Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do regulators determine whether you knew about an incident?
Updated
Notification clocks start from the event the cited article names — awareness, determination, or discovery — not from a product timestamp. This page is not legal advice, does not start a clock, and does not find that you became aware.
Clock-start analysis, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 33(1) ('after having become aware') and Recital 87, EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023, published 4 April 2023 — regulator guidance on when a controller is regarded as 'aware', not the regulation), Form 8-K Item 1.05 and SEC Division of Corporation Finance C&DIs Section 104B (last staff update 24 June 2024) on the materiality determination and 'reasonably likely' impact, HIPAA 45 CFR §164.404(a)(2) (known, or by exercising reasonable diligence would have been known), and, where DORA applies, Commission Delegated Regulation (EU) 2025/301 Article 5 (four hours from classification as major and no later than 24 hours from the moment the financial entity has become aware) plus Commission Delegated Regulation (EU) 2024/1772 (classification criteria). This page is not legal advice, does not start a clock, and is not a substitute for counsel.
This is how clocks are described, not YOUR start time
Audience: a CISO, compliance lead, incident commander, or counsel trying to see when a notification clock is described as starting. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that any regime applies, that you became aware, or that you must file.
The cited articles do not share one start event. GDPR Article 33(1) runs from becoming aware. Form 8-K Item 1.05 runs from a materiality determination made without unreasonable delay after discovery. HIPAA §164.404 runs from discovery, including constructive knowledge. DORA's initial-notification mark runs from classification as major, with a 24-hour-from-awareness cap. Those words are not interchangeable. The reporting-deadlines page on this site is the statute table of those clocks. Last verified 7 September 2026. Not legal advice.
- Statute versus guidance: Article 33(1) is a legal requirement only if GDPR applies. EDPB Guidelines 9/2022 are regulator guidance on how 'aware' is understood; they are not the regulation. SEC C&DIs are staff interpretations of Item 1.05; they are not the Form. This page quotes which kind of text it is relying on.
- This page does not find that YOU became aware, does not start 72 hours, four business days, 60 calendar days, or four hours, and does not treat a scanner match as awareness.
- The signed-in CRA ladder tracks recorded awareness the organisation entered for findings it classified as CRA-in-scope. That timestamp is the product's clock input. It is not a regulator's finding of when you became aware, and it does not start a GDPR, SEC, or HIPAA clock.
- The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. Unpublished jurisdiction guides (CRA, UK GDPR, US-state, SEC, HIPAA) are named in prose only. A dedicated guide for each is not on this site yet. Naming them is not a link.
'Became aware' — what the cited texts say
Work this table with counsel. Each row is a legal requirement only if that instrument applies to YOUR facts. EDPB materials and SEC C&DIs are labelled as guidance or staff interpretation, not the article. Last verified 7 September 2026. Not legal advice.
