Products
Every reporting clock you are on, from one timestamp.
After an incident the hard part is not knowing that you must report. It is knowing to whom, by when, and in what order, while several clocks run at the same time. Enter the moment of discovery and get the whole timeline, with the article behind every deadline.
Nothing you type here is transmitted: the calculation runs in your browser, and once this page has loaded it makes no further requests at all. How that works, and what our visit statistics do and do not record, is in the FAQ below.
Your deadlines
Your organisation
Your deadlines
This calculator runs in your browser, so it needs JavaScript. With scripting off you can still read every deadline, clock start and citation in the reference below.
How the deadlines are counted
- Hour-based deadlines are counted as elapsed time, so a 24-hour clock started at 09:30 runs out 24 real hours later even across a daylight-saving change.
- Day and month deadlines keep the clock time: 14 days after 09:30 is 09:30 on the fourteenth day, and one month after 31 January falls on 28 or 29 February.
- Business-day deadlines skip weekends and the public holidays of the relevant country, and fall due at that regulator's filing cut-off.
- Where a duty has no fixed period, it is shown as immediate rather than given an invented number of hours.
- Where a clock runs from something other than discovery, such as DORA's classification or the SEC's materiality determination, the tool asks for that moment instead of assuming it.
The duties behind the calculation
Every deadline carries its provision and its source in the row that opens below it. This is the same material gathered in one place: the entity test, what triggers each duty, and the moment its clock starts.
Swiss duty to report cyberattacks on critical infrastructure Switzerland
An entity-list test, not a size or impact test: 21 categories in Art. 74b(1) ISG, among them federal, cantonal and communal authorities, universities, energy, drinking-water, wastewater and waste operators, banks, insurers and financial market infrastructures, hospitals on a cantonal list, medical laboratories, postal, rail, bus, cableway, shipping and aviation operators, telecommunications providers, domain registries and registrars, cloud, search, digital trust and data-centre providers seated in Switzerland, and manufacturers of hardware or software used by critical infrastructure. Art. 12 CSV exempts, among others, universities under 2,000 students and — for medical laboratories, medicinal-product licensees, postal providers and suppliers of essential everyday goods — entities under 50 staff with no more than CHF 10 million turnover or balance-sheet total in the affected area. On request, BACS states by formal order whether the duty applies to you.
- Legal basis
- Art. 74a–74h ISG (SR 128); Cybersicherheitsverordnung (CSV, SR 128.51)
- Authority
- Federal Office for Cyber Security (BACS)
- Applies from
- 1 April 2025
- Triggered by
- A cyberattack that meets at least one of the four alternatives in Art. 74d ISG: it endangers the functional capability of the affected critical infrastructure; it has led to manipulated or leaked information; it remained undetected over a longer period, in particular where there are signs that it was carried out to prepare further attacks; or it is connected with extortion, threat or coercion.
- Clock starts
- Discovery of the cyberattack by the reporting entity (Art. 74e(1) ISG) — not the moment of the attack, and not a later classification or materiality assessment.
- Filed with
- The reporting form on the BACS Cyber Security Hub, the secure transmission system required by Art. 74f(1) ISG. An account requires registration with the federal eIAM identity service, which is worth doing before an incident rather than during one.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Initial report to the BACS | 24 hours from discovery | A report with the information required by Art. 74e(2) ISG and Art. 15 CSV: the reporting entity, the nature and execution of the attack, and its effects, as far as known. | Art. 74e(1)–(2) ISG; Art. 15 CSV |
| Complete the report | 14 days after the initial report to the BACS | The Art. 74e(2) ISG and Art. 15 CSV information that was not yet known when the initial report was filed. | Art. 16(1) CSV, implementing Art. 74e(3) ISG |
| Keep the report up to date | no fixed period (after the previous step) | An open-ended duty: supplement the report as soon as new information becomes available. | Art. 74e(3) and (5) ISG; Art. 16(2) CSV |
Note: The reporting duty has applied since 1 April 2025, but the enforcement mechanism and the fine of up to CHF 100,000 (Art. 74g, 74h ISG) only since 1 October 2025. The 14-day period is set by the ordinance (Art. 16(1) CSV), not by the act itself. Art. 74b(3) extends the duty to attacks whose effects are felt in Switzerland even where the affected IT resources are abroad; it is about where the systems sit, not where the entity is domiciled.
Primary sources: fedlex.admin.ch · fedlex.admin.ch · security-hub.ncsc.admin.ch
Swiss notification of a breach of data security Switzerland
Controllers subject to the Swiss Data Protection Act, and — for the duty to notify the controller — their processors.
- Legal basis
- Art. 24 DSG (SR 235.1); Art. 15 DSV (SR 235.11)
- Authority
- Federal Data Protection and Information Commissioner (FDPIC)
- Applies from
- 1 September 2023
- Triggered by
- A breach of data security that is likely to lead to a high risk to the personality or the fundamental rights of the data subjects. A processor's duty to notify its controller has no risk threshold at all.
- Clock starts
- The Act sets no clock-start event and no fixed period. Art. 24(1) DSG requires notification 'as quickly as possible' — in practice, from the moment the controller is aware.
