Digital Omnibus / Single Entry Point
Digital Omnibus & the Single Entry Point — proposed
Status: PROPOSAL. The Digital Omnibus was presented in November 2025 as a broad simplification package amending several digital laws at once. In the legislative process — verify before relying on detail.
The cybersecurity headline of the Digital Omnibus is the Single Entry Point (SEP) for incident reporting: today one incident can trigger separate notifications under NIS2, GDPR, DORA, CER and eIDAS — different authorities, portals, formats, languages. The SEP would let organisations report once, share many.
How the SEP would work
- A single, secure ENISA-operated interface (built on the CRA’s reporting platform).
- An organisation submits one notification; the platform filters and routes the relevant information to each competent authority.
- Interoperable with national systems (APIs, machine-readable standards); entities can retrieve what they previously submitted; fallback channels if the platform is unavailable.
- Legally anchored via a new NIS2 Article 23a establishing the SEP and ENISA’s role.
What it would cover
NIS2 significant incidents; GDPR personal-data breaches; DORA major ICT incidents (and voluntary threat notifications); CER incidents; eIDAS notifications; and CRA severe-incident/vulnerability reports — with plans to onboard further sectoral regimes (e.g. electricity NCCS, aviation) later.
The important caveat — it does not merge the legal tests
The SEP unifies the submission channel, not the underlying obligations. Each regime keeps its own threshold and timeline:
- NIS2 “significant incident” — 24h/72h/1 month;
- DORA “major ICT incident” — 4h/24h initial, 72h, 1 month;
- CER — 24h/1 month;
- CRA “severe incident” — 24h/72h/varies;
- GDPR “personal data breach” — proposed to move from 72h to 96h, threshold aligned to “high risk”. So classification decision-trees per regime remain necessary; the win is one portal, not one rulebook.
Timeline & concerns
The SEP would go live ~18 months after the Digital Omnibus enters into force (extendable to 24), following a pilot and a Commission “go-live” notice. GDPR deadline changes take effect only once the SEP is operational. Member States have raised concerns about security, technical feasibility, interoperability, single-point-of-failure risk, and ENISA’s resourcing (the Commission’s ~8-FTE estimate has been questioned).
Beyond the SEP
The Digital Omnibus also touches GDPR (personal-data definition, pseudonymisation), consolidates data rules into the Data Act, and adjusts several digital files — plus related proposals for a European Business Wallet and a Data Union Strategy.
Relationship to other files
- Changes reporting under → NIS2, GDPR, DORA, CER, eIDAS, CRA (
../10-eu-regulations/) - Wired into NIS2 via →
nis2-amendments-2026.md - ENISA operates it per →
cybersecurity-act-2.md
Sources
- European Parliament briefing on the SEP: https://www.europarl.europa.eu/thinktank
- Commission Digital Omnibus (package documents): https://digital-strategy.ec.europa.eu