How this links to the Cyber Security and Resilience Bill
The Bill defines a full notification with a fixed list of contents and a 72-hour deadline that runs from the same moment as the 24-hour clock. For data centres, digital service providers and managed service providers, giving it also starts the duty to notify affected customers. Content failures are in the higher penalty band.
- Reg 11(2)(b), 11(5) and 11(6)(b): OES full notification, contents and deadline.
- Reg 11A(2)(b), 11A(4) and 11A(5)(b): data centre equivalent.
- Reg 12A(1)(b), 12A(4) and 12A(5)(b): RDSP equivalent.
- Reg 14E(1)(b), 14E(4) and 14E(5)(b): RMSP equivalent.
- Regs 11C(2), 12C(1) and 14G(1): customer notification follows the full notification.
When is the full notification due?
Each regulation says the full notification must be given "before the end of the period of 72 hours beginning with that time", where "that time" is the moment of first awareness used for the initial notification. The two clocks start together.
So if you became aware on Monday at 09:00, the initial notification is due by Tuesday 09:00 and the full notification by Thursday 09:00. Reading the deadline as 72 hours after the initial notification would overstate the window by up to a day.
What must the full notification contain?
The content list is the same for each group, adjusted for the type of service. It must be given "so far as known", in writing, and in the form the regulator determines.
- the organisation's name and the affected service;
- the time the incident occurred, its duration and whether it is ongoing;
- information on the nature of the incident;
- where it was caused by an incident affecting another regulated person, details of that incident and that person;
- information on the impact, including cross-border impact (for data centres, including impact it could have had);
- any other information that may help the regulator exercise its functions.
What happens after the full notification?
For data centre operators, a relevant digital service provider and a relevant managed service provider, giving the full notification starts the customer notification duty. The regulator and the CSIRT may also share information with the organisation, other regulated persons or authorities abroad, and in some cases require or make public disclosure.
Regulators can also follow up with an information notice or an inspection if the full notification leaves questions open. Keep the incident record, timeline and evidence behind the report, because the same facts will be tested later.
Incident notification rules compared: OES, data centre, RDSP and RMSP
| Rule | OES (non-data centre) | Data centre OES | RDSP | RMSP |
|---|---|---|---|---|
| Regulation | Reg 11 | Reg 11A | Reg 12A | Reg 14E |
| Who you notify | Designated competent authority for the OES | Designated competent authority (Ofcom, cl.4(2)) | Information Commission | Information Commission |
| What makes it reportable | Has affected or is affecting the operation or security of the systems, and impact has been, is or is likely to be significant (reg 11(3)-(4)) | Could have had, has had, is having or is likely to have a significant impact (reg 11A(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 12A(2)-(3)) | Has affected or is affecting the systems, and impact is or is likely to be significant, with 7 factors (reg 14E(2)-(3)) |
| 24-hour initial notification | From first awareness (reg 11(6)(a)) | From first awareness (reg 11A(5)(a)) | From first awareness (reg 12A(5)(a)) | From first awareness (reg 14E(5)(a)) |
| 72-hour full notification | From the same moment of first awareness (reg 11(6)(b)) | From the same moment (reg 11A(5)(b)) | From the same moment (reg 12A(5)(b)) | From the same moment (reg 14E(5)(b)) |
| Customer notification duty | None in the Bill | Yes, reg 11C | Yes, reg 12C | Yes, reg 14G |
| Copy to the CSIRT (NCSC) | At the same time, reg 11(8) | At the same time, reg 11A(7) | At the same time, reg 12A(7) | At the same time, reg 14E(7) |
Worked example (illustrative)
Illustrative timeline
A cloud provider's on-call engineer confirms at 14:00 on Wednesday that customer data stores were encrypted by ransomware and the outage is significant. The initial notification to the Information Commission, copied to the NCSC, is due by 14:00 Thursday. The full notification, with timing, nature, impact and any supplier incident that caused it, is due by 14:00 Saturday. Customer notifications follow as soon as reasonably practicable after that.
Where it appears in the Bill
- New reg 11(5)-(6)OES full notification contents and 72-hour deadline.
- New reg 11A(4)-(5)Data centre contents and deadline.
- New reg 12A(4)-(5)RDSP contents and deadline.
- New reg 14E(4)-(5)RMSP contents and deadline.
- New reg 18(11)Timing and content failures in the higher penalty band.
References are to HL Bill 32 as brought from the Commons. Read the Bill.
Frequently asked questions
Is the 72-hour report due 72 hours after the 24-hour notification?
No. Both periods begin at the time the organisation is first aware that a reportable incident has occurred or is occurring. The full notification is due 72 hours from that moment, which is 48 hours after the initial notification deadline. This applies to operators of essential services, data centres, digital service providers and managed service providers alike.
What if we do not know everything within 72 hours?
The full notification must contain the listed information "so far as known" to the organisation. You are not expected to have finished the investigation, but you must give what you know by the deadline. Regulators can then use information notices to ask for more, so keep your incident record current as the facts develop.
Does the full notification have to mention a supplier?
Yes, where relevant. If the incident was caused by a separate incident affecting another regulated person, such as a managed service provider or a critical supplier, the full notification must include details of that separate incident and of the regulated person. This helps regulators trace supply chain incidents across several organisations.