- Filed with
- The FDPIC's online DataBreach portal.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Processor notifies the controller | no fixed period (from discovery) | Notification of any breach of data security to the controller, with no risk threshold and no prescribed content. Only where your organisation is the processor. |
Art. 24(3) DSG |
| Notify the FDPIC | no fixed period (from discovery) | A notification through the DataBreach portal with the Art. 15(1) DSV content: the form of the breach, its time and duration where possible, the categories and approximate number of data subjects and records, the consequences and risks, and the measures taken or planned. | Art. 24(1)–(2) DSG; Art. 15(1) DSV |
| Inform the data subjects | no fixed period (from discovery) | Information in simple and comprehensible language covering the form of the breach, its consequences and the measures taken. Where necessary to protect the data subjects, or where the FDPIC requires it. |
Art. 24(4) DSG; Art. 15(3) DSV |
| Supply what was missing | no fixed period (after the notify the FDPIC) | The Art. 15(1) DSV details that could not be given at the time of the notification. | Art. 15(2) DSV |
| Keep the breach documentation | 24 months after the notify the FDPIC | Nothing is filed. The documentation of the breach must be kept for at least two years from the notification to the FDPIC — the only fixed period in this regime. | Art. 15(4) DSV |
Note: There is no 72-hour rule here: Swiss law deliberately sets a standard rather than a number, and the only hard period in the whole regime is the 24-month documentation duty. Cantonal and communal public bodies are not covered by the federal Act — they report under their own cantonal data protection law, which is a separate and additional duty.
Primary sources: fedlex.admin.ch · fedlex.admin.ch · databreach.edoeb.admin.ch
FINMA reporting of cyber attacks Switzerland
Institutions supervised by FINMA. Where a bank or an insurance undertaking has outsourced a material function, the service provider is itself placed under the Art. 29 FINMASA duty by statute.
- Legal basis
- Art. 29(2) FINMASA (SR 956.1); FINMA Guidance 05/2020, as clarified by FINMA Guidance 03/2024
- Authority
- Swiss Financial Market Supervisory Authority (FINMA)
- Applies from
- 1 September 2020
- Triggered by
- A successful cyber attack on the institution's critical infrastructure, classified by severity.
- Clock starts
- Discovery of the cyber attack.
- Filed with
- The initial report goes informally to your FINMA key account manager; the full report is filed on the FINMA survey and application platform (EHP).
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Initial notification to FINMA | 24 hours from discovery | An informal notification to your key account manager with an initial assessment of the attack and its classification. | FINMA Guidance 03/2024, section 3, clarifying FINMA Guidance 05/2020, section 3 |
| Full report via EHP | 72 hours from discovery | The completed 'Report cyber attack' template in EHP: institution, contact person, description, classification, affected systems and the measures taken. | FINMA Guidance 05/2020, section 3 and footnote 8 |
| Report new developments | no fixed period (after the previous step) | A fresh EHP report on the same attack. This recurs each time there are new developments or a changed assessment. | FINMA Guidance 05/2020, section 3 |
| Closing root-cause report | no fixed period (after the previous step) | Due once the institution has finished handling the case; the content required scales with the severity classification. | FINMA Guidance 05/2020, section 3 |
Note: These periods come from FINMA supervisory guidance rather than from an ordinance, and Guidance 03/2024 clarifies the 2020 text. The 24-hour clock is suspended outside bank working days, except where the attack is classified as severe. A cyber attack on a FINMA-supervised institution will often trigger the BACS reporting duty in parallel. ⚠
Primary sources: finma.ch · finma.ch
GDPR personal data breach notification European Union
Controllers within the territorial scope of Art. 3 GDPR, and processors for their duty to notify the controller. A Swiss company is caught where it offers goods or services to people in the EU or monitors their behaviour.
- Legal basis
- Art. 33, 34 Regulation (EU) 2016/679
- Authority
- The competent national supervisory authority
- Applies from
- 25 May 2018
- Triggered by
- A personal data breach, unless it is unlikely to result in a risk to the rights and freedoms of natural persons.
- Clock starts
- Awareness of the controller. The EDPB treats this as the moment of a reasonable degree of certainty that a breach has occurred, which is earlier than knowing its full extent.
- Filed with
- No channel is prescribed by the Regulation; each supervisory authority runs its own form or portal.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify the supervisory authority | 72 hours from discovery | A notification with the four Art. 33(3) elements: the nature of the breach with categories and approximate numbers of data subjects and records, the contact point, the likely consequences, and the measures taken or proposed. | Art. 33(1) and 33(3) GDPR |
| Provide the rest in phases | no fixed period (after the notify the supervisory authority) | The outstanding Art. 33(3) information. This is what makes the 72 hours workable: notify on time with what you have, complete it after. Where the information could not all be provided at once. |
Art. 33(4) GDPR |
| Processor notifies the controller | no fixed period (from discovery) | Notification to each affected controller. No period is fixed, but the controller's own 72 hours depends on it. Only where your organisation is the processor. |
Art. 33(2) GDPR |
| Communicate to the data subjects | no fixed period (from discovery) | A communication in clear and plain language describing the breach, the contact point, the likely consequences and the measures taken. The Art. 34(3) exemptions apply, among them encryption that renders the data unintelligible. Where the breach is likely to result in a high risk to individuals. |
Art. 34(1)–(3) GDPR |
Note: The 72 hours is an outer limit on a duty that is owed 'without undue delay': where you can notify sooner, you must. Missing it does not end the duty — the late notification must carry the reasons for the delay. Periods are computed under Regulation (EEC, Euratom) No 1182/71.
