All articles

Incident Response

One Incident, Three Regulators: Why Your Real Deadline Is Four Hours, Not 72

Everyone learned 72 hours from GDPR. DORA's first filing is due in four hours and NIS2's early warning at 24. One incident, three clocks, three start times.

Sylvio Sorel··7 min read
An open pocket watch resting in an open hand — the reporting clocks that start before a company knows the scope of an incident.

Ask a compliance team how long they have to report a serious incident and you will almost always hear the same number: 72 hours. It is the one deadline everybody learned, because GDPR taught it to a generation of privacy officers and it stuck.

For a growing number of European companies it is now the least urgent clock running. If you are a financial entity under DORA, your first filing is due within four hours — not of the breach, but of the moment you classify it as major. If you are an essential or important entity under NIS2, an early warning is due at 24. GDPR’s 72 hours, the number everyone remembers, is the last of the three to expire.

One incident. Three regulators. Three clocks that start at different moments and finish on different dates. Nearly every incident response plan we review is built for one of them.

The three clocks do not start together

This is the planning error that matters, and it is upstream of every deadline. Teams assume that “the clock starts when we find out.” Each regime defines that moment differently.

NIS2 starts on becoming aware of a significant incident — two conditions, not one: you must know there is an incident and have concluded it clears the significance bar. GDPR starts on becoming aware of a personal data breach, which an availability incident touching no personal data never triggers at all. DORA starts on classification — the point at which the incident meets the criteria for major under Delegated Regulation (EU) 2024/1772.

Picture a Friday night. Encryption is spotted at 21:14. By midnight you know it is real and spreading; by Saturday afternoon you know customer records were staged for exfiltration. Three clocks have started at three different times, and only one started when your on-call engineer picked up the phone. If your plan records a single “time of detection” and counts back from 72 hours, it is already wrong.

The four-hour clock nobody rehearses

DORA is the one that surprises people. Under Article 5 of Delegated Regulation (EU) 2025/301, a financial entity must submit its initial notification within four hours of classifying an incident as major, and no later than 24 hours from becoming aware of it. Most commentary quotes the 24 and stops. The four-hour limb is the hard obligation; the 24-hour limb is only an outer bound for incidents you classify quickly.

Two details make this sharper than it first reads.

First, a confirmed malicious intrusion classifies itself. Under the classification standard, a successful, malicious and unauthorised access to your systems — where that access may result in data losses — satisfies both the criticality gate and a materiality threshold on its own. You do not need a second criterion, a victim count, or a euro figure. The moment your responders confirm an intruder was in, the incident is major and the four hours are running — which is precisely the moment your team is least able to stop and write.

Second, the weekend relief probably does not apply to you. DORA lets an entity facing a deadline on a weekend or bank holiday file by noon of the next working day. Article 5(5) then removes that relief from credit institutions, central counterparties, trading venue operators — and from any entity identified as essential or important under NIS2. If you are in both regimes, you lose the concession that single-regime firms keep. Being dual-regulated is not the sum of two rulebooks; in this instance it is strictly worse than either.

That interaction is the reason our DORA compliance services start with classification criteria and named decision rights rather than with reporting templates. The template is the easy part.

NIS2’s 24 hours is a phone call, not a report

The 24-hour early warning under Article 23(4)(a) is widely misread as a first report, and teams delay it while they assemble facts they do not owe yet. The Directive asks for very little: an indication of whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. Recital 102 makes the intent explicit — the early warning exists so the CSIRT knows, and so you can ask for help, and reporting must not divert resources from actually handling the incident.

The substance arrives at 72 hours: an updated picture, an initial severity and impact assessment, and indicators of compromise where you have them. Then a final report within one month of the 72-hour notification — and note the anchor, because DORA’s final report runs one month from the last updated intermediate report, not from the first filing. Two regimes, two different end dates, from the same incident. Our NIS2 readiness work treats the 24-hour warning as a two-sentence obligation with a named sender, which is the only way it gets sent on time.

One incident, three regulators: the reporting clocks compared One incident, three regulators — every filing a dual-regime company owes, plotted from the moment it becomes aware.

The clock that actually gets fined

Here is the uncomfortable asymmetry. As of July 2026, no NIS2 administrative fine has been publicly confirmed by any competent authority in the European Union, and DORA enforcement is effectively nil. The regime with a track record is the old one: in January 2026 the CNIL fined Free €42 million over a breach exposing 24 million subscribers, citing late notification of the affected individuals alongside deficient intrusion detection.

Do not read that as a ranking of risk. NIS2’s ceilings are €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important ones, whichever is higher. It also carries something GDPR does not: for essential entities, as a last resort once milder measures have failed, an authority can ask a court to bar the chief executive from managerial functions. The absence of a first fine is a fact about the calendar, not about exposure.

Where you are changes the answer

A group with entities in four of our core markets currently gets four different answers, which is why our GDPR compliance services and NIS2 work are so often scoped together.

France has not transposed NIS2. The résilience bill cleared committee in the Assemblée nationale in September 2025 and has never reached a plenary vote; the Commission referred France to the Court of Justice on 8 July 2026, seeking a lump sum and daily penalties. ANSSI’s own figure is roughly 15,000 entities waiting, and pre-registration on MonEspaceNIS2 remains voluntary. Belgium has been live since October 2024, its first essential-entity audit deadline already behind it. Luxembourg transposed by the law of 5 May 2026. Switzerland, outside the EU and not subject to NIS2 at all, has had its own 24-hour duty to the federal cybersecurity office (BACS/OFCS, the former NCSC) since April 2025.

So a French financial entity today has DORA and GDPR clocks running in law, and a NIS2 clock sitting in Parliament. Building the process now costs the same as building it later — and whatever ANSSI has said publicly about phasing sanctions in, no grace clause for the NIS2 title exists in either chamber’s text today.

The fourth clock nobody budgets for

One more deadline runs from the same incident, and it is not a regulator’s. Since the LOPMI, article L.12-10-1 of the French code des assurances makes indemnification under a cyber policy conditional, for a professional insured, on filing a criminal complaint within 72 hours of becoming aware of the offence. It runs to the police, not the CNIL, and sits so close to the GDPR deadline that French practitioners call it the RGPD’s false friend. It binds French insureds only — but if your group has a French entity and a group cyber policy, it is yours.

What has to exist before the incident

None of this is solved on the night. Every one of these clocks is decided by six things you either wrote down in advance or you didn’t: who is authorised to classify an incident as major at 03:00, who signs and sends each filing, which portal each report goes to, who tells the client or the data subject, where each clock’s start time is recorded, and who gets called out of hours. That is the same argument we made in Incident Response Without a SOC — the cost of an incident is set by preparation, not by tooling.

Before the incident: which clocks apply and who decides Which clocks apply to you, and the six decisions that have to exist on paper before the incident, not during it.

And from 11 September 2026, the Cyber Resilience Act adds a 24-hour early warning and 72-hour notification for actively exploited vulnerabilities and severe incidents in products with digital elements. If you make or sell connected products, that is a fifth clock, six weeks out.

What to do in the next 30 days

Take your last tabletop exercise and re-run it with three stopwatches instead of one. Write down, for each regime you are in, the exact moment its clock would have started and who had authority to start it. If the answer to “who classifies” is a job title rather than two names and two phone numbers, that is the gap — and it is the cheapest one on this list to close.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.