Definition
Severe incident having an impact on the security of the product
Also: Severe incident
An incident that negatively affects the product's ability to protect sensitive data or functions, or introduces malicious code — reportable under Article 14.
An incident having an impact on the security of a product with digital elements that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led to the introduction or execution of malicious code in the product or in the network and information systems of its users. Severe incidents follow the same 24-hour and 72-hour reporting steps as exploited vulnerabilities, with a final report one month after the notification.
Reference: Art. 3(45); Art. 14(4)–(5) · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.