Primary sources: eur-lex.europa.eu · edpb.europa.eu
NIS2 significant incident reporting European Union
Entities in the sectors of Annexes I and II that are neither micro nor small enterprises, plus entities caught regardless of size, as designated by the national transposing law. Being within the Directive's scope is not the same as being an essential or important entity: domain registrars, for example, are in scope for other duties but do not owe the Art. 23 reporting duty on that basis alone.
- Legal basis
- Art. 23 Directive (EU) 2022/2555, as transposed into national law
- Authority
- The national CSIRT or competent authority
- Applies from
- 18 October 2024
- Triggered by
- A significant incident: one that has caused or is capable of causing severe operational disruption of the services or financial loss, or that has affected or is capable of affecting others by causing considerable material or non-material damage.
- Clock starts
- Becoming aware of the significant incident. Implementing Regulation (EU) 2024/2690 reads this as covering both a suspicious event the entity detected itself and a potential incident brought to its attention by a third party.
- Filed with
- The single entry point designated by the Member State concerned.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Early warning | 24 hours from discovery | An early warning indicating, where applicable, whether the incident is suspected of being caused by unlawful or malicious acts and whether it could have a cross-border impact. | Art. 23(4)(a) Directive (EU) 2022/2555 |
| Incident notification | 72 hours from discovery | An update of the early warning with an initial assessment of the incident, including its severity and impact, and where available the indicators of compromise. | Art. 23(4)(b) Directive (EU) 2022/2555 |
| Incident notification — trust service providers | 24 hours from discovery | The same notification as above, but due within 24 rather than 72 hours. Trust service providers only, for incidents affecting their trust services. |
Art. 23(4), third subparagraph, Directive (EU) 2022/2555 |
| Intermediate report | no fixed period (after the incident notification) | Relevant status updates. No period is set because the duty only arises if the authority asks. Only on request from the CSIRT or competent authority. |
Art. 23(4)(c) Directive (EU) 2022/2555 |
| Final report | 1 month after the incident notification | A detailed description including severity and impact, the type of threat or likely root cause, the mitigation measures applied and ongoing, and any cross-border impact. | Art. 23(4)(d) Directive (EU) 2022/2555 |
| Notify the recipients of your services | no fixed period (from discovery) | Inform the recipients of the services of the significant incident and, where relevant, of any measures or remedies they can take. Where the incident is capable of adversely affecting the provision of your services. |
Art. 23(1) Directive (EU) 2022/2555 |
Note: NIS2 is a directive, so the duty you owe is the national transposition. This entry covers EU and EEA states that do not yet have their own entry in this tool; where one exists, use it, because the national periods, filing channels and in-force dates differ from the directive's own.
Primary sources: eur-lex.europa.eu · publications.europa.eu
German BSIG incident reporting (NIS2) Germany
Two tiers with the same reporting chain. Broadly: entities established in Germany in the Annex 1 and 2 fields — energy, transport, banking and financial market infrastructure, health, water and waste water, digital infrastructure and IT services, space, post and courier, waste, chemicals, food, manufacturing of medical devices, electronics, machinery and vehicles, online marketplaces, search engines, social networks and research — with 50 or more staff or with both turnover and balance-sheet total above EUR 10 million, counting group affiliates. Operators of critical installations, qualified trust service providers, TLD registries and DNS providers are caught regardless of size. Telecoms and energy network operators under the EnWG, and DORA financial entities, keep their own sector regimes instead of § 32.
- Legal basis
- § 32 BSIG (BGBl. 2025 I Nr. 301, Art. 1 NIS2UmsuCG); scope § 28 and Anlagen 1, 2 BSIG
- Authority
- Federal Office for Information Security (BSI)
- Applies from
- 6 December 2025
- Triggered by
- A significant security incident under § 2 no. 11 BSIG: one that has caused or can cause severe operational disruption or financial loss, or considerable damage to others. The BSI applies the criteria of Implementing Regulation (EU) 2024/2690, and significance is assumed where a critical service has failed.
- Clock starts
- Kenntniserlangung — becoming aware of the significant incident.
- Filed with
- The BSI-Portal, which requires an ELSTER organisation certificate and therefore a German tax number. Set that up before an incident, not during one.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Early warning to the BSI | 24 hours from discovery | An early warning stating whether the incident is suspected to be unlawful or malicious and whether it could have cross-border effects. | § 32(1) sentence 1 no. 1 BSIG |
| Incident notification | 72 hours from discovery | An update of the early warning with an initial assessment, severity, impact and where available the indicators of compromise. | § 32(1) sentence 1 no. 2 BSIG |
| Intermediate report | no fixed period (after the incident notification) | Status updates, due only if the BSI asks for them. Only when the BSI requests one. |
§ 32(1) sentence 1 no. 3 BSIG |
| Final report | 1 month after the incident notification | A detailed description with severity and impact, the type of threat or root cause, the mitigation applied and any cross-border effects. | § 32(1) sentence 1 no. 4 BSIG |
| Progress report instead of the final report | 1 month after the incident notification | Where the incident is still ongoing at the one-month point, a progress report falls due instead, followed by the final report once handling ends. Only if the incident is still ongoing one month after the notification. |
§ 32(2) BSIG |
| Warn the recipients of your services | no fixed period (from discovery) | Inform the recipients of the service about the incident and about any measures or remedies they can take. Where the incident can adversely affect the delivery of your service. |
§ 35(2) BSIG |
Note: There is no general transitional period: the duties applied from 6 December 2025. The separate registration duty in § 33 BSIG is not modelled here and its statutory deadline has already passed; unregistered entities are told to register immediately.