| Regime | What the text says about awareness | Clock that attaches | Source | Last verified |
|---|---|---|---|---|
| GDPR Article 33(1) — legal requirement only if GDPR applies. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. | The controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Recital 87: it should be ascertained whether all appropriate technological protection and organisational measures have been implemented to establish immediately whether a personal data breach has taken place and to inform promptly the supervisory authority and the data subject. Article 33(1) itself does not say 'should have known' or 'reasonable diligence'. | 72 hours from becoming aware (and without undue delay). Article 33(4) allows information in phases. This page does not convert 'without undue delay' into a number of hours, and it does not round 72 hours to three days. | Regulation (EU) 2016/679 Article 33(1) and Recital 87. Legal requirement, only if GDPR applies. | 7 September 2026 |
| EDPB Guidelines 9/2022 — regulator guidance, not the regulation. | Paragraph 31: the EDPB considers that a controller should be regarded as having become 'aware' when that controller has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. Paragraph 34: after first being informed of a potential breach, the controller may undertake a short period of investigation; during that period the controller may not be regarded as being 'aware'. The initial investigation should begin as soon as possible and establish with a reasonable degree of certainty whether a breach has taken place; a more detailed investigation can then follow. Paragraph 36: in most cases those preliminary actions should be completed soon after the initial alert — it should take longer only in exceptional cases. Paragraph 37: the controller should have internal processes to detect and address a breach, and report it upwards. Version 2.0, adopted 28 March 2023. | The same Article 33(1) 72-hour mark the guidelines interpret. The guidelines do not invent a second clock. They are not a finding that YOU have a reasonable degree of certainty. | EDPB Guidelines 9/2022 on personal data breach notification under GDPR, Version 2.0 (paragraphs 31–38). Regulator guidance, not Article 33. | 7 September 2026 |
| SEC Form 8-K Item 1.05 — legal requirement only if you are a registrant and the incident is determined material. A dedicated SEC cyber-disclosure guide is not on this site yet. | The four-business-day mark runs from the registrant's determination that it has experienced a material cybersecurity incident — not from GDPR-style awareness. Instruction 1 to Item 1.05: the materiality determination must be made without unreasonable delay after discovery of the incident. 'Without unreasonable delay' is not converted here into a number of hours. The materiality test, as the adopting release and C&DI 104B.05 restate it, is whether there is a substantial likelihood that a reasonable shareholder would consider the incident important in making an investment decision, or whether it would have significantly altered the total mix of information made available — including whether the incident had a material impact or is reasonably likely to have a material impact. 'Reasonably likely' is the impact test, not a knowledge test. C&DIs 104B.05–104B.09 (staff last update 24 June 2024) address ransomware cessation, insurance reimbursement, payment size, and related incidents; they do not replace Instruction 1. | Four business days after the materiality determination. Not four calendar days, not 72 hours, and not from discovery. Discovery still matters because Instruction 1 forbids parking the determination. | Form 8-K Item 1.05 and Instruction 1; 17 CFR 229.106. Staff C&DIs Section 104B (Exchange Act Form 8-K, last update 24 June 2024) are staff interpretations, not the Form. Adopting release 33-11216 / 34-97989 (26 July 2023). | 7 September 2026 |
| DORA Article 19 plus Delegated Regulation (EU) 2025/301 Article 5 — legal requirement only if DORA applies. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. | Initial notification: as early as possible, but in any case within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident. If classification as major happens after those 24 hours, the initial notification is within four hours from that later classification (Article 5(2) of the RTS). Classification criteria sit in Delegated Regulation (EU) 2024/1772. Commission Implementing Regulation (EU) 2025/302 templates treat 'date and time of detection' as the date and time at which the financial entity has become aware. Two named events, not one: classification as major, and awareness of the ICT-related incident. | Four hours from classification as major, capped at 24 hours from awareness. The intermediate report runs from submission of the initial notification, not from awareness. Do not paste NIS2's 24-hour / 72-hour ladder onto DORA. | Regulation (EU) 2022/2554 Article 19(4)(a); Commission Delegated Regulation (EU) 2025/301 Article 5(1)(a) and 5(2); Commission Delegated Regulation (EU) 2024/1772; Commission Implementing Regulation (EU) 2025/302. | 7 September 2026 |
| HIPAA 45 CFR §164.404(a)(2) — legal requirement only if HIPAA applies. A dedicated HIPAA jurisdiction guide is not on this site yet. | A breach is treated as discovered by a covered entity as of the first day on which such breach is known to such covered entity, or, by exercising reasonable diligence, would have been known to such covered entity. Constructive knowledge is in that sentence of the rule — not inferred from Recital 87. This page does not find reasonable diligence on YOUR facts. | Without unreasonable delay and in no case later than 60 calendar days after discovery (§164.404(b)), except as provided in §164.412. 60 calendar days — not 72 hours, and not four business days. | 45 CFR §164.404(a)(2) and (b). | 7 September 2026 |
Actual knowledge, constructive knowledge, and reasonable degree of certainty
These are different kinds of text. Quote which kind you are relying on. This page is none of those, and it does not apply them to YOUR facts. Last verified 7 September 2026. Not legal advice.
