Registration deadlines
| Entity | Deadline | Channel |
|---|---|---|
| Essential (Annex I, large) | 60 days | ENIRE@RO v2 |
| Important (Annex I/II, medium) | 150 days | ENIRE@RO v2 |
| New entities becoming applicable | Same windows from event date | ENIRE@RO v2 |
Use the free classification tool to confirm your entity type and starting date.
Incident reporting timeline
- 6 hours — early notification for cross-border impact incidents.
- 24 hours — early warning (initial assessment).
- 72 hours — incident notification (cause, impact, IoCs).
- 1 month — final report (root cause, mitigation, lessons learned).
Ongoing obligations
- Periodic effectiveness assessment of Art. 21 measures.
- Annual cybersecurity governance review by the management body.
- Supply chain risk reviews (SCRM).
- Training and awareness — at least annual.
- BCM/DR exercises — at least annual.
Sanctions for missing deadlines
Up to 10M EUR or 2% of global turnover for essential entities; 7M EUR or 1.4% for important entities. Personal liability of management body members on repeated non-compliance.
