Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What evidence should support a regulatory filing?

Updated

The filing is the notice. The evidence is the record that can show how you knew, what you scoped, what you assessed, and what you fixed. GDPR Art. 33(5) documents facts, effects, and remedial action. A forensic chain of custody is a different job. Not legal advice.

Operational guidance, last verified 7 September 2026 against Regulation (EU) 2016/679 Article 5(2) (accountability) and Article 33(5) (documentation of any personal data breach: facts, effects, remedial action), EDPB Guidelines 9/2022 on personal data breach notification (regulator guidance on documenting breaches), ENISA recommendations on assessing the severity of personal data breaches (agency guidance, not the regulation), NIST SP 800-61 Revision 3 (April 2025, current final; Revision 2 is superseded), NIST SP 800-86 (forensic techniques and chain of custody — guidance, not a statute), and, where DORA applies, Regulation (EU) 2022/2554 Article 17 plus Commission Delegated Regulation (EU) 2024/1774 Article 22 (retain ICT-incident evidence securely, no longer than necessary). This page is not legal advice, not a filing pack, does not start a clock, and is not a substitute for counsel or a retained DFIR firm.

Accountability record versus forensic exhibit — different jobs

Audience: a compliance lead, CISO, incident commander, or counsel assembling what sits behind a filing so a later follow-up can be answered. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Keeping a log is not a determination that any regime applies, that a clock has started, or that you must file.

Two jobs get mixed. The first is an accountability record: can you demonstrate what you knew, what you decided, and what you did. GDPR Article 5(2) says the controller shall be responsible for, and be able to demonstrate compliance with, the principles in Article 5(1) ('accountability'). GDPR Article 33(5) says the controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken, and that documentation shall enable the supervisory authority to verify compliance with Article 33. Article 33(5) is a documentation duty. It is not a list of forensic exhibits you must attach to the notice. Last verified 7 September 2026. Not legal advice.

The second job is a forensic exhibit: can another examiner reconstruct the bits and the handling. NIST SP 800-86 is the Guide to Integrating Forensic Techniques into Incident Response — guidance, not a statute. It is the document this cluster cites for collection that preserves integrity, working copies, hashes, and chain of custody. The chain-of-custody page on this site is that handling record. The preserve-evidence page on this site is the capture list. Those are not Article 33(5). Collapsing a memory image into 'the filing pack' is how a documentation duty gets mistaken for a crime-lab brief. Not legal advice.

  • Accountability record (legal requirement only if GDPR applies): Article 5(2) demonstrate compliance; Article 33(5) document any personal data breach — facts, effects, remedial action — so the supervisory authority can verify Article 33. EDPB Guidelines 9/2022 are regulator guidance on how that documentation is understood; they are not the regulation.
  • Forensic exhibit (guidance / best practice, not Article 33(5)): NIST SP 800-86 working copy, hashes, and chain of custody. RFC 3227 order of volatility is IETF BCP 55, a Best Current Practice, not a statute. The preserve-evidence page on this site is that list.
  • NIST SP 800-61 Revision 3 (April 2025) is the current final Incident Response Recommendations and Considerations for Cybersecurity Risk Management: a CSF 2.0 Community Profile. It supersedes NIST SP 800-61 Revision 2 (August 2012), Computer Security Incident Handling Guide. Cite r3 as current. Cite r2 as superseded. Neither revision is a filing-attachment statute.
  • Where DORA applies, Regulation (EU) 2022/2554 Article 17(2) requires financial entities to record all ICT-related incidents and significant cyber threats. Commission Delegated Regulation (EU) 2024/1774 Article 22(d) requires them to retain all evidence relating to ICT-related incidents for a period no longer than necessary, commensurate with criticality, in a secure manner. That is the RTS, and only if DORA applies. It is not GDPR Article 33(5), and it is not a chain of custody form.
  • This page does not invent a universal evidence binder. Article 33(5) does not name logs, hashes, or a chain of custody as required attachments. Those items are how facts, effects, and remedial action can later be shown. Not legal advice.

