Cybersecurity
Incident Reporting
The mandatory notification of cybersecurity incidents and space safety events to relevant authorities within specified timeframes.
Incident reporting obligations require space operators to promptly notify authorities of significant events affecting safety, security, or operations.
Cybersecurity Incidents (NIS2) Timeline for significant incidents, to the CSIRT or, where applicable, the competent authority (Art. 23(4)):
- Early Warning: Without undue delay and in any event within 24 hours of becoming aware
- Incident Notification: Without undue delay and in any event within 72 hours of becoming aware
- Intermediate Report: On request of the CSIRT or competent authority
- Final Report: Not later than one month after the incident notification; for an ongoing incident, a progress report then and the final report within one month of handling it
EU Space Act proposal (COM(2025) 335, not in force)
- Significant incidents affecting Union-owned assets would be reported to the structure under Art. 34(4) of Regulation (EU) 2021/696, other significant incidents to the competent authority (Art. 93(1)-(2)); NIS2 entities would report through the CSIRT or NIS2 authority (Art. 93(3))
- Unplanned changes affecting compliance would be reported to the Union collision avoidance provider (Art. 64(3)(c)), as would actions taken after a high interest event alert (Art. 64(5))
Reporting Channels
- CSIRT or, where applicable, competent authority under NIS2 (Art. 23(1))
- Competent authority under the national space law
- Insurance providers
Content Requirements Reports must include:
- Event timeline
- Impact assessment
- Root cause (when known)
- Mitigation measures taken
- Lessons learned
Confidentiality Incident information is protected but may be anonymized and shared to improve sector-wide security.