Free tool · Incident response

Cyber incident reporting deadlines in the US and EU: who you tell, and by when

Work out every notification a US or EU incident triggers — SEC 8-K, NYDFS, the US bank rule, HIPAA, the FTC, NIS2, DORA, GDPR and the CRA — with what starts each clock.

In short
Most US and EU incident clocks do not start at the breach. GDPR, NIS2, HIPAA and the FTC run from becoming aware or discovery. The SEC’s four business days, NYDFS’s 72 hours and the US bank rule’s 36 hours run from a determination you make. DORA’s initial notification is four hours from classifying an incident as major, and never later than 24 hours from awareness.

Work out your deadlines

Tick every regime that binds you — most organisations with US and EU operations are under several at once. The tool resolves each filing and what starts its clock. Add the moment you became aware, and the moment you decided the incident was reportable, to turn the windows into deadlines in your own time zone.

United States
European Union
The two moments that matter
7filings owed — windows from each trigger
InstrumentWhat you fileWindowGoes to
SEC Form 8-K, Item 1.05US · Form 8-K, General Instruction B.1; Item 1.05Disclose a material cybersecurity incident — its nature, scope and timing, and its material impactThe four days run from the materiality determination, not from discovery — and Instruction 1 requires that determination “without unreasonable delay after discovery”.4 business daysfrom: determining it is materialSEC, via EDGAR — a public filing
SEC Form 8-K/AUS · Form 8-K, Item 1.05, Instruction 2Amend the 8-K with anything not determined or unavailable at filingOwed if the original 8-K said information was not yet available.4 business daysfrom: the missing information becoming availableSEC, via EDGAR
NYDFS, 23 NYCRR 500.17(a)US · 23 NYCRR 500.17(a)(1)Notify the Superintendent of a cybersecurity incident at you, an affiliate or a third-party service providerAn incident at an affiliate or a third-party service provider counts, and ransomware deployed within a material part of your systems is a cybersecurity incident by definition.72 hoursfrom: determining it is reportableNYDFS SuperintendentElectronically, in the form on the DFS website
NYDFS, 23 NYCRR 500.17(c)US · 23 NYCRR 500.17(c)(1)Notice of an extortion paymentOwed only if an extortion payment is made.24 hoursfrom: making an extortion paymentNYDFS Superintendent
NYDFS, 23 NYCRR 500.17(c)US · 23 NYCRR 500.17(c)(2)Written explanation of why payment was necessary, the alternatives considered, and the sanctions diligence performedOwed only if an extortion payment is made.30 calendar daysfrom: making an extortion paymentNYDFS Superintendent
Computer-Security Incident Notification RuleUS · 12 CFR 53.3 (OCC) · 225.302 (Fed) · 304.23 (FDIC)Notify your primary federal regulator of a notification incidentA notification incident is one that has materially disrupted or degraded — or is reasonably likely to — banking operations, a business line whose failure would cause material loss, or operations whose failure would threaten financial stability.36 hoursfrom: determining it is reportableOCC, Federal Reserve or FDIC — whichever is primary
CIRCIAUS · Cyber Incident Reporting for Critical Infrastructure Act of 2022Report a covered cyber incident to CISA, within 72 hours of reasonably believing it occurredNot in force until CISA’s final rule takes effectCISA
NIS2, Article 23EU · Directive (EU) 2022/2555, Art. 4 and Recital 28Not owed separately. For a financial entity, DORA’s major-incident reporting applies instead of NIS2’s.——
DORAEU · Delegated Regulation (EU) 2025/301, Art. 5(1)(a)Initial notification of a major ICT-related incidentBoth limbs bind: classify at hour 22 and you have two hours, not four. Classified only after 24 hours, it is due within four hours of classification (Art. 5(2)). No weekend relief: Art. 5(5) removes the next-working-day extension from the initial and intermediate reports of credit institutions, CCPs, trading venues and NIS2 essential or important entities.4 hours from classification — and no later than 24 hours from awarenessfrom: classifying it as majorYour competent authority
DORAEU · Delegated Regulation (EU) 2025/301, Art. 5(1)(b)Intermediate report — due even if nothing has changedMeasured from submitting the initial notification. Update it when regular activities are recovered.72 hoursfrom: submitting the previous reportYour competent authority
DORAEU · Delegated Regulation (EU) 2025/301, Art. 5(1)(c)Final reportMeasured from the latest intermediate report, not from the incident.One monthfrom: submitting the previous reportYour competent authority
GDPR, Article 33EU · Regulation (EU) 2016/679, Art. 33(1)Notify a personal data breach, unless it is unlikely to result in a risk to people’s rights and freedoms“Where feasible” — a late notification must carry the reasons for the delay, and the detail may follow in phases (Art. 33(4)).72 hoursfrom: becoming awareCompetent supervisory authority
GDPR, Article 34EU · Regulation (EU) 2016/679, Art. 34(1)Tell the people affectedOwed where the breach is likely to result in a high risk to them.Without undue delayfrom: becoming awareAffected data subjects

Indicative, and not legal advice. US state breach-notification laws are not covered, and SEC closures announced at short notice are not modelled. Whether an instrument applies to you, and whether an event is reportable under it, are determinations for your compliance and legal team.

