Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Which cybersecurity reporting deadline fires first?
Updated
Statutory clocks differ by regime. GDPR Article 33 is 72 hours from awareness; CRA Article 14 is a 24-hour, 72-hour, and 14-day ladder. This table is not legal advice, does not start a clock, and does not average those times.
Statute table, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 33, Directive (EU) 2022/2555 Article 23, Regulation (EU) 2022/2554 Article 19, Commission Delegated Regulation (EU) 2025/301 Article 5, Regulation (EU) 2024/2847 Article 14, Form 8-K Item 1.05 and 17 CFR 229.106, HIPAA 45 CFR §164.404, and Cal. Civ. Code §1798.82. It is not legal advice, not a filing, and not a substitute for counsel.
This is a statute table, not YOUR clock
Audience: a compliance lead, CISO, incident commander, or counsel triaging which reporting clock might fire first. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the regime applies, that the trigger event has occurred, or that you must file.
One incident can start more than one clock at once — personal-data notification, sector incident reporting, listed-issuer disclosure, and product-vulnerability reporting are different duties with different recipients and different start events. Filing one never discharges the others. Last verified 7 September 2026. Not legal advice.
- Statutory times are quoted in the article's words. This page does not average them, does not round 72 hours to three days, and does not invent a US-state typical deadline.
- Clock-start is the event the cited article names — awareness, determination, discovery, or classification. Those words are not interchangeable.
- The who-to-notify page on this site is the recipient-class map. Unpublished guides (failure-to-report, how-regulators-determine-knowledge, GDPR, NIS2, DORA, CRA Article 14 feature page, US-state, SEC, HIPAA) are named in prose only. A dedicated guide for each is not on this site yet. Naming them is not a link.
- The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. This page is the statute table of clocks those pages name.
Comparison table — statutory clocks, not an average
Work this table with counsel. Each row is a legal requirement only if that instrument applies to YOUR facts. Times are not averaged and not rounded. Last verified 7 September 2026. Not legal advice.
| Regime | Deadline (statutory words) | Clock starts | Recipient class | Source | Last verified |
|---|---|---|---|---|---|
| GDPR Article 33 — legal requirement only if GDPR applies. A dedicated GDPR jurisdiction guide is not on this site yet. | Without undue delay and, where feasible, not later than 72 hours after having become aware of the personal data breach. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay. Article 33(4) allows information in phases. Article 34 communication to the data subject (high risk) is without undue delay — this page does not convert that phrase into 72 hours. | Awareness. Article 33(1): after having become aware. EDPB Guidelines 9/2022 (regulator guidance, version 2.0, 4 April 2023) treat awareness as a reasonable degree of certainty that a security incident has compromised personal data — not the close of the investigation. | The supervisory authority competent in accordance with Article 55. The processor notifies the controller without undue delay after becoming aware (Article 33(2)) — a different duty from the controller's 72-hour authority notice. | Regulation (EU) 2016/679 Article 33(1)–(2). EDPB Guidelines 9/2022 are regulator guidance, not the regulation. | 7 September 2026 |
| NIS2 Article 23 — early warning. Legal requirement only if NIS2 as transposed applies. A dedicated NIS2 jurisdiction guide is not on this site yet. | Without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning. | Awareness of the significant incident. Article 23(4)(a). 'Significant' is Article 23(3) — this page does not apply that test. | The CSIRT or, where applicable, the competent authority. Recipients of the entity's services are notified where appropriate (Article 23(1)–(2)). | Directive (EU) 2022/2555 Article 23(4)(a). | 7 September 2026 |
| NIS2 Article 23 — incident notification. Legal requirement only if NIS2 as transposed applies. | Without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, updating the early warning and including an initial assessment and indicators of compromise where available. | Awareness of the significant incident. Article 23(4)(b). Same start event as the 24-hour early warning — not a second, later start. The 24-hour band and the 72-hour band are not averaged into one number. | The CSIRT or, where applicable, the competent authority. | Directive (EU) 2022/2555 Article 23(4)(b). | 7 September 2026 |
