Skip to content
cyberincidentreporting.eu

The four EU regimes that put a clock on a cyber incident – NIS2, DORA, the GDPR and the Cyber Resilience Act – read against each other, article by article.

Open the clock finder→
  • §1Instruments
  • §2Clock finder
  • §3The combined rule
  • §4How they stack
  • §5Guides
Home

About cyberincidentreporting.eu

Updated 13 September 2026

A wrong deadline on a page like this is not a typo. It is a filing missed at three in the morning by somebody who trusted a stranger. That is the reason this site exists in the shape it does, and the reason it says nothing it could not read from the instrument itself.

Publisher

The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, an incident response and offensive security company. Contact: support@offseq.com.

What we are not

OffSeq is not a law firm, a supervisory authority or a CSIRT. It cannot file a regulatory notification for you, it cannot decide whether a duty applies to your facts, and nothing on this site is legal advice. The technical work behind a report is ours; the legal judgment about the report is not.

How every deadline here is sourced

  • Each hour count is read from the article cited beside it, in the English text on EUR-Lex, and not from a summary, a law-firm briefing or another website.
  • The full instruments are linked at the foot of the home page and at the foot of every guide, by CELEX identifier, so you can open the article and check the wording in one click.
  • Delegated and implementing acts are cited separately from the parent instrument, because that is where most of the operative numbers actually live. DORA's deadlines are in Delegated Regulation (EU) 2025/301, not in DORA; the NIS2 thresholds for digital infrastructure are in Implementing Regulation (EU) 2024/2690, not in the Directive.
  • Every deadline is printed with the event it runs from. An hour count without its trigger is the single most common error in this subject area and it is the one that costs a filing.
  • National detail is quoted from the national statute itself. Latvia is quoted from the Nacionālās kiberdrošības likums on likumi.lv, Finland from Kyberturvallisuuslaki 124/2025 on Finlex.
  • The "Updated" date moves only when the text changes. An automated content-hash ledger reverts an unearned bump.

What the site refuses to state

Estonia and Lithuania have transposed NIS2 and have their own reporting channels. Their statutes are published on portals whose text this site could not retrieve, and the alternative was to reproduce numbers from secondary sources. On a page whose entire purpose is deadlines, that is worse than an admitted gap, so both are left out and the reader is sent to the national CSIRT instead.

The clock finder is built the same way. It will not name your national channel, because NIS2 is a directive and the channel is national. It will not tell you whether your incident is significant or major, because that is a judgment about facts it cannot see. It tells you which articles reach your situation, what they require and in what order, which is the part that can be got exactly right.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.

Commercial interest

We sell incident response, digital forensics, ransomware readiness and the resilience testing that these regimes drive. That is a direct interest in you concluding that you need them, and it should colour how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
  • No law firm, compliance platform, insurer or tool vendor pays for a mention. There is no advertising and no affiliate revenue.
  • Where the honest answer is that a duty does not apply to you, or that the report is one you can file yourself, the site says so. That answer costs us work and it is still the right one.

Corrections

If a deadline here is wrong, tell us and it will be fixed the same day. Send corrections to support@offseq.com, ideally with the article reference. Substantive changes are made and re-dated in the open.

cyberincidentreporting.eu

cyberincidentreporting.eu is a free reference on the EU incident-reporting deadlines that four separate instruments now impose on overlapping populations. Every hour count on this site is read from the article it comes from, and cited so you can check it before you rely on it.

Guides

  • NIS2 Article 23
  • DORA Article 19
  • GDPR Articles 33 and 34
  • CRA Article 14

Professional help

  • Incident response and forensics
  • Ransomware readiness
  • NIS2 and DORA compliance
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies and browser storage

cyberincidentreporting.eu is a free reference maintained by the OffSeq security team. OffSeq is an incident response and offensive security firm; it is not a law firm and cannot file a report on your behalf.

Nothing on this site is legal advice. Deadlines are quoted from the instrument named beside them; a directive is applied through your national transposition, so confirm the channel and any national addition with your own CSIRT or supervisory authority before you rely on it.

Operated by SEQ SIA · Riga, Latvia