Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What happens if you fail to report a cybersecurity incident?
Updated
Failure to make a required notification can attract statutory maxima under GDPR Article 83, NIS2 Article 34, HIPAA 45 CFR 160.404, and SEC civil-penalty authority. Those maxima are not typical fines. This table is not legal advice, does not start a clock, and does not compute YOUR penalty.
Maxima table, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 83, Directive (EU) 2022/2555 Article 34, Regulation (EU) 2022/2554 Article 50, HIPAA 45 CFR §160.404 and 45 CFR part 102, Form 8-K Item 1.05, 15 U.S.C. 78u(d)(3), and 17 CFR 201.1001. It is not legal advice, not a fine calculator, and not a substitute for counsel.
This is a maxima table, not YOUR fine
Audience: a founder, CISO, incident commander, or counsel weighing exposure from delay or silence. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the regime applies, that a notification was required, or that a fine will be imposed. A maximum is not a typical outcome.
A statutory maximum is a ceiling the cited article names. Supervisory authorities, Member States, HHS, and the SEC decide amounts on the facts, using the factors the article lists. This page does not average those maxima, does not invent a typical fine, and does not compute YOUR penalty. Last verified 7 September 2026. Not legal advice.
- Quote the article's words. GDPR Article 83 has two tiers — up to 10 000 000 EUR or 2 % of turnover, and up to 20 000 000 EUR or 4 % of turnover, whichever is higher. Those two tiers are not averaged into one GDPR number.
- Notification infringements under GDPR Articles 33 and 34 sit in Article 83(4)(a) (Articles 25 to 39) — the 10 000 000 EUR / 2 % tier — not automatically in the 20 000 000 EUR / 4 % tier. Article 83(5) is a different list. This page does not collapse them.
- NIS2 Article 34 says 'a maximum of at least' a figure. That is a floor on the Member State maximum, not a Union cap, and not a typical fine.
- DORA Article 50 does not name a euro maximum. This page does not invent one.
- The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. Unpublished guides (DORA, CRA, SEC cyber-disclosure, HIPAA, US-state-laws) are named in prose only. A dedicated guide for each is not on this site yet. Naming them is not a link.
Penalty table — statutory maxima, not a typical fine
Work this table with counsel. Each row is a legal requirement only if that instrument applies to YOUR facts. Maxima are not typical fines and are not averaged. Last verified 7 September 2026. Not legal advice.
| Regime | Statutory maximum (cite the article) | Clock it attaches to | Last verified |
|---|---|---|---|
| GDPR Article 83 — legal requirement only if GDPR applies. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. | Two tiers, not one number. Article 83(4): administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher — including the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43. Articles 33 and 34 sit in that 25-to-39 list. Article 83(5): up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher — basic principles (Articles 5, 6, 7 and 9), data-subject rights (Articles 12 to 22), transfers (Articles 44 to 49), Chapter IX, and non-compliance with an order. Article 83(2)(h) is a factor, not a third tier: the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement. Article 83(1): effective, proportionate and dissuasive. This page does not pick a tier for YOUR facts and does not treat either ceiling as a typical fine. | The Article 33 clock, only if GDPR applies: without undue delay and, where feasible, not later than 72 hours after having become aware of the personal data breach. Article 34 communication to the data subject (high risk) is without undue delay — this page does not convert that phrase into 72 hours. Article 83 is the fine article; it does not start a second clock. The reporting-deadlines page on this site is the statute table of clocks. | 7 September 2026 |
| NIS2 Article 34 — essential entities. Legal requirement only if NIS2 as transposed applies. The NIS2 incident-reporting guide on this site. | Article 34(4): Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher. 'A maximum of at least' is a floor on the Member State maximum, not a Union cap. Transposition can set a higher ceiling. Article 34(1): effective, proportionate and dissuasive. This page does not invent a typical NIS2 fine. | The Article 23 reporting clock, only if NIS2 as transposed applies: early warning within 24 hours of becoming aware of the significant incident; incident notification within 72 hours of becoming aware. Article 34 is the penalty article for infringing Article 21 or 23; it does not start a second clock. | 7 September 2026 |