| Phrase | Kind of text | Where it lives | What this page does not do |
|---|---|---|---|
| Became aware / having become aware | Legal requirement — only if the cited instrument applies | GDPR Article 33(1); NIS2 Article 23(4); CRA Article 14(2) and (4); DORA Delegated Regulation (EU) 2025/301 Article 5(1)(a) (the 24-hour cap). The article names the event; it does not define the minute. | Does not decide that you have become aware. Does not start the 72 hours, the 24 hours, or the four hours. |
| Reasonable degree of certainty | Regulator guidance, not the regulation | EDPB Guidelines 9/2022 paragraph 31: a controller should be regarded as having become 'aware' when it has a reasonable degree of certainty that a security incident has occurred that has led to personal data being compromised. Paragraph 34: a short investigation may mean the controller is not yet 'aware'. | Does not find that YOU have a reasonable degree of certainty. Does not convert the short investigation into a number of hours. Does not treat the close of a forensic exam as the only possible awareness minute. |
| Establish immediately whether a breach has taken place | Recital (GDPR Recital 87) plus regulator guidance (EDPB paragraphs 32 and 37) | Recital 87: appropriate technological protection and organisational measures to establish immediately whether a personal data breach has taken place. EDPB paragraph 37: internal processes to detect and address a breach, and report it upwards. Detection capability is how those measures are later described — not a second clock. | Does not audit YOUR monitoring. Does not treat a gap in logging as a finding that you were aware. Ties detection capability to later defensibility of the awareness stamp; it does not start the stamp. |
| Constructive knowledge (would have been known by reasonable diligence) | Legal requirement — only if HIPAA applies | 45 CFR §164.404(a)(2): known, or by exercising reasonable diligence would have been known. That constructive-knowledge clause is in the HIPAA rule. Article 33(1) does not contain the same sentence. | Does not paste HIPAA constructive knowledge onto GDPR Article 33(1). Does not find that YOU should have known. Does not start 60 calendar days. |
| Determination without unreasonable delay after discovery | Legal requirement — only if Item 1.05 applies | Instruction 1 to Form 8-K Item 1.05. The four business days run from determination, not from discovery; the determination itself may not be parked. 'Reasonably likely' material impact is the materiality test (adopting release; C&DI 104B.05), not a knowledge test. | Does not determine materiality. Does not start four business days from discovery. Does not convert 'without unreasonable delay' into a number of hours. |
| Recorded awareness (product timestamp) | Product input, not a legal finding | The signed-in CRA ladder's recorded-awareness field for findings the organisation classified as CRA-in-scope. A KEV match timestamp is disclosure, never that clock. | Does not start a GDPR, SEC, or HIPAA clock. Is not a regulator's finding of when you became aware. Without a recorded (past) awareness time the 24-hour and 72-hour CRA stages do not run — never a fabricated overdue. |
Fictional examples — labelled fictional, not a ruling
These facts are invented to show how the cited texts talk past each other. They are not YOUR facts, not a supervisory-authority decision, and not a finding that a clock started. Last verified 7 September 2026. Not legal advice.