Primary sources: gesetze-im-internet.de · bsi.bund.de
Austrian NISG 2026 incident reporting Austria
Essential and important entities across the 18 sectors of the Act's annexes, with the usual size thresholds, as established in Austria.
- Legal basis
- § 34 and § 35 NISG 2026 (BGBl. I Nr. 94/2025)
- Authority
- Cybersecurity Authority (Bundesamt für Cybersicherheit), via the competent CSIRT
- Applies from
- 1 October 2026
- Triggered by
- A significant cybersecurity incident as defined in § 35 NISG 2026.
- Clock starts
- Becoming aware of the significant incident.
- Filed with
- The sector CSIRT competent for the entity, or the national CSIRT where none exists.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Early warning | 24 hours from discovery | An early warning to the competent CSIRT. | § 34 Abs. 2 Z 1 NISG 2026 |
| Incident notification | 72 hours from discovery | An updated notification with an initial assessment of severity and impact. | § 34 Abs. 2 Z 2 NISG 2026 |
| Notification — trust service providers | 24 hours from discovery | The same notification, but due within 24 rather than 72 hours. Trust service providers only, for incidents affecting their trust services. |
§ 34 Abs. 2 NISG 2026 |
| Interim report | no fixed period (after the incident notification) | Status updates, due only on request. Only on request by the CSIRT or the Cybersecurity Authority. |
§ 34 Abs. 2 Z 3 NISG 2026 |
| Final report | 1 month after the incident notification | A detailed description, the root cause, the mitigation applied and any cross-border effects. | § 34 Abs. 2 Z 4 NISG 2026 |
| Notify the recipients of your service | no fixed period (from discovery) | Inform service recipients where the incident impairs delivery of the service. Where the incident impairs delivery of your own service. |
§ 34 Abs. 3 NISG 2026 |
Note: The Act entered into force on 1 October 2026, so practice is young. The separate registration and self-declaration duties are not modelled here.
Primary sources: ris.bka.gv.at
Italian NIS2 incident reporting (d.lgs. 138/2024) Italy
Essential and important entities established in Italy across the decree's sector annexes. A separate regime, legge 90/2024, binds listed public bodies and their in-house companies, and an entity can owe both.
- Legal basis
- Art. 25 d.lgs. 4 settembre 2024, n. 138; separately legge 28 giugno 2024, n. 90
- Authority
- National Cybersecurity Agency (ACN), through CSIRT Italia
- Applies from
- 15 January 2026
- Triggered by
- A significant incident under art. 25, with the taxonomy set by ACN determination.
- Clock starts
- Becoming aware of the significant incident.
- Filed with
- CSIRT Italia through the ACN service portal. The legge 90/2024 route is a separate channel and the two must not be conflated.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Pre-notification | 24 hours from discovery | The pre-notification to CSIRT Italia. | Art. 25, comma 5, lett. a) d.lgs. 138/2024 |
| Incident notification | 72 hours from discovery | The notification with an initial assessment of the incident. | Art. 25, comma 5, lett. b) d.lgs. 138/2024 |
| Notification — trust service providers | 24 hours from discovery | The same notification, within 24 rather than 72 hours. Trust service providers only. |
Art. 25, comma 6 d.lgs. 138/2024 |
| Intermediate report | no fixed period (after the incident notification) | Status updates, due only on request from CSIRT Italia. Only on request by CSIRT Italia. |
Art. 25, comma 5, lett. c) d.lgs. 138/2024 |
| Final report | 1 month after the incident notification | A detailed description, the root cause, the mitigation applied and any cross-border effects. | Art. 25, comma 5, lett. d) d.lgs. 138/2024 |
| Legge 90 first notification | 24 hours from discovery | The first notification under the separate legge 90/2024 regime, on its own channel. Only for the public bodies and in-house companies legge 90/2024 names. |
Art. 1, comma 2 legge 90/2024 |
| Legge 90 complete notification | 72 hours from discovery | The complete notification under legge 90/2024. Only for the public bodies and in-house companies legge 90/2024 names. |
Art. 1, comma 2 legge 90/2024 |
Note: Both the NIS2 decree (art. 38, comma 14) and legge 90/2024 contain a first-offence moratorium for the public bodies they name. Legge 90/2024 was coordinated with the NIS2 decree by art. 15-bis, inserted by legge 132/2025.
Primary sources: normattiva.it
France: the duties that bind before NIS2 France
Only entities individually designated by the Prime Minister as opérateur d'importance vitale or opérateur de services essentiels, and digital service providers (online marketplaces, search engines, cloud) above the size threshold. France had not transposed NIS2 at the time of review, so the 24/72-hour cascade does not apply there yet.
