Law / Iceland

Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response Team

Log nr. 78/2019, Art. 8

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2020.

A vulnerability and incident reporting rule binding public and private bodies.

As of 15 September 2026.

What it requires

  • This duty binds the same digital-infrastructure operators and digital-service providers as the risk-management duty of Article 7, other than a micro-enterprise, plus the same broader sector-gated essential-service population this vocabulary cannot express.
  • Notify Iceland's national cybersecurity incident-response team as soon as may be about a serious incident or risk threatening the security of a network or information system; the Act sets no fixed hour-based clock of its own for this notification.
  • State in the notification the number of affected users, the incident's duration, its geographic spread and scale, any outsourcing arrangement relied on, and any possible cross-border contagion effect.
  • An operator in banking or financial-market infrastructure notifies under Regulation (EU) 2022/2554 (DORA) and Iceland's implementing act instead of under this article.
  • A breach of this duty draws an administrative fine of up to ISK 10,000,000, capped at 3 percent of turnover for a legal entity, and, if committed intentionally, imprisonment for up to two years; knowingly or recklessly giving a false notification is separately punishable under the General Penal Code.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 26: an intentional breach of Article 8 (notification of a serious incident or risk), Article 7 (risk-management and preparedness) or Article 19 (special confidentiality duty) is punishable by imprisonment for up to two years, unless a heavier penalty applies under other law. A person who intentionally or through gross negligence gives a false notification under Article 8 or Article 15 is separately liable under Articles 120 and 120a of the General Penal Code, No. 19/1940. Where an Article 7, 8 or 19 offence is committed in the operations of a legal entity, the legal entity may instead be fined under Chapter II A of the same Code.

Penalty structure

Article 23 sets a base range of ISK 10,000 to ISK 10,000,000 for a breach of Article 7, 8 or 19, further capped at 3 percent of the offender's turnover for the last calendar year where the offender is a legal entity, which binds below the ISK 10,000,000 figure for a smaller entity. A separate daily coercive fine of up to ISK 500,000 per day (Article 22) may be imposed for failing to comply with a supervisory order or a request for information or data under Article 12, running until the entity complies.

Rule
Fixed only
As of
15 September 2026
Minimum
10,000
Currency
ISK
Fixed cap
10,000,000

Who enforces it

Enforcement body

Fjarskiptastofa (the Icelandic Post and Telecom Administration), which Article 11 designates as the sector supervisory authority for the network and information systems of digital-infrastructure operators (internet exchange points, DNS service providers and top-level domain registries) and, under the article's closing paragraph, for providers of a digital service (online marketplace, online search engine or cloud computing service). Iceland's national cybersecurity incident-response team, which receives the Article 8 notification itself, sits at the Ministry for Foreign Affairs and is legally distinct from the supervisory authority since Act No. 51/2025.

Settledness

Regulation (EU) 2024/2847 (the Cyber Resilience Act) is tracked by the same government database at the equivalent status: an EU act under review by Iceland, Liechtenstein and Norway for EEA incorporation, with domestic implementation work not begun, and not itself in force in Iceland.

As of
15 September 2026
Guidance link
https://gagnagrunnur.ees.is/32022l2555
Guidance body
Government of Iceland, Ministry for Foreign Affairs, EEA Agreement Database (EES-gagnagrunnur)
Open questions
Iceland's own EEA-incorporation tracker records Directive (EU) 2022/2555 (NIS2) as still under review by Iceland, Liechtenstein and Norway with domestic implementation work not begun, and NIS2 Article 23 would add the tiered 24-hour, 72-hour and one-month reporting clock this Article currently lacks: when Iceland transposes NIS2, will the resulting notification duty still reach the same digital-infrastructure and digital-service-provider population this row describes, or will the population change along with the clock?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 8 requires an operator of essential services or a provider of digital services within the Act's scope to notify Iceland's national cybersecurity incident-response team of a serious incident or risk threatening the security of its network and information systems as soon as may be, with severity assessed by the number of users affected, the duration of the incident, its geographic spread and scale, and its possible effect on other critical infrastructure or on economic and social activity or digital services; the notification must also disclose any outsourcing arrangement the operator relies on and any possible cross-border contagion effect.

The duty carries no fixed reporting-clock deadline of its own, unlike the tiered 24-hour, 72-hour and one-month clock of the EU's NIS2 Directive. An operator in banking and financial-market infrastructure instead notifies under Regulation (EU) 2022/2554 (DORA) and Iceland's implementing act. The duty binds the same digital-infrastructure and digital-service-provider population as Article 7, and the same broader, sector-gated essential-service categories that this vocabulary cannot express.

When LexLint raises it

  • operates_social_platform

Read the law

Official consolidated text, Althingi Lagasafn (Icelandic Law Database)

Back to the example  ·  Lint your app