| Label | Invented facts | What the cited texts say | What this page does not do |
|---|---|---|---|
| Fictional — delayed detection | A SIEM rule fires at 09:00 UTC on Monday. The alert sits in an unreviewed queue. A human opens it at 11:00 UTC on Thursday and confirms personal data on the host was accessed. | EDPB paragraph 34 (guidance): after first being informed of a potential breach, a short investigation may mean the controller is not yet 'aware'; the initial investigation should begin as soon as possible. Paragraph 36 (guidance): those preliminary actions should be completed soon after the initial alert, longer only in exceptional cases. Recital 87 talks about measures to establish immediately whether a breach has taken place. Article 33(1) still runs from becoming aware, not from the SIEM timestamp. HIPAA §164.404(a)(2), only if HIPAA applies, asks when the breach was known or would have been known by reasonable diligence. | Does not pick Monday 09:00 or Thursday 11:00 as YOUR awareness minute. Does not start 72 hours from the SIEM fire. Does not treat an unreviewed queue as a ruling. Not a ruling. |
| Fictional — ignored alert | An analyst closes a high-severity IDS alert as noise on Tuesday without checking whether the destination held personal data. On Friday a customer forwards a dump that includes those records. The same alert ID is in the ticket. | EDPB paragraph 37 (guidance): internal processes should detect and address a breach and report it upwards. Recital 87 is about measures, not a constructive-knowledge clause in Article 33(1). HIPAA §164.404(a)(2), only if HIPAA applies, is the rule that names 'would have been known' by reasonable diligence. Instruction 1 to Item 1.05, only if it applies, still requires the materiality determination without unreasonable delay after discovery — discovery is not the four-business-day start. | Does not find that you should have known on Tuesday. Does not paste HIPAA constructive knowledge onto GDPR. Does not start any clock from the closed ticket. Not a ruling. |
Checklist — what to timestamp
This is a question list, not a filing. Three different stamps get collapsed: the event the article names (awareness, determination, or discovery), the minute you decided to notify or not, and the minute someone typed into the product. Keep them separate. The reporting-deadlines page on this site is the statute table. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record.
- Awareness (UTC): the minute you currently believe the organisation became aware, in the article's words. Do not back-date it. Do not treat reading this page as becoming aware. This page does not find that minute.
- Determination (UTC): if Item 1.05 may apply, the minute of the materiality determination, separate from discovery. Instruction 1 still requires that determination without unreasonable delay after discovery.
- Discovery (UTC): if HIPAA or a discovery-start statute may apply, the minute it was known — and, only if that rule says so, whether reasonable diligence would have made it known earlier. Do not paste that test onto Article 33(1).
- Recorded-in-product (UTC): the CRA ladder's recorded awareness for findings classified CRA-in-scope. That is the product's timestamp. It is not a regulator's finding, and it does not start a GDPR, SEC, or HIPAA clock. A KEV match time is disclosure, never that clock.
- Decision (UTC): when the notify / no-notify decision was taken, and by whom in role terms. Separate from awareness. The document-your-decision page on this site is that field list.
- Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| Awareness / became aware | Clock-start language in GDPR Article 33(1), NIS2 Article 23(4), CRA Article 14, and the DORA 24-hour cap. Not the same event as SEC determination or HIPAA discovery. |
| Reasonable degree of certainty | EDPB Guidelines 9/2022 paragraph 31's description of when a controller is regarded as 'aware'. Regulator guidance, not Article 33(1). |
| Constructive knowledge | A 'would have been known' test. HIPAA §164.404(a)(2) names it (reasonable diligence). Article 33(1) does not use that sentence. |
| Actual knowledge | Teaching contrast with constructive knowledge: known, not merely knowable. Not a defined term in Article 33(1). |
| Determination | Clock-start language in Form 8-K Item 1.05 (materiality). Instruction 1 still requires the determination without unreasonable delay after discovery. |
| Reasonably likely material | The Item 1.05 impact test restated in the adopting release and C&DI 104B.05: material impact, or reasonably likely material impact, under the ordinary securities-law materiality standard. Not a knowledge test, and not GDPR awareness. |
| Discovery | Clock-start language in HIPAA §164.404(a)(2) and, separately, the event after which Instruction 1 requires the Item 1.05 determination without unreasonable delay. |
| Recorded awareness | The product timestamp the organisation entered on the CRA ladder (`awareAt`) for CRA-in-scope findings. Not a regulator's finding of when you became aware. |
Where this shows up in ShipReady Metrics
The signed-in app does not decide that you became aware, does not start a GDPR Article 33 clock, does not start a Form 8-K Item 1.05 clock, does not start a HIPAA §164.404 clock, does not start a DORA Article 19 clock, and does not file with a regulator. None of the surfaces below is 'you became aware' or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. The 24-hour / 72-hour clocks run from the organisation's recorded awareness — a human determination the platform must not backdate. A KEV match timestamp is disclosure, never that clock. Without a recorded (past) awareness time those stages do not run — never a fabricated overdue. It is not a regulator's finding of when you became aware. It does not start a GDPR, SEC, or HIPAA clock. A named human still submits.