| NIS2 Article 23 — final report. Legal requirement only if NIS2 as transposed applies. | Not later than one month after the submission of the incident notification, a final report. If the incident is still ongoing at that mark, a progress report then, and a final report within one month of handling the incident. | The one-month mark runs from the incident notification (Article 23(4)(d)), not from becoming aware. This page does not convert 'one month' into a number of hours. | The CSIRT or, where applicable, the competent authority. | Directive (EU) 2022/2555 Article 23(4)(c)–(d). | 7 September 2026 |
| DORA Article 19 — initial notification. Legal requirement only if DORA applies. A dedicated DORA jurisdiction guide is not on this site yet. | As early as possible, but in any case within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident. If classification as major happens after those 24 hours, the initial notification is within four hours from that later classification (Delegated Regulation (EU) 2025/301 Article 5(2)). | Two named events, not one: classification as major (four hours) and awareness of the ICT-related incident (24-hour cap). Classification is Article 18 plus Delegated Regulation (EU) 2024/1772. Not NIS2 'becoming aware of the significant incident'. Do not paste NIS2's 24-hour / 72-hour ladder onto DORA. | The relevant competent authority (Article 19(1)). | Regulation (EU) 2022/2554 Article 19(4)(a); Commission Delegated Regulation (EU) 2025/301 Article 5(1)(a) and 5(2). Templates: Commission Implementing Regulation (EU) 2025/302. | 7 September 2026 |
| DORA Article 19 — intermediate report. Legal requirement only if DORA applies. | At the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed. An updated intermediate report without undue delay, and in any case when regular activities have been recovered. | Submission of the initial notification — not awareness, and not classification. Article 19(4)(b); Delegated Regulation (EU) 2025/301 Article 5(1)(b). | The relevant competent authority. | Regulation (EU) 2022/2554 Article 19(4)(b); Commission Delegated Regulation (EU) 2025/301 Article 5(1)(b). | 7 September 2026 |
| DORA Article 19 — final report. Legal requirement only if DORA applies. | No later than one month after either the submission of the intermediate report or, where applicable, after the latest updated intermediate report. | Submission of the intermediate report (or the latest updated intermediate report) — not awareness. This page does not convert 'one month' into a number of hours. The initial, intermediate, and final marks are not collapsed into one DORA number. | The relevant competent authority. | Regulation (EU) 2022/2554 Article 19(4)(c); Commission Delegated Regulation (EU) 2025/301 Article 5(1)(c). | 7 September 2026 |
| CRA Article 14 — 24-hour early warning (actively exploited vulnerability). Legal requirement only if CRA applies; Article 14 applies from 11 September 2026. A dedicated CRA jurisdiction guide is not on this site yet. A dedicated CRA Article 14 feature page is not on this site yet. | Without undue delay and in any event within 24 hours of the manufacturer becoming aware of the actively exploited vulnerability, an early warning notification. | Awareness. Article 14(2)(a): the manufacturer becoming aware of it. The signed-in CRA ladder, if you use it, tracks recorded awareness — it does not decide that you have become aware, and it does not start this clock. | The CSIRT designated as coordinator and ENISA, via the Single Reporting Platform (Articles 14(1), 14(7), 16). | Regulation (EU) 2024/2847 Article 14(2)(a). | 7 September 2026 |
| CRA Article 14 — 72-hour vulnerability notification (actively exploited vulnerability). Legal requirement only if CRA applies. | Without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, a vulnerability notification (unless the relevant information has already been provided). | Awareness. Article 14(2)(b): the manufacturer becoming aware of the actively exploited vulnerability. Same start event as the 24-hour early warning — not a later start. The 24-hour band and the 72-hour band are not averaged, and 72 hours is not three days. | The CSIRT designated as coordinator and ENISA, via the Single Reporting Platform. | Regulation (EU) 2024/2847 Article 14(2)(b). | 7 September 2026 |
| CRA Article 14 — 14-day final report (actively exploited vulnerability). Legal requirement only if CRA applies. | A final report, no later than 14 days after a corrective or mitigating measure is available (unless the relevant information has already been provided). | Measure availability — not awareness. Article 14(2)(c). The 14-day mark is not the 24-hour mark and not the 72-hour mark. The product's 14-day tracker runs from recorded measure availability for findings the organization classified as CRA-in-scope; it does not start this clock. | The CSIRT designated as coordinator and ENISA, via the Single Reporting Platform. | Regulation (EU) 2024/2847 Article 14(2)(c). | 7 September 2026 |
