New EU regulation on when cybersecurity incident notifications can be delayed for security reasons
20 Apr 2026
91 views
Who is affected:
Companies and entities required to report cybersecurity incidents under NIS2 regulations
Summary
The EU regulates cases where companies can defer reporting cybersecurity incidents. Strict conditions are established to justify such delays.
Detailed analysis
PRO
This Delegated Regulation complements Regulation (EU) 2024/2847 by specifying the cybersecurity-related circumstances under which incident notification disclosure can be deferred. Affected organizations must demonstrate that immediate disclosure could compromise ongoing investigations or worsen the incident's impact. O…
Full official title
CELEX:32026R0881: Reglamento Delegado (UE) 2026/881 de la Comisión, de 11 de diciembre de 2025, por el que se completa el Reglamento (UE) 2024/2847 del Parlamento Europeo y del Consejo mediante la especificación de las condiciones de aplicación de los motivos relacionados con la ciberseguridad en lo que respecta al aplazamiento de la difusión de notificaciones