Security findings is where ingested scanner rows land (Dependabot and other SCA, SAST / code scanning, secret scanning, DAST). Those rows can be detection evidence a later reader looks at. They are not awareness. The cyber risk register lives under Security. The obligation map lists frameworks the organization has marked in-scope; that mark is not a legal opinion that a reporting duty applies. The vulnerability-management glossary on this site is the practice definition — not a feature that starts a clock. None of those surfaces files a GDPR Article 33 notice, a Form 8-K Item 1.05, a HIPAA §164.404 notice, or a DORA Article 19 report.
Primary sources (last verified 7 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2016/679 Article 33(1) is a legal requirement only when GDPR applies: notify without undue delay and, where feasible, not later than 72 hours after having become aware. Recital 87 addresses measures to establish immediately whether a personal data breach has taken place. EDPB Guidelines 9/2022 on personal data breach notification under GDPR (Version 2.0, adopted 28 March 2023) are regulator guidance on the timing of awareness, including the 'reasonable degree of certainty' formulation in paragraph 31; they are not the regulation. Form 8-K Item 1.05 and Instruction 1, with definitions in 17 CFR 229.106, are securities-law disclosure; SEC Division of Corporation Finance C&DIs Section 104B (Exchange Act Form 8-K, last staff update 24 June 2024) and the 21 May 2024 staff statement on disclosure of cybersecurity incidents determined to be material are staff materials, not the Form. HIPAA 45 CFR §164.404(a)(2) is the US breach-notification discovery rule, including constructive knowledge. Commission Delegated Regulation (EU) 2025/301 Article 5 is the DORA RTS on incident-reporting time limits; Commission Delegated Regulation (EU) 2024/1772 is the classification RTS; Commission Implementing Regulation (EU) 2025/302 is the template ITS. These are examples, not a complete world list. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The failure-to-report-consequences page on this site is the maxima table. The do-I-have-to-report page on this site is the class map. The reporting-decision-tree page on this site is the branching tree. The who-to-notify page on this site is the recipient-class map. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. A dedicated CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.
Frequently asked questions
How do regulators determine whether you knew about an incident?
They look at the start event the cited article names. GDPR Article 33(1) runs from becoming aware; EDPB Guidelines 9/2022 (guidance) describe that as a reasonable degree of certainty that personal data have been compromised, not the close of the investigation. Form 8-K Item 1.05 runs from a materiality determination made without unreasonable delay after discovery. HIPAA §164.404(a)(2) includes constructive knowledge. This page does not find that event on your facts. Last verified 7 September 2026. Not legal advice.
Is this legal advice?
No. It is a clock-start analysis distilled from GDPR Article 33(1) and Recital 87, EDPB Guidelines 9/2022 (Version 2.0), Form 8-K Item 1.05 and SEC C&DIs Section 104B (last staff update 24 June 2024), HIPAA 45 CFR §164.404(a)(2), and DORA Delegated Regulation (EU) 2025/301 Article 5. Whether any duty applies, and whether a clock has started, are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady start my GDPR clock?
No. The signed-in app does not start a GDPR Article 33 clock, does not decide that you became aware, and does not file with a regulator. Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the org classified as CRA-in-scope. That timestamp is the product's input, not a regulator's finding of when you became aware, and it does not start GDPR, SEC, or HIPAA clocks.
When does the GDPR 72-hour breach notification clock start?
Article 33(1) says after having become aware of the personal data breach. EDPB Guidelines 9/2022 paragraph 31 (regulator guidance, not the article) treats awareness as a reasonable degree of certainty that a security incident has compromised personal data. A short investigation may come first (paragraph 34). This page does not find that you have become aware and does not start the 72 hours. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.