The worksheet needs JavaScript to filter this catalogue down to your situation. The complete catalogue is below: every reporting duty the four regimes impose, with its article, its deadline, the trigger the deadline runs from, the recipient, and the content required.
-
NIS2 Art. 23(4)(a) – Early warning
Deadline: Within 24 hours of becoming aware of the significant incident.
Report to: Your national CSIRT or, where your Member State so provides, the competent authority.
Must contain: Where applicable, whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have a cross-border impact. Nothing more is required at this point.
-
NIS2 Art. 23(4)(b) – Incident notification
Deadline: Within 72 hours of becoming aware of the significant incident.
Report to: Your national CSIRT or, where your Member State so provides, the competent authority.
Must contain: An update to the early warning plus an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise. A trust service provider files this at 24 hours, not 72, where its trust services are affected.
-
NIS2 Art. 23(4)(c) – Intermediate report
Deadline: On request only when the CSIRT or competent authority asks for one.
Report to: Your national CSIRT or, where your Member State so provides, the competent authority.
Must contain: Relevant status updates. There is no scheduled intermediate report under NIS2.
-
NIS2 Art. 23(4)(d) – Final report
Deadline: Within one month of submitting the 72-hour incident notification.
Report to: Your national CSIRT or, where your Member State so provides, the competent authority.
Must contain: A detailed description including severity and impact; the type of threat or root cause likely to have triggered it; applied and ongoing mitigation measures; and, where applicable, the cross-border impact. If the incident is still running at that point, Art. 23(4)(e) takes a progress report instead and the final report follows within one month of your handling ending.
-
NIS2 Art. 23(1) – Notice to your service recipients
Deadline: Without undue delay where the incident is likely to adversely affect the provision of your services.
Report to: The recipients of your services.
Must contain: That the significant incident is likely to affect the service. Under Art. 23(2) a significant cyber threat carries a separate duty to tell potentially affected recipients what they can do about it.
-
DORA Del. Reg. 2025/301, Art. 5(1)(a) – Initial notification
Deadline: Within 4 hours of classifying the incident as major, normally capped at 24 hours from awareness. If classification occurs after those 24 hours, Article 5(2) allows four hours from that later classification.
Report to: The competent authority under DORA Art. 46. A credit institution classified as significant reports to its national authority, which transmits the report to the ECB immediately.
Must contain: Your incident reference; the date and time of detection and of classification; a description; which of the Articles 1 to 8 criteria of Delegated Regulation (EU) 2024/1772 made it major; the Member States affected; how it was discovered; where available its origin; and whether the business continuity plan has been activated.
-
DORA Del. Reg. 2025/301, Art. 5(1)(b) – Intermediate report
Deadline: Within 72 hours of submitting the initial notification, even where nothing about the incident has changed.
Report to: The same competent authority.
Must contain: When it occurred and, where applicable, when regular activities were recovered; how the 2024/1772 criteria were met; the incident type; the threat actor techniques where applicable; affected functional areas, business processes and infrastructure; the impact on clients' financial interests; which other authorities you have reported to; temporary measures; and indicators of compromise. Update it without undue delay, and in any case once regular activities are back.
-
DORA Del. Reg. 2025/301, Art. 5(1)(c) – Final report
Deadline: Within one month of the intermediate report, or of the last updated intermediate report.
Report to: The same competent authority.
Must contain: Root causes; when the incident was resolved and the root cause addressed; how it was resolved; anything relevant for resolution authorities; direct and indirect costs and losses without netting recoveries, plus the recoveries themselves; and any recurrence.
-
DORA DORA Art. 19(3) – Notice to clients
Deadline: Without undue delay as soon as you become aware, where the major incident affects clients' financial interests.
Report to: The clients concerned.
Must contain: The incident, and the measures taken to mitigate its adverse effects.
-
GDPR Art. 33(1) – Notification to the supervisory authority
Deadline: Without undue delay and, where feasible, within 72 hours of having become aware of the breach – unless it is unlikely to result in a risk to the rights and freedoms of natural persons.
