The US Department of Homeland Security (DHS) and the European Commission’s Directorate General for Communications, Networks, Content, and Technology (DG CONNECT) have announced efforts to harmonize cyber incident reporting by organizations in each jurisdiction.
The first step in the initiative includes an analysis of similarities and differences between the recommendations of the DHS Report on Harmonization of Cyber Incident Reporting to the Federal Government and the cybersecurity incident reporting framework under the NIS 2 Directive in the EU.
The findings in the report of the joint analysis identify six main areas for comparative analysis between the DHS’s report and the EU’s Directive, including:
- Definitions and reporting thresholds,
- Timelines, triggers and types of cyber incident reporting,
- Contents of cyber incident reports,
- Reporting mechanisms,
- Aggregation of incident data, and
- Public disclosure of cyber incident information.
This initiative – which aligns with the 2024 Joint Statement between Secretary of Homeland Security Alejandro N. Mayorkas and European Commissioner for Internal Market Thierry Breton – marks the beginning of a process to align transatlantic cyber incident reporting where feasible.
Over the next year cooperation will continue on a more technical level, including by mapping elements such as cyber security incident taxonomies, reporting templates, and the content of reports and formats.