| NIS2 Article 34 — important entities. Legal requirement only if NIS2 as transposed applies. | Article 34(5): Member States shall ensure that where they infringe Article 21 or 23, important entities are subject to administrative fines of a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher. That 1,4 % figure is not 2 %, and not GDPR's 2 % or 4 %. Essential-entity and important-entity ceilings are not averaged. 'A maximum of at least' remains a floor on the Member State maximum. | The same Article 23 clock as the essential-entity row — awareness of the significant incident — only if the entity is important under the transposition. This page does not classify YOUR entity. | 7 September 2026 |
| DORA Article 50 — legal requirement only if DORA applies. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. | Article 50 does not name a euro maximum. Article 50(3): without prejudice to the right of Member States to impose criminal penalties in accordance with Article 52, Member States shall lay down rules establishing appropriate administrative penalties and remedial measures for breaches of this Regulation and shall ensure their effective implementation. Those penalties and measures shall be effective, proportionate and dissuasive. Article 50(4) lists powers that include adopting any type of measure, including of pecuniary nature, and issuing public notices. This page does not invent a DORA euro cap and does not invent a typical DORA fine. | The Article 19 reporting clock, only if DORA applies: initial notification within four hours from classification as a major ICT-related incident and no later than 24 hours from awareness (Delegated Regulation (EU) 2025/301 Article 5). Article 50 is the sanctions article; it does not start a second clock. | 7 September 2026 |
| HIPAA 45 CFR §160.404 — legal requirement only if HIPAA applies. A dedicated HIPAA jurisdiction guide is not on this site yet. | Four tiers for violations on or after 18 February 2009 (§160.404(b)(2)). Did not know and, by exercising reasonable diligence, would not have known: not less than $100 or more than $50,000 for each violation; not in excess of $1,500,000 for identical violations during a calendar year. Reasonable cause and not to willful neglect: not less than $1,000 or more than $50,000; same $1,500,000 calendar-year cap. Willful neglect corrected during the 30-day period beginning on the first date the covered entity or business associate knew, or by reasonable diligence would have known: not less than $10,000 or more than $50,000; same cap. Willful neglect not corrected during that 30-day period: not less than $50,000; same cap. §160.404(a) states these amounts were adjusted under the Federal Civil Monetary Penalty Inflation Adjustment Act and appear at 45 CFR part 102, updated annually. 2025 maximum adjusted amounts fetched from 45 CFR 102.3 (eCFR as of 3 September 2026): did-not-know and reasonable-cause maxima $73,011 per violation and $2,190,294 calendar-year cap; willful-neglect-corrected minimum $14,602 and maximum $73,011. Those 102 figures are inflation adjustments of the 160.404 numbers, not a typical fine. This page does not pick a tier for YOUR facts. | The 45 CFR §164.404 clock, only if HIPAA applies: without unreasonable delay and in no case later than 60 calendar days after discovery of a breach. §160.404 is the civil-money-penalty amount article; it does not start a second clock. | 7 September 2026 |
| SEC Exchange Act civil-penalty authority — legal requirement only if you are a registrant and the cited provision applies. A dedicated SEC cyber-disclosure guide is not on this site yet. | There is no cyber-specific 'failure to report' tariff in Item 1.05. The Commission may seek civil monetary penalties under Exchange Act Section 21(d)(3), 15 U.S.C. 78u(d)(3). 17 CFR 201.1001 requires annual inflation adjustment; current amounts are published at the SEC civil-penalties inflation-adjustments page. As of 15 January 2025 (Release Nos. 33-11350, 34-102134; effective 15 January 2025, for penalties imposed after that date for violations after 2 November 2015): for any other person, $118,225; for any other person / fraud, $591,127; for any other person / fraud / substantial losses or risk of losses to others or gain to self, $1,182,251. Those are Exchange Act civil-penalty maxima, not a typical fine, and not a cyber-only schedule. This page does not pick a tier for YOUR facts. | Form 8-K Item 1.05, only if you are a registrant and the incident is determined material: file within four business days after the registrant determines that it has experienced a material cybersecurity incident. Four business days run from determination, not from discovery. Instruction 1 still requires that determination without unreasonable delay after discovery. Section 21(d)(3) is the penalty authority; it does not start a second clock. | 7 September 2026 |
Legal consequence versus reputational, contractual, and disclosure fallout
The rows above are legal consequences: administrative fines, civil money penalties, and SEC civil-penalty authority named in the cited articles. The items below are not those articles. Labelling them separately is the point. Last verified 7 September 2026. Not legal advice.