- Legal basis
- Code de la défense art. L1332-6-2 (OIV); loi n° 2018-133 arts. 7 and 13 (OSE, FSN); Code des assurances art. L12-10-1
- Authority
- ANSSI (CERT-FR)
- Applies from
- 10 May 2018
- Triggered by
- An incident affecting the security or continuity of the designated systems or services.
- Clock starts
- Becoming aware of the incident — the French duties use an 'as soon as you know' standard rather than an hour count.
- Filed with
- ANSSI's declaration forms, separately for OIV, OSE and digital service providers.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Declare to ANSSI as an OIV | no fixed period (from discovery) | Declare the incident affecting the designated systems of vital importance. Only for operators designated of vital importance. |
Code de la défense art. L1332-6-2 |
| Declare to ANSSI as an OSE | no fixed period (from discovery) | Declare the incident. This is owed in addition to any sector-specific reporting regime, not instead of it. Only for operators individually designated as providing essential services. |
Loi n° 2018-133 art. 7 I; décret n° 2018-384 art. 11 |
| Declare to ANSSI as a digital service provider | no fixed period (from discovery) | Declare the incident affecting the digital service. Online marketplaces, search engines and cloud services with 50 or more staff. |
Loi n° 2018-133 art. 13 I |
| File a criminal complaint to preserve insurance cover | 72 hours from discovery | File a criminal complaint. Under French insurance law, indemnification under a cyber clause is conditional on a complaint being filed within 72 hours of becoming aware. Only where you intend to claim under a cyber insurance clause governed by French law. |
Code des assurances art. L12-10-1 |
Note: This entry exists because applying the NIS2 cascade to France would be wrong: the loi résilience had not entered into force at the time of review. These declarations are owed in addition to, not instead of, any sector regime. Re-check the transposition status before relying on this.
Primary sources: senat.fr · assemblee-nationale.fr
DORA major ICT-related incident reporting European Union
The financial entities listed in Art. 2 DORA — among them credit institutions, payment and e-money institutions, investment firms, insurers and intermediaries, fund managers, crypto-asset service providers and trading venues — and certain ICT third-party service providers.
- Legal basis
- Art. 19 Regulation (EU) 2022/2554; Commission Delegated Regulation (EU) 2025/301
- Authority
- The relevant national competent authority
- Applies from
- 17 January 2025
- Triggered by
- An ICT-related incident classified as major under the classification criteria of Delegated Regulation (EU) 2024/1772.
- Clock starts
- Two clocks run in parallel for the initial notification and the earlier one governs: four hours from classifying the incident as major, and in any event 24 hours from becoming aware of it.
- Filed with
- The competent authority for your sector, through the secure electronic channels it makes available.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Initial notification | 4 hours from classification as major | The initial notification on the Annex I template of Implementing Regulation (EU) 2025/302, with the general information required by the delegated regulation. | Art. 5(1)(a) Delegated Regulation (EU) 2025/301 |
| Initial notification — outer limit | 24 hours from discovery | The same filing as above. Whichever of the two limits falls first is the one that governs. | Art. 5(1)(a) and 5(2) Delegated Regulation (EU) 2025/301 |
| Intermediate report | 72 hours after the initial notification | An intermediate report on the Annex I template, due even where nothing about the incident or its handling has changed. The period runs from your actual submission, so filing the initial notification early moves this forward too. | Art. 5(1)(b) Delegated Regulation (EU) 2025/301 |
| Final report | 1 month after the intermediate report | The final report on the Annex I template: root causes, the dates and times of the incident, and the remediation applied. | Art. 5(1)(c) Delegated Regulation (EU) 2025/301 |
| Inform affected clients | no fixed period (from discovery) | Inform clients about the incident and about the measures taken to mitigate its adverse effects. Where the incident has an impact on the financial interests of clients. |
Art. 19(3) Regulation (EU) 2022/2554 |
Note: All of these periods run in continuous calendar time. Art. 5(4) of the delegated regulation then moves a deadline that would fall outside working hours to 12:00 on the next working day, and Art. 5(5) withdraws even that for credit institutions, central counterparties, trading venue operators and NIS2 essential or important entities on the initial notification. This tool shows the unadjusted, earlier date.
Primary sources: eur-lex.europa.eu · eur-lex.europa.eu
Cyber Resilience Act reporting by manufacturers European Union
Manufacturers of products with digital elements made available on the EU market, wherever they are established.
- Legal basis
- Art. 14 Regulation (EU) 2024/2847
- Authority
- The CSIRT designated as coordinator, and ENISA
- Applies from
- 11 September 2026
- Triggered by
- Two separate chains: an actively exploited vulnerability contained in the product, and a severe incident having an impact on the security of the product.
- Clock starts
- Becoming aware. The 24-hour and 72-hour steps both run from that same moment — the 72 hours is not counted from the early warning. Only the final report for a vulnerability runs from something else: the availability of a corrective or mitigating measure.
