of your essential service, or a substantial impact on your digital service, including an incident affecting a third-party digital service provider you rely on.
- Notify the CSIRT again once the incident has been resolved.
- Where the incident also compromises personal data, expect the competent authority, the CSIRT or the single point of contact to cooperate with the Data Protection Commission on it, a duty separate from your own breach-notification duty to the Commission under the General Data Protection Regulation.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A failure to notify the CSIRT under Regulation 18 or 22 is itself an offence under Regulation 34, unlike a failure to take the Regulation 17 or 21 security measures, which is enforced only through a compliance notice.
Penalty structure
Regulation 34 makes a person guilty of an offence under Regulation 18 or 22 (among others) liable, on summary conviction, to a class A fine, or, on conviction on indictment, to a fine not exceeding EUR 50,000 for an individual or EUR 500,000 for a person other than an individual.
- Rule
- Fixed only
- As of
- 12 September 2026
- Currency
- EUR
- Fixed cap
- 500,000
Who enforces it
Enforcement body
The Minister (or, for the banking and financial-market-infrastructure sectors, the Central Bank of Ireland) as competent authority, with the National Cyber Security Centre's CSIRT unit receiving and handling the notification.
What it reaches
Obligation class
Reporting, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Regulation 18 requires a designated operator of essential services to notify the State's CSIRT, without delay and in any event not later than 72 hours after becoming aware, of an incident with a significant impact on the continuity of an essential service it provides, including an incident affecting a third-party digital service provider it relies on, and to notify the CSIRT again once the incident is resolved.
Regulation 22 imposes the equivalent duty on a relevant digital service provider for an incident with a substantial impact on a service listed in Schedule 2. The CSIRT is the unit of the State's cybersecurity department that Regulation 10 designates.
Regulation 6 requires the competent authority, the CSIRT and the single point of contact to cooperate with the Data Protection Commission where a notified incident also compromises personal data, a duty distinct from the breach-notification duty General Data Protection Regulation (GDPR) itself imposes on a controller.
When LexLint raises it
operates_social_platform
Read the law
Statutory Instrument text, Irish Statute Book, S.I. No. 360 of 2018