| Kind | What this page means | Do not treat as |
|---|---|---|
| Legal consequence — administrative fine or civil money penalty | GDPR Article 83, NIS2 Article 34, HIPAA §160.404, and SEC Section 21(d)(3) as quoted above. GDPR Article 82 is a separate legal consequence: the right to compensation for material or non-material damage. Article 84 lets Member States lay down other penalties. NIS2 Article 36 is a residual penalties clause. DORA Article 52 is criminal penalties where Member State law provides them. | Not a typical fine. Not a product calculation. Not reputational fallout. |
| Legal consequence — individual claims | GDPR Article 82 compensation; HIPAA individual actions where a statute provides them; US-state private rights where a statute provides them. A dedicated US-state-laws guide is not on this site yet. This page does not find that YOU face a claim. | Not Article 83. Not a class-action forecast. Not a typical damages figure — this page does not invent one. |
| Contractual fallout — not a statute | Customer, processor, or insurer contracts often require notice on a clock the contract names. Missing that mark can be a contractual breach. PCI DSS v4.0.1 is a payment-card industry standard, not a statute. YOUR policy is YOUR policy. This page does not interpret it. | Not GDPR Article 83. Not NIS2 Article 34. Do not collapse a contract clause into 'the law'. |
| Reputational fallout — not a statute | Press, customer confidence, hiring, and partner diligence can move after a missed or delayed notice. Those are not statutory maxima. This page does not measure them and does not invent a typical reputational cost. | Not a fine. Not a legal conclusion. Not a statistic. |
| Disclosure fallout — not a second fine schedule | A listed registrant that files Item 1.05 late, or that the Commission later alleges omitted a material cybersecurity incident, faces Exchange Act disclosure consequences under the authority quoted above — plus whatever the market does with the filing. Market reaction is not Section 21(d)(3). | Not a typical share-price move. This page does not invent one. |
Verified enforcement examples
This page does not cite an enforcement example we have not fetched as the original decision or official press, with date, authority, and official URL. Headlines are not a source. A maximum is not a typical outcome. Last verified 7 September 2026. Not legal advice.
Checklist
This is a question list, not a fine. The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The document-your-decision page on this site is the decision record.
- List the regimes that may apply. The decision-tree page on this site is the walk. This table does not add a regime and does not drop one.
- For each regime on that list, quote the statutory maximum in the article's words. Do not treat the ceiling as typical. Do not average GDPR's two Article 83 tiers. Do not average NIS2 essential and important figures.
- Name the clock the penalty attaches to. Article 83 is not a second GDPR clock. Article 34 is not a second NIS2 clock. §160.404 is not a second HIPAA clock.
- Label legal consequence versus reputational, contractual, and disclosure fallout. Do not collapse a contract clause or a headline into the statute.
- Whether a no-notification decision still has to be documented (GDPR Article 33(5) is the example, only if GDPR applies). The document-your-decision page on this site is the decision record.