- Filed with
- A single electronic submission to the single reporting platform operated by ENISA.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Early warning — exploited vulnerability | 24 hours from discovery | An early warning indicating, where applicable, the Member States in which the product has been made available. Actively exploited vulnerability. |
Art. 14(2)(a) Regulation (EU) 2024/2847 |
| Vulnerability notification | 72 hours from discovery | General information about the product, the general nature of the exploit and of the vulnerability, and any corrective or mitigating measures taken. Actively exploited vulnerability. |
Art. 14(2)(b) Regulation (EU) 2024/2847 |
| Final report — exploited vulnerability | 14 days from the corrective measure becoming available | A description of the vulnerability with its severity and impact, information on any malicious actor where available, and details of the security update or other corrective measure made available. Runs from when the corrective measure becomes available, not from awareness. |
Art. 14(2)(c) Regulation (EU) 2024/2847 |
| Early warning — severe incident | 24 hours from discovery | An early warning stating at least whether the incident is suspected of being caused by unlawful or malicious acts. Severe incident affecting the security of the product. |
Art. 14(4)(a) Regulation (EU) 2024/2847 |
| Incident notification | 72 hours from discovery | General information about the nature of the incident, an initial assessment, and any corrective or mitigating measures taken. Severe incident affecting the security of the product. |
Art. 14(4)(b) Regulation (EU) 2024/2847 |
| Final report — severe incident | 1 month after the incident notification | A detailed description of the incident including its severity and impact, the type of threat or root cause, and the mitigation measures applied. Severe incident affecting the security of the product. |
Art. 14(4)(c) Regulation (EU) 2024/2847 |
| Inform the users of the product | no fixed period (from discovery) | Inform the impacted users, and where appropriate all users, of the vulnerability or incident and of any risk mitigation or corrective measures they can take. | Art. 14(8) Regulation (EU) 2024/2847 |
Note: Art. 14 applies from 11 September 2026 while the rest of the Regulation applies from 11 December 2027, and the enforcement provisions are not among those brought forward. The two chains have different final reports: 14 days for a vulnerability, one month for an incident.
Primary sources: eur-lex.europa.eu
EU medical device and IVD vigilance reporting European Union
Manufacturers, and in a more limited way authorised representatives, importers and distributors. A cyber incident is in scope where it makes a device unsafe or impairs its performance.
- Legal basis
- Art. 87 Regulation (EU) 2017/745 (MDR); Art. 82 Regulation (EU) 2017/746 (IVDR)
- Authority
- National competent authority of the Member State where the incident occurred
- Applies from
- 26 May 2021
- Triggered by
- A serious incident involving the device, graded by outcome: a serious public health threat, a death or unanticipated serious deterioration in health, or any other serious incident.
- Clock starts
- Becoming aware of the serious incident and of the causal link to the device, or of the reasonable likelihood of one.
- Filed with
- The national competent authority of the Member State where the incident occurred; the route is national rather than through Eudamed.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Report a serious public health threat | 2 days from discovery | Report the serious incident to the competent authority. Where the incident is or involves a serious public health threat. |
Art. 87(4) MDR; Art. 82(4) IVDR |
| Report a death or unanticipated serious deterioration | 10 days from discovery | Report the serious incident to the competent authority. Where the incident involved a death or an unanticipated serious deterioration in health. |
Art. 87(5) MDR; Art. 82(5) IVDR |
| Report any other serious incident | 15 days from discovery | Report the serious incident to the competent authority. This is the default tier. Any serious incident not covered by the 2-day or 10-day tier. |
Art. 87(3) MDR; Art. 82(3) IVDR |
| Economic operator forwards to the manufacturer | no fixed period (from discovery) | An importer, distributor or authorised representative that receives a complaint forwards it to the manufacturer immediately. Where your EU entity is the importer, distributor or authorised representative rather than the manufacturer. |
Arts. 11(3)(g), 13(8) and 14(5) MDR |
Note: All three periods carry an overriding duty to report immediately; the day counts are outer limits, not targets. The Swiss MepV mirrors these timeframes for devices placed on the Swiss market.
Primary sources: eur-lex.europa.eu · eur-lex.europa.eu
UK GDPR personal data breach notification United Kingdom
Controllers within the scope of the UK GDPR, and processors for their duty to notify the controller.
- Legal basis
- Art. 33, 34 UK GDPR; Data Protection Act 2018
- Authority
- Information Commissioner's Office (ICO)
- Applies from
- 25 May 2018
- Triggered by
- A personal data breach, unless it is unlikely to result in a risk to the rights and freedoms of individuals.
- Clock starts
- Awareness of the controller. The ICO counts the 72 hours in calendar time, including weekends and public holidays.
- Filed with
- The ICO's online personal data breach report form.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify the ICO | 72 hours from discovery | A report with the Art. 33(3) content: the nature of the breach, the contact point, the likely consequences and the measures taken. | Art. 33(1) and 33(3) UK GDPR |
| Processor notifies the controller | no fixed period (from discovery) | Notification to the controller. No content is prescribed and no period is fixed. Only where your organisation is the processor. |
Art. 33(2) UK GDPR |
| Provide the rest in phases | no fixed period (after the notify the ICO) | The balance of the Art. 33(3) information that could not be supplied in the initial report. Where the information could not all be provided at once. |
Art. 33(4) UK GDPR |
| Communicate to the affected individuals | no fixed period (from discovery) | A communication in clear and plain language describing the breach and the measures taken, subject to the Art. 34(3) exemptions. Where the breach is likely to result in a high risk to individuals. |
Art. 34(1)–(3) UK GDPR |
Note: Separate duties can apply under the UK NIS Regulations and, for public electronic communications services, under PECR, which has its own 24-hour clock.