Evidence checklist — what sits behind the filing

Work this table with counsel. Each row is a class of record, not a required attachment and not YOUR pack. The legal-requirement column is a legal requirement only if the cited instrument applies to YOUR facts. EDPB and ENISA materials are regulator or agency guidance. NIST SP 800-86 and RFC 3227 are guidance / best practice. This page is none of those. Last verified 7 September 2026. Not legal advice.

Evidence behind a filing (not a required attachment list; not a binder this product ships; not legal advice)
ItemWhy it mattersLegal requirement vs guidance vs best practiceDo not alter
LogsAuth, cloud trail, endpoint, network, and application logs reconstruct what happened and when. They are often the facts Article 33(5) later has to recite. Off-box is not immortal: rotation still drops the window.Legal requirement (only if GDPR applies): Article 33(5) documents facts; logs are how those facts are often shown, not a named attachment in the article. Legal requirement (only if DORA applies): RTS (EU) 2024/1774 Article 22(d) retain ICT-incident evidence securely, no longer than necessary. Best practice: freeze or export before retention rotates; the preserve-evidence page on this site is the capture list (NIST SP 800-86 / RFC 3227 — guidance, not a statute).Do not rotate, tidy, or delete the window to 'clean the report'. Do not disable logging to hide noise. Isolate the source; export or hold it. The never-delete-after-breach page on this site is the anti-list.
Awareness and containment timelineWhen the organisation became aware, what was contained, and in what order. Clocks in the cited articles run from awareness or a named determination, not from this page. A UTC log is how a later reader sees sequence.Legal requirement (only if GDPR applies): Article 33(1) runs from becoming aware; Article 33(5) documents facts and remedial action, which include when you knew and what you did. EDPB Guidelines 9/2022 are regulator guidance on 'aware' and on documenting the breach as it develops — guidance, not the article. Best practice: one UTC commander log, not a Slack reconstruction after the fact.Do not back-date awareness. Do not 'clean up' the ticket thread. Do not collapse containment into eradication. List unknowns as unknowns. The reporting-deadlines page on this site is the statute table of clocks; this page does not start one.
Scope determinationWhat systems, data, and people are in, what is out, and what is not yet known. Categories and approximate numbers, where an article asks for them, come from this work. A guess is not scope.Legal requirement (only if GDPR applies): Article 33(3)(a) includes, where possible, categories and approximate numbers of data subjects and of personal data records. 'Where possible' is in the article. Article 33(4) permits information in phases when it cannot all be provided at once. Guidance: EDPB Guidelines 9/2022 on phased notification. This page does not invent a headcount.Do not fill a gap with a round number. Do not treat 'where possible' as a licence to omit the nature of the breach. Do not paste a GDPR headcount onto a CRA Article 14 draft. The prepare-regulatory-report page on this site is the field checklist.
Risk assessmentWhether the facts are likely to result in a risk (or a high risk) to rights and freedoms, and the reasons. The notify / do-not-notify decision sits on this assessment. The document-your-decision page on this site is the decision record.Legal requirement (only if GDPR applies): Article 33(1) unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; Article 34 is the separate high-risk communication to data subjects. Article 5(2) accountability is the duty to be able to demonstrate that assessment. Guidance: EDPB Guidelines 9/2022 on risk and high risk; ENISA recommendations on assessing the severity of personal data breaches (agency methodology, 2013 — not the regulation). This page does not run YOUR risk test.Do not write the conclusion first and the factors after. Do not treat ENISA's severity methodology as a statute. Do not convert Article 33(1) 'risk' into Article 34 'high risk' without saying so. Keep the reasons, not only the verdict.
Forensic findingsWhat a trained examination showed: how access happened, what was taken or viewed, what remains unknown. Findings support the facts and effects in Article 33(5). The image and the chain that produced them are the forensic exhibit, not the notice.Best practice / guidance, not Article 33(5): NIST SP 800-86 collection, working copy, hashes, chain of custody. RFC 3227: make a bit-level copy and do not analyse the evidence copy. Legal admissibility is a forum-specific rules-of-evidence question; it is not a NIST checkbox and not this page. The chain-of-custody page on this site is the handling record. This product does not keep one.Do not examine the original. Do not reimage over it. Do not 'clean up' malware samples before they are imaged. Do not treat a matching hash as a ruling of admissibility. Do not attach a memory image to a GDPR Article 33 notice because this table listed forensic findings.
Remediation proofWhat was taken or proposed to address the incident, and what can be shown later: token revoked, session killed, patch applied, access removed, hold placed. Article 33(5) names remedial action. Article 33(3)(d) names measures taken or proposed on the notice itself.Legal requirement (only if GDPR applies): Article 33(5) remedial action; Article 33(3)(d) measures taken or proposed, including, where appropriate, measures to mitigate adverse effects. Legal requirement (only if DORA applies): RTS (EU) 2024/1774 Article 22 and DORA Article 17 — record incidents and retain related evidence. Guidance: EDPB Guidelines 9/2022. A containment ticket is not automatically the whole limb.Do not claim eradication that is not done. Do not destroy the pre-remediation image to prove you cleaned it. Do not treat a CRA ladder draft as proof a measure was submitted. Isolate, then remediate on a copy you can still show.