Report to: The supervisory authority competent under Art. 55; for cross-border processing, your lead authority under Art. 56.
Must contain: The nature of the breach with the categories and approximate numbers of data subjects and of records; the data protection officer or other contact point; the likely consequences; and the measures taken or proposed, including mitigation. Art. 33(4) lets you supply this in phases; a notification later than 72 hours must carry reasons for the delay.
-
GDPR Art. 34(1) – Communication to data subjects
Deadline: Without undue delay once the breach is likely to result in a HIGH risk to the rights and freedoms of natural persons. No hour count attaches to this one.
Report to: The affected data subjects.
Must contain: In clear and plain language: the nature of the breach, the DPO contact, the likely consequences and the measures taken. Art. 34(3) removes the duty where the data were rendered unintelligible, for example by encryption; where later measures mean the high risk is no longer likely; or where it would take disproportionate effort, in which case a public communication takes its place.
-
GDPR Art. 33(2) – Notification to the controller
Deadline: Without undue delay after becoming aware of the personal data breach.
Report to: The controller you process for.
Must contain: Enough for the controller to run its own Art. 33 assessment on its own 72-hour clock. The Regulation sets no hour count for a processor; your Art. 28 processing agreement almost certainly does.
-
GDPR Art. 33(5) – Internal record of the breach
Deadline: Continuously for every breach, including those you decide not to notify, from the moment you become aware.
Report to: Your own breach register.
Must contain: The facts of the breach, its effects and the remedial action taken, in enough detail for the supervisory authority to verify your decision. This is the document that defends a decision not to notify.
-
CRA Art. 14(2)(a) – Early warning – exploited vulnerability
Deadline: Within 24 hours of becoming aware of the actively exploited vulnerability.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: Where applicable, the Member States on whose territory you are aware the product has been made available.
-
CRA Art. 14(2)(b) – Vulnerability notification
Deadline: Within 72 hours of becoming aware of the actively exploited vulnerability.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: General information as available about the product; the general nature of the exploit and of the vulnerability; any corrective or mitigating measures taken and any that users can take; and, where applicable, how sensitive you consider the notified information to be.
-
CRA Art. 14(2)(c) – Final report – exploited vulnerability
Deadline: No later than 14 days after a corrective or mitigating measure is available – not after the notification.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: A description of the vulnerability including severity and impact; where available, information on any malicious actor that exploited it; and details of the security update or other corrective measures made available.
-
CRA Art. 14(4)(a) – Early warning – severe incident
Deadline: Within 24 hours of becoming aware of the severe incident affecting the product's security.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: At least whether the incident is suspected of being caused by unlawful or malicious acts, and where applicable the Member States where the product has been made available.
-
CRA Art. 14(4)(b) – Incident notification
Deadline: Within 72 hours of becoming aware of the severe incident.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: General information on the nature of the incident, an initial assessment, corrective or mitigating measures taken and those users can take, and your sensitivity marking.
-
CRA Art. 14(4)(c) – Final report – severe incident
Deadline: Within one month of submitting the 72-hour incident notification.
Report to: The CSIRT designated as coordinator and ENISA, simultaneously, over the ENISA single reporting platform (CRA Art. 16).
Must contain: A detailed description including severity and impact; the type of threat or root cause likely to have triggered it; and applied and ongoing mitigation measures.
-
CRA Art. 14(8) – Notice to product users
Deadline: After becoming aware of the exploited vulnerability or the severe incident.
Report to: Impacted users of the product, and where appropriate all users.
Must contain: The vulnerability or incident and, where necessary, the risk mitigation and corrective measures users can deploy – where appropriate in a structured, machine-readable format. If you do not tell users in time, the notified CSIRTs may do it for you.
A duty is listed here whether or not it applies to you. The four guides set out which populations each regime reaches, and the NIS2 and DORA guides explain which one displaces the other for a financial entity.