Primary sources: legislation.gov.uk · legislation.gov.uk · ico.org.uk
SEC material cybersecurity incident disclosure United States
Registrants filing current reports with the SEC. Foreign private issuers — which is what most Swiss-headquartered groups are — do not file Form 8-K at all and are not on the four-business-day clock.
- Legal basis
- Item 1.05 of Form 8-K (17 CFR 249.308); 17 CFR 229.106
- Authority
- US Securities and Exchange Commission
- Applies from
- 18 December 2023
- Triggered by
- A cybersecurity incident that the registrant determines to be material.
- Clock starts
- The registrant's own determination that the incident is material — not discovery, detection or containment. The determination itself must be made without unreasonable delay.
- Filed with
- Electronically on EDGAR, tagged in Inline XBRL.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Determine whether the incident is material | no fixed period (from discovery) | Nothing is filed. This internal determination is what starts the filing clock, and delaying it does not postpone the duty. | Instruction 1 to Item 1.05, Form 8-K |
| File Form 8-K, Item 1.05 | 4 business days from the materiality determination | A current report describing the material aspects of the nature, scope and timing of the incident and its material impact or reasonably likely material impact on the registrant. | Item 1.05(a) and General Instruction B.1, Form 8-K |
| Foreign private issuer: furnish on Form 6-K | no fixed period (from discovery) | A Form 6-K furnishing the information, due when the material is made public elsewhere. There is no four-business-day SEC clock for foreign private issuers. Foreign private issuers file this instead of Form 8-K. |
General Instruction B, Form 6-K |
Note: Business days here exclude weekends and US federal holidays, and the tool places the deadline at the 17:30 Eastern EDGAR cut-off. Not modelled: the amendment on Form 8-K/A for information that was unavailable at the original filing, the Attorney General national-security delay of 30 plus 30 plus 60 days, and the seven-business-day FCC delay for telecommunications carriers.
Primary sources: sec.gov · sec.gov · sec.gov
NYDFS Part 500 (New York financial services) United States
Covered entities licensed under New York banking, insurance or financial services law — which includes the New York branches of foreign banks and insurers, so a Swiss institution with a New York licence is caught directly.
- Legal basis
- 23 NYCRR 500.17
- Authority
- New York State Department of Financial Services (DFS)
- Applies from
- 1 December 2023
- Triggered by
- A cybersecurity incident, and separately the making of an extortion payment.
- Clock starts
- The determination that a reportable cybersecurity incident has occurred — not discovery. The extortion-payment clocks run from the payment itself.
- Filed with
- Electronic filing through the DFS Portal.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify the Superintendent | 72 hours from determining a reportable event occurred | Electronic notice of the cybersecurity incident through the DFS Portal. | 23 NYCRR 500.17(a)(1) |
| Provide the information DFS requests | no fixed period (after the notify the Superintendent) | Supply the information the Superintendent requests about the incident, and keep it updated. Arises once the incident notice has been filed. |
23 NYCRR 500.17(a)(2) |
| Report the extortion payment | 24 hours from making the extortion payment | Notify the Superintendent that an extortion payment has been made. Only where an extortion payment is actually made. |
23 NYCRR 500.17(c)(1) |
| Explain the extortion payment | 30 days from making the extortion payment | A written description of the reasons for the payment, the alternatives considered, the diligence performed and the sanctions diligence. Only where an extortion payment is actually made. |
23 NYCRR 500.17(c)(2) |
Note: The extortion-payment duties are independent of the incident notice: a payment starts its own 24-hour clock even where the incident itself was already reported. The annual certification is not modelled here.
Primary sources: dfs.ny.gov · dfs.ny.gov
HIPAA Breach Notification Rule United States
Covered entities and business associates, including subcontractors. A Swiss pharma, medtech or IT provider acting as a business associate for a US health plan or provider is caught directly.
- Legal basis
- 45 CFR 164.400–414
- Authority
- US Department of Health and Human Services, Office for Civil Rights
- Applies from
- 23 September 2009
- Triggered by
- A breach of unsecured protected health information. A breach is presumed unless a four-factor risk assessment shows a low probability of compromise.
- Clock starts
- Discovery: the first day the breach is known, or would have been known with reasonable diligence, to anyone other than the person who committed it.
- Filed with
- Individuals by first-class mail or email; HHS through the OCR Breach Portal; prominent media where required.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify the affected individuals | 60 days from discovery | A plain-language notice describing the breach, the types of information involved, the steps individuals should take, what you are doing, and contact details. | 45 CFR 164.404(a) and (b) |
| Notify HHS | 60 days from discovery | File the breach with the Office for Civil Rights through the breach portal. Where the breach involves 500 or more individuals. |
45 CFR 164.408(a) and (b) |
| Notify prominent media | 60 days from discovery | Notify prominent media serving the state or jurisdiction concerned. Where more than 500 residents of a single state or jurisdiction are affected. |
45 CFR 164.406 |
| Business associate notifies the covered entity | 60 days from discovery | Notify the covered entity and identify the individuals affected. Your contract will usually require this far sooner. Where your organisation is a business associate rather than a covered entity. |
45 CFR 164.410 |
Note: Sixty days is an outer limit on a duty owed without unreasonable delay. Breaches affecting fewer than 500 individuals are reported to HHS annually rather than within 60 days, which is not modelled here.
