Digital Omnibus / Single Entry Point

← All proposals

PROPOSAL

PROPOSAL
Proposed
2025-11
Key date
proposed 2025-11
Last verified
2026-07-16

Digital Omnibus & the Single Entry Point — proposed

Status: PROPOSAL. The Digital Omnibus was presented in November 2025 as a broad simplification package amending several digital laws at once. In the legislative process — verify before relying on detail.

The cybersecurity headline of the Digital Omnibus is the Single Entry Point (SEP) for incident reporting: today one incident can trigger separate notifications under NIS2, GDPR, DORA, CER and eIDAS — different authorities, portals, formats, languages. The SEP would let organisations report once, share many.

How the SEP would work

  • A single, secure ENISA-operated interface (built on the CRA’s reporting platform).
  • An organisation submits one notification; the platform filters and routes the relevant information to each competent authority.
  • Interoperable with national systems (APIs, machine-readable standards); entities can retrieve what they previously submitted; fallback channels if the platform is unavailable.
  • Legally anchored via a new NIS2 Article 23a establishing the SEP and ENISA’s role.

What it would cover

NIS2 significant incidents; GDPR personal-data breaches; DORA major ICT incidents (and voluntary threat notifications); CER incidents; eIDAS notifications; and CRA severe-incident/vulnerability reports — with plans to onboard further sectoral regimes (e.g. electricity NCCS, aviation) later.

The SEP unifies the submission channel, not the underlying obligations. Each regime keeps its own threshold and timeline:

  • NIS2 “significant incident” — 24h/72h/1 month;
  • DORA “major ICT incident” — 4h/24h initial, 72h, 1 month;
  • CER — 24h/1 month;
  • CRA “severe incident” — 24h/72h/varies;
  • GDPR “personal data breach” — proposed to move from 72h to 96h, threshold aligned to “high risk”. So classification decision-trees per regime remain necessary; the win is one portal, not one rulebook.

Timeline & concerns

The SEP would go live ~18 months after the Digital Omnibus enters into force (extendable to 24), following a pilot and a Commission “go-live” notice. GDPR deadline changes take effect only once the SEP is operational. Member States have raised concerns about security, technical feasibility, interoperability, single-point-of-failure risk, and ENISA’s resourcing (the Commission’s ~8-FTE estimate has been questioned).

Beyond the SEP

The Digital Omnibus also touches GDPR (personal-data definition, pseudonymisation), consolidates data rules into the Data Act, and adjusts several digital files — plus related proposals for a European Business Wallet and a Data Union Strategy.

Relationship to other files

  • Changes reporting under → NIS2, GDPR, DORA, CER, eIDAS, CRA (../10-eu-regulations/)
  • Wired into NIS2 via → nis2-amendments-2026.md
  • ENISA operates it per → cybersecurity-act-2.md

Sources