Chain of custody — different job; this product does not keep one

A chain of custody is the chronological record of digital evidence: who collected it, when (UTC), where, how, why, who it was transferred to, where it was stored, and the hashes of original and copy. NIST SP 800-86 tracks movement through collection, safeguarding, and analysis. The chain is itself evidence. A Slack 'fyi' is not a chain. Last verified 7 September 2026. Not legal advice.

That record is a forensic exhibit. It is not GDPR Article 33(5). Article 33(5) does not name a chain of custody. NIST SP 800-86 does. The chain-of-custody page on this site is the field list and the fictional custody-log example. The preserve-evidence page on this site is what to capture first. This page does not reprint that form, and it does not ship one. This product does not keep a chain of custody.

  • Record the chain as you collect, not after. Who, what, when (UTC), where, how, why, hashes, and every transfer.
  • Work from a working copy. Hash original and copy. RFC 3227: do not analyse the evidence copy. Guidance, not a statute.
  • Legal admissibility is a forum-specific rules-of-evidence question. A matching hash is an integrity check, not a court ruling. Not legal advice.
  • This product does not image hosts, does not keep a chain of custody, does not produce a forensic report, and does not ship a downloadable custody form or evidence binder. That file does not exist.

Checklist

This is a question list, not a filing pack. The prepare-regulatory-report page on this site is the field checklist. The preserve-evidence page on this site is the capture order. The chain-of-custody page on this site is the handling record. The document-your-decision page on this site is the decision record.

  • Which job is this row doing — accountability documentation (Article 33(5) / 5(2), only if GDPR applies) or forensic exhibit (NIST SP 800-86 / chain of custody)? Do not collapse them.
  • For each item in the table — logs, awareness and containment timeline, scope, risk assessment, forensic findings, remediation proof — what do you have, what is missing, and who holds it.
  • Have originals been left unaltered. Isolate, do not wipe. The never-delete-after-breach page on this site is the anti-list.
  • Is the chain of custody a record, or a Slack ping. This product does not keep one.
  • Who is the named reviewer of the filing. A named human submits. The product does not. This page does not.
  • This page does not start a clock. Keeping a log is not a filing.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Accountability recordThe documentation that can demonstrate compliance: GDPR Article 5(2) generally, Article 33(5) for personal data breaches (facts, effects, remedial action). Not a forensic image and not a chain of custody.
Forensic exhibitThe image, working copy, hashes, and chain of custody that let another examiner reconstruct handling. NIST SP 800-86 (guidance). Not Article 33(5).
Article 33(5)GDPR duty to document any personal data breach — facts, effects, remedial action — so the supervisory authority can verify Article 33. Separate from the Article 33(1) notification. Legal requirement only if GDPR applies.
Article 5(2)GDPR accountability: the controller shall be responsible for, and be able to demonstrate compliance with, Article 5(1). Legal requirement only if GDPR applies.
Chain of custodyThe chronological handling record of digital evidence. NIST SP 800-86 (guidance). This product does not keep one. The chain-of-custody page on this site is the field list.
NIST SP 800-61r3April 2025 current final. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: a CSF 2.0 Community Profile. Supersedes SP 800-61r2 (August 2012). Guidance, not a statute.