| CRA Article 14 — severe incident having an impact on the security of the product. Legal requirement only if CRA applies. | Early warning within 24 hours of becoming aware (Article 14(4)(a)); incident notification within 72 hours of becoming aware (Article 14(4)(b)); final report within one month after the submission of the incident notification (Article 14(4)(c)). The one-month final-report mark is not the 14-day mark on the actively exploited track. Those two final-report marks are not averaged. | Awareness for the 24-hour and 72-hour stages (the manufacturer becoming aware of the severe incident). The one-month final report runs from the incident notification under Article 14(4)(b), not from awareness. 'Severe' is qualitative in Article 14(5). | The CSIRT designated as coordinator and ENISA, via the Single Reporting Platform. Impacted users are informed without undue delay (Article 14(8)) — this page does not convert that phrase into an hour count. | Regulation (EU) 2024/2847 Article 14(3)–(5) and 14(8). | 7 September 2026 |
| SEC Form 8-K Item 1.05 — legal requirement only if you are a registrant and the incident is determined material. A dedicated SEC cyber-disclosure guide is not on this site yet. | File a Form 8-K within four business days after the registrant determines that it has experienced a material cybersecurity incident. Four business days — not four calendar days, and not 72 hours. | Determination. Four business days run from the materiality determination, not from discovery and not from awareness as GDPR uses that word. Instruction 1 to Item 1.05: the materiality determination must be made without unreasonable delay after discovery of the incident. 'Without unreasonable delay' is not converted here into a number of hours. | The U.S. Securities and Exchange Commission, on Form 8-K. Definitions of cybersecurity incident and related terms sit in 17 CFR 229.106 (Item 106 of Regulation S-K). | Form 8-K Item 1.05; 17 CFR 249.308; 17 CFR 229.106. | 7 September 2026 |
| HIPAA 45 CFR §164.404 — legal requirement only if HIPAA applies. A dedicated HIPAA jurisdiction guide is not on this site yet. | Without unreasonable delay and in no case later than 60 calendar days after discovery of a breach, except as provided in §164.412 (law-enforcement delay). 60 calendar days — not 72 hours, and not four business days. | Discovery. A breach is treated as discovered on the first day it is known to the covered entity, or by exercising reasonable diligence would have been known (§164.404(a)(2)). Constructive knowledge is in that sentence — this page does not find it on YOUR facts. | Each individual whose unsecured protected health information has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach. Media notice if more than 500 residents of a State or jurisdiction (§164.406). Secretary notice contemporaneous with individual notice if 500 or more individuals (§164.408(b)); annual log if fewer than 500 (§164.408(c)). Those are different recipients and different marks — not averaged. | 45 CFR §164.404(a)–(b); see also §§164.406, 164.408, 164.412. | 7 September 2026 |
| Cal. Civ. Code §1798.82 — legal requirement only if it applies. A dedicated US-state-laws guide is not on this site yet. | As of 1 January 2026 (Stats. 2025, Ch. 319, SB 446), the disclosure shall be made within 30 calendar days of discovery or notification of the data breach, subject to delay to accommodate the legitimate needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. 30 calendar days is this statute's number — not a 50-state average, and not HIPAA's 60 calendar days. If more than 500 California residents are notified, a sample copy of the notice goes to the Attorney General within 15 calendar days of notifying those residents (§1798.82(f) as amended) — a different mark from the 30 calendar days to the resident. | Discovery or notification of the breach. §1798.82(a). Other US states use different start language and different times. This page does not invent a US-state typical deadline. | A California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person (or encrypted information plus the encryption key, with a reasonable belief the key could render it readable). The Attorney General is a separate recipient when the 500-resident threshold is met. | Cal. Civ. Code §1798.82(a)(2) and (f), official Legislative Counsel text including the 1 January 2026 amendment. | 7 September 2026 |
Clock-start: awareness, determination, discovery, and without undue delay
The statutes do not share a start event. This page does not find that event on YOUR facts, and it does not convert 'without undue delay' or 'without unreasonable delay' into a number of hours. A dedicated how-regulators-determine-knowledge guide is not on this site yet. Last verified 7 September 2026. Not legal advice.
