About cyberincidentreporting.eu
A wrong deadline on a page like this is not a typo. It is a filing missed at three in the morning by somebody who trusted a stranger. That is the reason this site exists in the shape it does, and the reason it says nothing it could not read from the instrument itself.
Publisher
The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, an incident response and offensive security company. Contact: support@offseq.com.
How every deadline here is sourced
- Each hour count is read from the article cited beside it, in the English text on EUR-Lex, and not from a summary, a law-firm briefing or another website.
- The full instruments are linked at the foot of the home page and at the foot of every guide, by CELEX identifier, so you can open the article and check the wording in one click.
- Delegated and implementing acts are cited separately from the parent instrument, because that is where most of the operative numbers actually live. DORA's deadlines are in Delegated Regulation (EU) 2025/301, not in DORA; the NIS2 thresholds for digital infrastructure are in Implementing Regulation (EU) 2024/2690, not in the Directive.
- Every deadline is printed with the event it runs from. An hour count without its trigger is the single most common error in this subject area and it is the one that costs a filing.
- National detail is quoted from the national statute itself. Latvia is quoted from the Nacionālās kiberdrošības likums on likumi.lv, Finland from Kyberturvallisuuslaki 124/2025 on Finlex.
- The "Updated" date moves only when the text changes. An automated content-hash ledger reverts an unearned bump.
What the site refuses to state
Estonia and Lithuania have transposed NIS2 and have their own reporting channels. Their statutes are published on portals whose text this site could not retrieve, and the alternative was to reproduce numbers from secondary sources. On a page whose entire purpose is deadlines, that is worse than an admitted gap, so both are left out and the reader is sent to the national CSIRT instead.
The clock finder is built the same way. It will not name your national channel, because NIS2 is a directive and the channel is national. It will not tell you whether your incident is significant or major, because that is a judgment about facts it cannot see. It tells you which articles reach your situation, what they require and in what order, which is the part that can be got exactly right.
Authorship
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.
Commercial interest
We sell incident response, digital forensics, ransomware readiness and the resilience testing that these regimes drive. That is a direct interest in you concluding that you need them, and it should colour how you read every recommendation here.
- Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
- No law firm, compliance platform, insurer or tool vendor pays for a mention. There is no advertising and no affiliate revenue.
- Where the honest answer is that a duty does not apply to you, or that the report is one you can file yourself, the site says so. That answer costs us work and it is still the right one.
Corrections
If a deadline here is wrong, tell us and it will be fixed the same day. Send corrections to support@offseq.com, ideally with the article reference. Substantive changes are made and re-dated in the open.