Where this shows up in ShipReady Metrics

The signed-in app does not keep a chain of custody, does not produce a regulator filing pack, does not ship a downloadable evidence binder, does not attach forensic images to a notice, and does not file with a regulator. That binder does not exist. CRA ladder drafts are not attachments.

If you already have a session: signed-in app → Compliance → CRA reporting produces draft ladder text (24-hour early warning, 72-hour notification, 14-day final report) from recorded awareness for findings the organization has classified as CRA-in-scope. Each draft is marked DRAFT and states that a named reviewer must verify and submit; nothing in that surface has been sent to any authority. Status is the literal 'draft'. Those drafts are not a GDPR Article 33 pack, not a NIS2 Article 23 pack, not a DORA RTS pack, and not evidence you attach to a filing.

Compliance surfaces also hold evidence artifacts: control-mapped collection and a human evidence review overlay (accept can render a manual row as met; reject as gap). That met-verdict overlay is a compliance artifact for SOC 2 / ISO 27001-style programs — a timestamped evidence record for controls. It is not a forensic chain of custody and not a regulator filing pack. The obligation map lists frameworks the organization marked in-scope; that mark is not a legal opinion. The cyber risk register lives under Security. None of those surfaces images a host, keeps a chain of custody, or substitutes for the commander, counsel, the insurer, or DFIR.

Primary sources (last verified 7 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2016/679 Article 5(2) and Article 33(5) are legal requirements only when GDPR applies. EDPB Guidelines 9/2022 are regulator guidance on personal data breach notification, including documenting breaches; they are not the regulation. ENISA's recommendations for a methodology of the assessment of severity of personal data breaches are agency guidance on severity, not a documentation statute. NIST SP 800-61 Revision 3 (April 2025) is the current final incident-response community profile and supersedes Revision 2 (August 2012). NIST SP 800-86 (August 2006) remains the current final guide this page cites for forensic techniques and chain of custody — guidance, not a statute. Regulation (EU) 2022/2554 Article 17 is the DORA incident-recording duty; Commission Delegated Regulation (EU) 2024/1774 Article 22 is the RTS on retaining ICT-incident evidence — only if DORA applies. These are examples, not a complete world list. Not legal advice.

The prepare-regulatory-report page on this site is the field checklist. The reporting-deadlines page on this site is the statute table. The who-to-notify page on this site is the recipient-class map. The preserve-evidence page on this site is the capture list. The chain-of-custody page on this site is the handling record. The never-delete-after-breach page on this site is the anti-list. The document-your-decision page on this site is the decision record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is the jurisdiction treatment of Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. A dedicated CRA, UK GDPR, US-state-laws, SEC cyber-disclosure, HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.

Frequently asked questions

What evidence should support a regulatory filing?

The record that can show facts, effects, and remedial action: logs, an awareness and containment timeline, scope determination, the risk assessment and its reasons, forensic findings, and remediation proof. GDPR Article 33(5) is a documentation duty (only if GDPR applies), not a list of forensic attachments. A chain of custody is a different job under NIST SP 800-86. Last verified 7 September 2026. Not legal advice.

Is this legal advice?

No. It is operational guidance distilled from GDPR Article 5(2) and Article 33(5), EDPB Guidelines 9/2022, ENISA severity-assessment recommendations, NIST SP 800-61 Revision 3 (current final; Revision 2 is superseded), NIST SP 800-86, and, where DORA applies, DORA Article 17 plus RTS (EU) 2024/1774 Article 22. Whether any duty applies, what you must retain, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady keep a chain of custody or a filing pack?

No. This product does not keep a chain of custody, does not produce a regulator filing pack, and does not ship a downloadable evidence binder. Compliance evidence review and the met-verdict overlay are compliance artifacts (accept can render met; reject, gap), not a forensic chain. CRA ladder drafts are not attachments. The cyber risk register lives under Security. A named human still submits.

Does Article 33(5) require attaching forensic images to the notice?

No. Article 33(5) requires the controller to document any personal data breach — facts, effects, remedial action — so the supervisory authority can verify Article 33. It does not name memory images, hashes, or a chain of custody as required attachments. Forensic preservation is NIST SP 800-86-class handling, a different job. Counsel maps what YOUR authority will actually ask to see. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.