Take this away as an escalation pack

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Two kinds of starting gun

A list of durations — 4 business days, 72 hours, 36 hours, 24 hours — reads as a queue with the shortest first. It is not one, because the durations run from different events.

  • Becoming aware, or discovery. GDPR, NIS2, the Cyber Resilience Act, HIPAA and the FTC Safeguards Rule. HIPAA's discovery reaches back to when you would have known with reasonable diligence, and the FTC counts knowledge held by any employee or agent — neither is the moment the security team was told.
  • A determination. The SEC runs from determining an incident is material, NYDFS from determining a cybersecurity incident has occurred, and the US bank rule from determining a notification incident has occurred. DORA runs from classifying an incident as major — capped at 24 hours from awareness.

Several clocks then chain rather than run from the incident. NIS2's final report is due a month after the 72-hour notification; DORA's intermediate report 72 hours after the initial one, and its final report a month after that. Miss the first and every later date moves with it.

One incident, many clocks

Work it in this order.

  1. Fix the moment of awareness and write it down, with its time zone and its source — alert, vendor call, researcher email. Five of these regimes run from it.
  2. Start the determinations at once. Materiality, major classification and notification-incident status are separate questions for different owners. Log when each is answered.
  3. Resolve DORA before NIS2. A financial entity reports under DORA instead of NIS2, so filing both duplicates effort, and filing only NIS2 misses the tighter clock.
  4. Check the third-party direction. A bank service provider's notice starts its customers' analysis, a HIPAA business associate's starts the covered entity's, and a GDPR processor's starts the controller's. If you are the supplier, your delay spends someone else's window.
  5. Decide on any extortion payment with the clock in view. Under NYDFS, paying starts a 24-hour notice and a 30-day written explanation.

What this tool does not cover

  • US state breach-notification laws. Every state has one, with its own thresholds and windows. They can add recipients, and some are shorter than the federal clocks here.
  • Member State additions to NIS2. NIS2 is a directive. The authority you file with, and any extra detail, come from your country's transposing law.
  • CIRCIA, until it binds. CISA's critical-infrastructure reporting rule is shown as a planned obligation only. CISA states nothing is required until its final rule takes effect.

For an entity in India, the Indian incident reporting clock resolves CERT-In, the RBI, SEBI, IRDAI and IFSCA. How the Indian, EU and US clocks compare, and why six hours in India sets the pace for a group reporting in all three, is in incident reporting deadlines across India, the EU and the US.

Read from the issuing body's own text: Form 8-K and Form 6-K on sec.gov; 23 NYCRR Part 500 on dfs.ny.gov; 12 CFR Parts 53, 225 and 304, 45 CFR Part 164 and 16 CFR Part 314 on the eCFR; CISA's CIRCIA page; and Directive (EU) 2022/2555, Delegated Regulation (EU) 2025/301, Regulation (EU) 2016/679 and Regulation (EU) 2024/2847 on EUR-Lex. This tool is indicative and is not legal advice. Every instrument cited here was verified against the issuing regulator's own notification on .

Questions this page answers

When does the SEC’s four-business-day deadline start?
From the date the registrant determines that a cybersecurity incident is material, not from the date of the breach. Instruction 1 to Item 1.05 of Form 8-K requires that determination to be made without unreasonable delay after discovery, so the four days are measured from a decision the company controls — and a slow decision is itself what draws scrutiny. An event on a weekend or holiday starts the count on the next business day.
Is DORA’s initial notification due within four hours or 24 hours?
Both limbs bind. Delegated Regulation (EU) 2025/301 sets the initial notification within four hours of classifying an ICT-related incident as major, and no later than 24 hours from becoming aware of it. Classify at hour 22 and two hours remain. Where classification only happens after 24 hours, the notification is due within four hours of it. The intermediate report follows within 72 hours of the initial notification.
Does a bank covered by DORA also report under NIS2?
Not separately. NIS2 Article 4 disapplies its own provisions where a sector-specific Union act imposes at least equivalent obligations, and Recital 28 names DORA as that act for financial entities. A financial entity reports major ICT-related incidents under DORA instead of significant incidents under NIS2 Article 23. Being identified as an essential or important entity still matters under DORA: it removes weekend relief from the initial and intermediate reports.
How long does NYDFS give to report a cybersecurity incident?
Seventy-two hours from determining that a cybersecurity incident has occurred, under 23 NYCRR 500.17(a). The incident can be at the covered entity, an affiliate or a third-party service provider, and ransomware deployed within a material part of its systems is a cybersecurity incident by definition. An extortion payment adds two more filings: notice within 24 hours of paying, and a written explanation within 30 days.
Is GDPR’s 72 hours a hard deadline?
It is a deadline with a stated exception rather than an absolute one. Article 33 requires notification without undue delay and, where feasible, within 72 hours of becoming aware; a later notification must carry the reasons for the delay, and the detail may follow in phases. No notification is owed where the breach is unlikely to result in a risk to individuals. A processor tells its controller without undue delay.
Does CIRCIA require incident reporting to CISA today?
No. CIRCIA requires CISA to make rules for reporting covered cyber incidents within 72 hours of reasonably believing one occurred, but CISA states that nothing is required until its final rule takes effect, and that rule has not been published. Worth building into a runbook as a planned obligation; not one to file against today.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source →The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating →All free tools