EU cyber reporting reforms face setback

Ferma has warned that the European Union may lose a chance to streamline cyber-incident reporting after the Digital Omnibus was divided into separate AI and data packages. The split follows objections from several member states about a centralised reporting platform. The organization argues that a unified system would simplify compliance for firms operating in multiple jurisdictions.
Package division stalls single-point proposal
The European Commission introduced the Digital Omnibus in November, bundling reforms for artificial intelligence, cybersecurity and data rules. Part of the plan sought to create a Europe-wide entry hub for notifying authorities after a breach. The launch was presented as a major step toward harmonising cross-border obligations.
Negotiations on the AI portion concluded, and the AI Omnibus entered force on 27 July. The data component, which contains the reporting hub and related GDPR changes, remains under discussion and is unlikely to be adopted before the end of the year. Ongoing talks focus on how the hub will interact with existing national systems.
Member-state concerns, notably from France and Germany, delayed progress. Officials cited security risks and interoperability questions about linking a central hub with national systems.
Industry reaction to fragmented approach
Ferma’s chief executive, Laurent Nihoul, said the security worries have pushed back the single-point initiative. “Progress on the single entry-point has faced delays due to security concerns raised by several member states, including France and Germany, regarding a centralised reporting platform and its interoperability with existing national infrastructure,” he explained. The federation continues to press policymakers for a faster resolution.
President Philippe Cotelle said the current state of the package represents a “missed opportunity.” He noted that companies must now file multiple, often overlapping reports to different authorities across the bloc. Cotelle emphasized that the added paperwork strains resources.
The federation plans to keep advocating for a simpler, coordinated method that would let firms submit one report covering obligations under NIS2, GDPR, DORA, CER and eIDAS.
Potential savings and stakeholder concerns
The Commission estimates that the proposal would reduce reporting costs by at least 50%, possibly rising to 80%. A study by the European Cyber Security Organisation found that 82% of entities said they have to notify more than one authority following a cyber incident, with 21% of respondents stating they had to notify five authorities.
During a consultation on the Digital Omnibus, stakeholders told the EC that this discourages firms from reporting incidents, potentially lowers compliance rates and reduces the amount of meaningful shared data. The reporting burden comes just as companies are trying to deal with a cyber incident, taking their focus away from responding to an event, the EC was told.
While the proposal does not alter the rules and obligations companies face, it is the fastest way to reduce the administrative burden. The proposal’s costs would be borne by the European cyber agency ENISA, which would also be responsible for developing and maintaining the system.
Implementation responsibilities and outlook
Under the plan, the European cyber agency ENISA would fund, develop and maintain the reporting hub. The EC has also recognised the potential need to integrate national solutions with the single entry-point.

YMCA-YWCA Education Staff Earns International Trade Certification
