(c)
Cyber Resilience Act
unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following: a detailed description of the incident, including its severity and impact; the type of threat or root cause that is likely to have triggered the incident; applied and ongoing mitigation measures.
← (b) · All articles · (i) →
Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.