Primary sources: ecfr.gov
US state breach notification laws United States
Any organisation holding personal information about residents of a US state, wherever it is established. Most Swiss companies with US customers, a US webshop or US employees are caught by several state laws at once.
- Legal basis
- Fifty state statutes; the shortest fixed windows are set by RCW 19.255.010 (WA), Tex. Bus. & Com. Code § 521.053 and 9 V.S.A. § 2435
- Authority
- State attorneys general and the affected residents
- Applies from
- 1 July 2002
- Triggered by
- Unauthorised acquisition of personal information, as each state defines it; the definitions and the data elements covered differ.
- Clock starts
- Discovery of the breach in most states; a few run from the determination that a breach occurred.
- Filed with
- Residents directly, and each state regulator separately through its own form.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify affected residents — shortest state limit | 30 days from discovery | Notice to the affected residents. Washington, Colorado, Florida, Maine and others impose a 30-day outer limit; where several states apply, the shortest controls. | RCW 19.255.010(8) (Washington); comparable limits in CO, FL, ME |
| Notify the attorney general — shortest state limit | 14 business days from discovery | Preliminary notice to the state attorney general. Vermont's 14 business days is the shortest; other states range from 10 calendar days to 60. | 9 V.S.A. § 2435(b)(3)(B) |
| Notify the Texas attorney general | 30 days from determining a reportable event occurred | Electronic notice to the Texas attorney general. Where at least 250 Texas residents are affected. |
Tex. Bus. & Com. Code § 521.053(i) |
| Notify residents of the remaining states | no fixed period (from discovery) | Most states set no fixed outer limit and require notice without unreasonable delay, subject to the needs of law enforcement and of restoring system integrity. | e.g. Okla. Stat. tit. 24, § 163(A) |
Note: This is a consolidated view of fifty statutes, not a substitute for checking the states you are actually exposed to. Where several apply, the shortest window controls. The figures here are the shortest fixed outer limits; most states use a without-unreasonable-delay standard with no fixed number, and the state legislatures amend these frequently. ⚠
Primary sources: app.leg.wa.gov · legislature.vermont.gov
FTC Safeguards Rule notification United States
Non-banking financial institutions as the Rule defines them, which is broader than it sounds: mortgage brokers, auto dealers, tax preparers, lenders, collection agencies and many fintechs.
- Legal basis
- 16 CFR 314.4(j)
- Authority
- US Federal Trade Commission
- Applies from
- 13 May 2024
- Triggered by
- A notification event: unauthorised acquisition of unencrypted customer information of 500 or more consumers.
- Clock starts
- Discovery of the notification event.
- Filed with
- Electronically, on the form on the FTC's website.
| Step | Deadline | What is due | Provision |
|---|---|---|---|
| Notify the FTC | 30 days from discovery | Electronic notice naming the institution, the type and amount of information involved, the date or date range, and the number of consumers affected. | 16 CFR 314.4(j)(1) |
Note: The law-enforcement delay available under the Rule is not modelled here.
Primary sources: ecfr.gov
What this tool is not
This is a free calculator, not legal advice, and it does not create or remove any obligation. Sector-specific duties, contractual notice periods and the facts of your incident can all change the answer.
Deadlines are reproduced from the instruments cited on this page. Verify each one against the primary source before you rely on it, and take legal advice where the consequences matter.
Regulatory data last reviewed: 8 October 2026
FAQ
Does anything I enter get sent to Point Break Security?
No. The calculation runs in your browser, the page makes no requests at all while you use it, and the shareable link keeps your inputs after the # in the URL, which browsers never transmit to a server. You can load the page, disconnect from the network and it still works. The page load itself is counted in our cookie-free visit statistics, the same as any other page here; those statistics record the visit, never the contents of the form.
Which clock starts when we only suspect an incident?
Most of these duties start when your organisation becomes aware of the incident, which is earlier than the moment you have confirmed its full scope. The GDPR's own guidance treats awareness as a reasonable degree of certainty that a breach occurred, not certainty about its extent. If you are unsure, use the earlier timestamp: it gives you the tighter deadline.
Why does the tool ask separately when the incident was classified as major?
Because DORA counts its initial notification from that classification rather than from discovery, with an outer limit measured from awareness. Substituting the discovery time would produce a deadline that looks authoritative and is wrong, so the tool asks for the classification moment instead.
Can we rely on this for a regulatory filing?
Treat it as a fast way to see the shape of the problem and to put the right dates in front of the right people. Before you file, check each deadline against the provision cited on this page; where the stakes are high, confirm with counsel.
Rehearse this before you need it
The hour after discovery is not the time to find out who files what. We run incident-readiness reviews and crisis exercises that put these clocks into a playbook your team has already practised.