- Who is authorised to file, and who is not. A named human files. The product does not. This table does not file and does not compute a penalty.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Statutory maximum | The ceiling the cited article names. Not a typical fine, not an average of several articles, and not a product output. |
| Typical fine | A figure this page refuses to print. A maximum is not a typical outcome. |
| Article 83(4) | GDPR's up-to-10-000-000-EUR or 2 % tier, whichever is higher. Articles 33 and 34 sit here via 'Articles 25 to 39'. |
| Article 83(5) | GDPR's up-to-20-000-000-EUR or 4 % tier, whichever is higher. Principles, rights, transfers, Chapter IX, orders. Not the automatic home of a missed Article 33 notice. |
| A maximum of at least | NIS2 Article 34 language. A floor on the Member State maximum, not a Union cap, and not a typical fine. |
| Civil money penalty | HIPAA §160.404 amount of a civil money penalty. Inflation-adjusted at 45 CFR part 102. Not GDPR Article 83. |
| Legal consequence | A result the cited statute or regulation names: administrative fine, civil money penalty, compensation article, criminal-penalty reservation. Not reputational fallout. |
| Reputational / contractual / disclosure fallout | Consequences this page labels as not statute: press, contract notice clauses, market reaction to a filing. Not a second fine schedule. |
Where this shows up in ShipReady Metrics
The signed-in app does not compute fines, does not compute penalties, does not start these clocks, does not decide whether you must report, and does not file with a regulator. None of the surfaces below is a penalty calculator, 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a GDPR Article 83 calculation, not a NIS2 Article 34 calculation, not a DORA Article 50 calculation, not a HIPAA §160.404 calculation, and not an Exchange Act Section 21(d)(3) calculation. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still submits.
The obligation map lists frameworks the organization has marked in-scope. That mark is not a legal opinion that a reporting duty applies, not a list of penalty-bearing regimes as legal conclusions, and not a fine. The cyber risk register lives under Security. None of those surfaces computes a GDPR Article 83 fine, a NIS2 Article 34 fine, a DORA Article 50 penalty, a HIPAA §160.404 civil money penalty, or an SEC civil penalty.
Primary sources (last verified 7 September 2026)
Every regulatory claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Article 83 is a legal requirement only when GDPR applies; Articles 33 and 34 sit in the Article 83(4)(a) list (Articles 25 to 39). Directive (EU) 2022/2555 Article 34 is a legal requirement only as transposed and only if you are an in-scope essential or important entity; the 'maximum of at least' figures attach to infringements of Article 21 or 23. Regulation (EU) 2022/2554 Article 50 is a legal requirement only if DORA applies; it does not name a euro maximum. HIPAA 45 CFR §160.404 is the US civil-money-penalty amount rule; 45 CFR part 102 updates those dollar figures annually (eCFR Title 45 last amended 31 August 2026; displayed as of 3 September 2026). Form 8-K Item 1.05 and 17 CFR 229.106 are securities-law disclosure. Exchange Act Section 21(d)(3), 15 U.S.C. 78u(d)(3), and 17 CFR 201.1001 are the civil-penalty authority and inflation-adjustment rule; current amounts as of 15 January 2025 are on the SEC civil-penalties inflation-adjustments page. These are examples, not a complete world list. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The supporting-evidence page on this site is the evidentiary record. The document-your-decision page on this site is the decision record. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. A dedicated CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.
Frequently asked questions
What happens if you fail to report a cybersecurity incident?
If a required notification was due and was missed, the cited regimes name statutory maxima — GDPR Article 83 two tiers, NIS2 Article 34, HIPAA 45 CFR §160.404, SEC Exchange Act civil-penalty authority — not typical fines. Counsel maps which rows may apply. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a maxima table distilled from GDPR Article 83, NIS2 Article 34, DORA Article 50, HIPAA 45 CFR §160.404 and 45 CFR part 102, Form 8-K Item 1.05, and Exchange Act Section 21(d)(3). Whether any duty applies, whether a clock has started, and what amount if any will be imposed are legal questions for counsel on your facts. This page does not start a reporting clock.
Is the maximum the typical fine?
No. A statutory maximum is a ceiling the article names. Article 83(1) and NIS2 Article 34(1) require fines to be effective, proportionate and dissuasive; HIPAA §160.404 and SEC Section 21(d)(3) are tiered authorities, not a typical. This page does not invent a typical fine and does not average the ceilings.
Does ShipReady compute these penalties?
No. The signed-in app does not compute fines or penalties, does not start these clocks, and does not file with a regulator. Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the org classified as CRA-in-scope. That is one product tracker, not a penalty calculator. The obligation map is frameworks marked in-scope, not a legal opinion.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.