| Start word | Where it appears | What this page does not do |
|---|---|---|
| Awareness / becoming aware | GDPR Article 33(1); NIS2 Article 23(4); CRA Article 14(2) and (4); DORA Delegated Regulation (EU) 2025/301 Article 5(1)(a) (the 24-hour cap from the moment the financial entity has become aware). EDPB Guidelines 9/2022 discuss GDPR awareness as a reasonable degree of certainty. | Does not decide that you have become aware. Does not start the 72 hours, the 24 hours, or the four hours. Does not treat a KEV match in a scanner as CRA awareness. |
| Determination | Form 8-K Item 1.05: four business days after the registrant determines that it has experienced a material cybersecurity incident. Instruction 1 still requires that determination without unreasonable delay after discovery. | Does not determine materiality. Does not start four business days from discovery. Does not convert 'without unreasonable delay' into a number of hours. |
| Discovery | HIPAA §164.404(a)(2) (known, or by reasonable diligence would have been known). Cal. Civ. Code §1798.82(a) (discovery or notification of the breach). | Does not decide that a breach of unsecured PHI, or a California-resident personal-information acquisition, has been discovered. Does not start the 60 calendar days or the 30 calendar days. |
| Classification as major | DORA Article 18 plus Delegated Regulation (EU) 2025/301 Article 5(1)(a): the four-hour initial-notification mark runs from classification as a major ICT-related incident, with a 24-hour-from-awareness cap. | Does not classify the incident as major. Does not start the four hours. Does not paste NIS2's 24-hour / 72-hour ladder onto DORA. |
| Without undue delay / without unreasonable delay | GDPR Article 33(1) ('without undue delay and, where feasible, not later than 72 hours'). NIS2 Article 23(4) (the same pairing with 24 hours and 72 hours). CRA Article 14(2) and (4) (the same pairing with 24 hours and 72 hours). HIPAA §164.404(b) ('without unreasonable delay and in no case later than 60 calendar days'). Instruction 1 to Item 1.05 ('without unreasonable delay after discovery'). Article 34 GDPR and CRA Article 14(8) use 'without undue delay' with no hour count attached. | Does not convert 'without undue delay' or 'without unreasonable delay' into a number of hours where the article does not give one. Where the article gives both a qualitative phrase and a numeric outer mark, both are quoted; they are not averaged. |
What fires first — how to read the table
This is a reading method, not a determination. Counsel decides which rows may apply. Among the rows that may apply, the earliest statutory outer mark is the one that fires first — not the one this page prefers, and not a blended typical. Last verified 7 September 2026. Not legal advice.
- Do not rank rows by how often they appear in headlines. A 24-hour CRA or NIS2 early warning can sit on the same facts as a 72-hour GDPR Article 33 notice and a four-business-day Item 1.05. Those are different clocks.
- Compare like with like. GDPR's 72 hours run from awareness. HIPAA's 60 calendar days run from discovery. Item 1.05's four business days run from determination. DORA's four hours run from classification as major. Putting those four numbers in one cell would be an average this page refuses to print.
- A later start can still fire first. Four business days from a determination made today can precede 60 calendar days from a discovery last week — or the reverse. UTC timestamps on the event the article names are how you compare, not a league table of the Deadline column.
- The product's CRA ladder is one tracker, for findings the organization classified as CRA-in-scope. It is not a GDPR clock, not a NIS2 clock, not a DORA clock, not an Item 1.05 clock, and not a HIPAA clock. It does not tell you which row fires first.
- A dedicated failure-to-report guide is not on this site yet. Missing a mark is a counsel question. This page does not start a clock by listing it.
Checklist
This is a question list, not a filing. The first-72-hours page on this site is the operational 72-hour plan. The who-to-call page on this site is the contact order. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. A dedicated document-your-decision, prepare-regulatory-report, and supporting-evidence guide is not on this site yet.
- List the regimes that may apply. The decision-tree page on this site is the walk. This table does not add a regime and does not drop one.
- For each regime on that list, write the clock-start the article names and the UTC time you currently believe that event occurred. This page does not find that event.
- Quote the statutory time in the article's words. Do not round 72 hours to three days. Do not average GDPR 72 hours with CRA 24 hours. Do not invent a US-state typical.
- Name the recipient class. Supervisory authority, CSIRT, competent authority, ENISA via the Single Reporting Platform, SEC, individuals, California residents, and the Attorney General are not interchangeable.
- Who is authorised to file, and who is not. A named human files. The product does not. This table does not file.
- Whether a no-notification decision still has to be documented (GDPR Article 33(5) is the example, only if GDPR applies).
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Statutory clock | The time limit the cited article or technical standard names. Not a product timer, and not an average of several articles. |
| Awareness | Clock-start language in GDPR Article 33, NIS2 Article 23(4), CRA Article 14, and the DORA 24-hour cap. Not the same event as SEC determination or HIPAA discovery. |
| Determination | Clock-start language in Form 8-K Item 1.05 (materiality). Instruction 1 still requires the determination without unreasonable delay after discovery. |
| Discovery | Clock-start language in HIPAA §164.404(a)(2) and Cal. Civ. Code §1798.82. HIPAA includes constructive knowledge (reasonable diligence). |
| Without undue delay | Qualitative timing language several articles pair with a numeric outer mark. This page quotes both and does not replace the phrase with a number the article does not give. |
| 72 hours | GDPR Article 33(1)'s outer mark from awareness, NIS2 Article 23(4)(b)'s incident-notification mark from awareness, CRA Article 14(2)(b) and 14(4)(b)'s notification mark from awareness, and DORA's intermediate-report mark from the initial notification. Those 72-hour marks are different clocks. None of them is three days. |
| 24 hours | NIS2 Article 23(4)(a) early warning from awareness; CRA Article 14(2)(a) and 14(4)(a) early warning from awareness; DORA's 24-hour-from-awareness cap on the initial notification. Those 24-hour marks are different clocks. None of them is GDPR's 72 hours. |
| Four business days | Form 8-K Item 1.05's outer mark from the materiality determination. Not four calendar days, and not 72 hours. |
Where this shows up in ShipReady Metrics
The signed-in app does not start these clocks, does not decide whether you must report, does not file with a regulator, and does not interpret YOUR facts. None of the surfaces below is 'this clock has started' or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a GDPR Article 33 clock, not a NIS2 Article 23 clock, not a DORA Article 19 clock, not a Form 8-K Item 1.05 clock, and not a HIPAA §164.404 clock. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.
The obligation map lists frameworks the organization has marked in-scope. That mark is not a legal opinion that a reporting duty applies, and it is not a list of reporting duties as legal conclusions. The cyber risk register lives under Security. None of those surfaces files a GDPR Article 33 notice, a NIS2 Article 23 notification, a DORA Article 19 report, a CRA Article 14 notification, a Form 8-K Item 1.05, a HIPAA §164.404 notice, or a California §1798.82 disclosure.
Primary sources (last verified 7 September 2026)
Every regulatory claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Article 33 is a legal requirement only when GDPR applies. EDPB Guidelines 9/2022 are regulator guidance. Directive (EU) 2022/2555 Article 23 is a legal requirement only as transposed and only if you are an in-scope essential or important entity. Regulation (EU) 2022/2554 Article 19 is a legal requirement only if DORA applies; the hours live in Commission Delegated Regulation (EU) 2025/301 Article 5, with templates in Commission Implementing Regulation (EU) 2025/302. Regulation (EU) 2024/2847 Article 14 is a legal requirement only if CRA applies and applies from 11 September 2026; ENISA's Single Reporting Platform materials describe the filing path. Form 8-K Item 1.05 and 17 CFR 229.106 are securities-law disclosure. HIPAA 45 CFR §164.404 is the US breach-notification rule for unsecured PHI. Cal. Civ. Code §1798.82 is a California statute, last checked in the official Legislative Counsel text, including the 1 January 2026 amendment. These are examples, not a complete world list. Not legal advice.
The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. A dedicated prepare-regulatory-report, supporting-evidence, document-your-decision, failure-to-report-consequences, how-regulators-determine-knowledge, GDPR, NIS2, DORA, CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree.
Frequently asked questions
Which cybersecurity reporting deadline fires first?
This table cannot tell you. Counsel decides which regimes may apply. Among those, compare the statutory outer marks from the start event each article names — do not average GDPR's 72 hours with CRA's 24 hours, and do not round 72 hours to three days. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a statute table distilled from GDPR Article 33, NIS2 Article 23, DORA Article 19 and Delegated Regulation (EU) 2025/301 Article 5, CRA Article 14, Form 8-K Item 1.05, HIPAA 45 CFR §164.404, and Cal. Civ. Code §1798.82. Whether any duty applies, and whether a clock has started, are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady start these clocks?
No. The signed-in app does not start these clocks, does not decide whether you must report, and does not file with a regulator. Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness and measure availability for findings the org classified as CRA-in-scope. That is one product tracker, not the GDPR, NIS2, DORA, SEC, or HIPAA clocks. The obligation map is frameworks marked in-scope, not a legal opinion.
Does this page start a reporting clock?
No. GDPR Article 33 runs from becoming aware; NIS2 Article 23(4) runs from becoming aware of a significant incident; CRA Article 14 runs from the manufacturer becoming aware; Form 8-K Item 1.05 runs from determination of materiality; HIPAA §164.404 runs from discovery. Reading a public page is none of those events. The signed-in CRA ladder tracks recorded awareness; it does not start a clock either.
Can one incident start more than one clock?
Yes. Personal-data notification, sector or incident reporting, listed-issuer disclosure, and product-vulnerability reporting are different duties with different recipients and different start events. Filing one never discharges the others. This page does not average those clocks. Counsel maps the set. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.