Definition

Severe incident having an impact on the security of the product

Also: Severe incident

An incident that negatively affects the product's ability to protect sensitive data or functions, or introduces malicious code — reportable under Article 14.

An incident having an impact on the security of a product with digital elements that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led to the introduction or execution of malicious code in the product or in the network and information systems of its users. Severe incidents follow the same 24-hour and 72-hour reporting steps as exploited vulnerabilities, with a final report one month after the notification.

Reference: Art. 3(45); Art. 14(4)–(5) · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.