Source: OJ L, 2024/2690, 18.10.2024

Current language: EN

Article 14 Significant incidents with regard to trust service providers


Summary What does Article 14 of the Cybersecurity measures and significant incidents for relevant entities say?

This article sets out the specific thresholds that determine when an incident affecting a trust service provider is considered significant.

It sits within the broader framework established by Article 3, which defines significance criteria across all relevant entity types, and this article provides the sector-specific detail for trust service providers.

Notably, the thresholds here are comparatively stricter than those applied to other entity types in the regulation, reflecting the critical and sensitive nature of trust services — such as electronic signatures and certificates — which underpin secure digital transactions across the EU.

Important points:

  • Trust service providers must be aware that complete unavailability of a trust service for just 20 minutes is sufficient to trigger a significant incident.
  • The data integrity threshold is particularly demanding: a compromise affecting more than 0.1% of users or relying parties, or more than 100 individuals, whichever is smaller, qualifies as significant.
  • Physical security breaches — specifically, unauthorised or compromised access to restricted areas housing network and information systems — also independently qualify as a significant incident.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

With regard to trust service providers, an incident shall be considered significant under Article 3(1)(g) where it fulfils one or more of the following criteria:

  1. a trust service is completely unavailable for more than 20 minutes;

  2. a trust service is unavailable to users, or relying parties, for more than one hour calculated on a calendar week basis;

  3. more than 1 % of the users or relying parties in the Union, or more than 200 000 users or relying parties in the Union, whichever number is smaller, are impacted by limited availability of a trust service;

  4. physical access to an area where network and information systems are located and to which access is restricted to trusted personnel of the trust service provider, or the protection of such physical access, is compromised;

  5. the integrity, confidentiality or authenticity of stored, transmitted or processed data related to the provision of a trust service is compromised with an impact on more than 0,1 % of users or relying parties, or more than 100 of users or relying parties, whichever number is smaller, of the trust service in the Union.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod