Feature 2 of 6 · Incidents
When something happens Record it once, miss no deadline.
With a significant security incident, the clock starts the moment you know about it. UniqSuite tells you what has to be reported and by when.

What it is about
In an emergency nobody has time to read legislation. Under the BSIG, an early warning is due within 24 hours, the notification with an initial assessment within 72 hours and the final report one month later. If the Cyber Resilience Act also applies to you, or you operate high-risk AI, there are further reporting channels.
What you do with it
- Record an incident once, with the time you became aware, the impact and the services affected.
- See which reporting duties follow from your frameworks.
- Keep the deadline timers in view: 24 hours, 72 hours, one month.
- Move measures and lessons from the incident straight into the plan.
What you get out of it
- No missed report because someone got the deadline wrong.
- A complete history if the authority asks later.
Part of these steps
Where the requirements come from
- BSIG section 32: reporting duties for significant security incidents
- BSIG section 30(2) no. 2: incident handling
- ISO/IEC 27001, Annex A 5.24 to 5.28: information security incident management
- CRA Art. 14: reporting obligations of manufacturers
The references show where the requirements come from. They do not replace a legal assessment.
See it with your own questions.
In half an hour we show you what this feature looks like in your day-to-day work. Or check first where you stand with the quick check.
