Who you have to tell, inside what window, and in what form. This is the domain where an obligation turns into a countdown, and where most organisations discover their process on the day they need it.
What we track
NIS2 reporting clocks
EU. Early warning, incident notification and final report, plus the guidance narrowing what counts as a significant incident.
DORA major incident reporting
EU financial entities. Classification criteria, thresholds, and the templates the ESAs expect you to use.
SEC disclosure rules
US. Item 1.05 material incident disclosure, the voluntary 8.01 practice that has grown around it, and the enforcement posture behind both.
CIRCIA
US critical infrastructure. The final rule, its timing, and what covered entities will owe CISA once it applies.
EU Digital Omnibus
EU. Proposals for a single reporting point, which would change where notifications go without changing whether they are owed.
Sector and privacy overlays
All jurisdictions. Telecoms, energy, payments and health duties, and the separate breach notification owed to a data protection authority.
Who is in scope
Almost everyone, eventually. Reporting duties attach through several routes at once. As an essential or important entity under NIS2, as a financial entity under DORA, and as a listed company under the SEC rules. GDPR adds a duty as controller or processor, and your sector regulator will have its own.
The practical consequence is that scope is not a single yes or no. It is a set of overlapping triggers, and one event can activate several of them at different thresholds.
Where the deadlines fall
These are not calendar deadlines. They are clocks that start when an event does, which makes them the only obligations in the whole coverage set that you cannot prepare for by diarising a date.
NIS2 runs an early warning, then a fuller notification, then a final report. DORA runs initial, intermediate and final notifications against classification criteria. The SEC rules turn on materiality and run in business days from that determination. CIRCIA will add its own window for covered entities. Our analysts keep the windows in the Radar’s regulatory timeline, per regime, so your incident manager is not reading legislation at two in the morning.
Where organisations get caught
The clock starts on awareness, not on confirmation. Teams that wait for certainty about scope have usually missed the first window, and the regulator’s question afterwards is about when you first knew. Awareness is also a lower bar than most incident processes assume, and it can be satisfied by a supplier’s email or a security alert nobody escalated.
One event, several clocks. A breach notification to a data protection authority and an incident notification under NIS2 can describe the same event to different regulators on different thresholds. Inconsistency between the two is its own finding, and it is the kind an enforcement team notices.
Classification is where the argument happens. Whether an incident is significant, major or material decides whether you report at all, and that judgement is usually made at speed by whoever is awake. Guidance has been narrowing the classification window, which makes a pre-agreed severity mapping more valuable than another playbook.
Questions worth asking now
- Which reporting regimes could one incident trigger for us, and at what thresholds?
- Who is authorised to decide that a clock has started, at three in the morning?
- Does our severity scale map to the regulators’ classification criteria, or only to our own?
- Have we ever rehearsed a notification, with the actual form in front of us?
- Who signs a filing, and what happens if that person is unavailable?
- Can we reconstruct, after the fact, when we first became aware?
Related domains
Cybersecurity regulation covers the regimes these clocks belong to. Data security and privacy covers the parallel breach notification. Operational resilience covers the classification criteria in financial services.