The 2026 InfoSec Playbook · Daniel Ramos

#Appendix C — Regulatory Notification Matrix

Every notification clock this book covers, in one table — who it binds, what starts it, when it expires, who receives it, and what it costs to miss.

Who needs this: Legal Liaison, Incident Commander, DPO, Communications Lead, CISO, Compliance | Read time: 15 min | Maps to: CSF 2.0 RESPOND (RS.CO), GOVERN (GV.OC-03) | Verified as of: 5 September 2026 | Owns: the reference table; Chapter 15 owns the process and the privilege guidance, Playbook 14.7 owns the determination sequence

This is a reference, not a chapter. Chapter 15 tells you how to run the notification track; this tells you what the clocks actually say. Read the two together, print this one, and keep it in the incident binder — because at hour six of a real incident nobody is going to read prose.

Four warnings before the table.

This is not legal advice, and it is not a compliance opinion. This appendix summarises notification obligations across a dozen regimes to help you build a response process. It is a starting point for a conversation with counsel, not a substitute for one. Deadlines change, national transpositions differ, sector rules layer on top, and the facts of your incident determine which clocks actually run. Confirm the ones that apply to your footprint with a lawyer — and do that before the incident, not on the day a clock is already running.

The deadline is the easy part. Almost every clock below runs from a subjective state — "aware," "determines," "reasonably believes," "discovers." Those states arise at different moments, they diverge by days, and the only evidence of when each one arose is your contemporaneous log. Column five is the column that gets organizations fined.

A regime is not a row. NIS2 is twenty-seven national laws in a trench coat, and four Member States were referred to the Court of Justice on 8 July 2026 for not having written theirs yet (EC, ). Where a row says "EU," you still need a per-country portal, threshold and language.

Cells marked † are second-hand. They are drawn from law-firm or survey reporting rather than from the operative legal text, and the verification notes at the end of section C.8 say exactly what is unconfirmed about each. Do not put a † figure in front of a regulator or a board without checking it first.


#C.1 The matrix — European Union

RegimeApplies toTriggerDeadlineClock starts atNotify whomPenalty exposure
GDPR Art. 33Controllers processing personal data in GDPR scope (processors owe a separate duty to the controller)Personal data breach that is not "unlikely to result in a risk" to rights and freedomsWithout undue delay, not later than 72 hours; if later, reasons for the delay are a required elementController becomes aware — a reasonable degree of certainty that a security incident compromised personal dataCompetent supervisory authority (lead SA under one-stop-shop)Art. 83(4): up to €10m or 2% of global turnover, higher applies. Late notification is a standalone infringement
GDPR Art. 34SameBreach likely to result in a high risk to rights and freedomsWithout undue delay (no fixed hour count)Same awareness pointAffected data subjects directly; public communication permitted where individual notice is disproportionate effortAs above. Exemptions: data rendered unintelligible (e.g. strong encryption), or subsequent measures eliminate the high risk
NIS2 — early warningEssential and important entities in Annex I/II sectors, as transposed by each Member StateBecoming aware of a significant incident (severe operational disruption or financial loss, or considerable damage to others)24 hoursBecoming awareNational CSIRT or competent authorityArt. 34 floors: essential ≥ €10m or 2%; important ≥ €7m or 1.4% †. Member States may exceed. Management bodies personally liable and temporarily barrable
NIS2 — incident notificationSameSame incident72 hoursBecoming aware (not from the early warning)SameAs above
NIS2 — final reportSameSame incidentOne month after the incident notification; if still ongoing at one month, a progress report then and a final report one month after the incident is handledThe 72-hour incident notificationSameAs above
DORA — initial~20 categories of financial entity plus designated critical ICT third-party providersClassification of an ICT-related incident as major under the RTS criteria4 hours from classification as major, and in any event no later than 24 hours from becoming awareTwo-part: classification, capped by awarenessNational competent authority (single designated addressee; significant credit institutions file nationally, NCA transmits to the ECB)No harmonized EU ceiling for financial entities — Art. 50 leaves amounts to Member States and they diverge widely †. The 1% of average daily worldwide turnover periodic penalty applies only to designated critical ICT third-party providers under Art. 35
DORA — intermediateSameSame incident72 hours after the initial notification, plus an updated report without undue delay once regular activities are recoveredSubmission of the initial notificationSameAs above
DORA — finalSameSame incidentOne month after the intermediate (or latest updated intermediate) reportThe intermediate reportSameAs above
DORA — weekend reliefSameAny of the aboveDeadline falling on a weekend or bank holiday moves to noon the next working dayexcept for entities identified as significant/essential by the competent authority
CRA Art. 14 — early warningManufacturers of products with digital elements placed on the EU market, wherever establishedAwareness of an actively exploited vulnerability in the product, or a severe incident affecting product security24 hoursapplies from 11 September 2026Becoming aware (reasonable degree of certainty of active exploitation / severe incident)Designated coordinator CSIRT and ENISA simultaneously, via the CRA Single Reporting PlatformArt. 64: breach of Annex I essential requirements or of Arts. 13–14 — up to €15m or 2.5% of global turnover †; other operator obligations €10m/2%; false or misleading information to a market surveillance authority €5m/1%
CRA Art. 14 — notificationSameSame72 hoursBecoming awareSameAs above
CRA Art. 14 — final reportSameSameActively exploited vulnerability: 14 days after a corrective or mitigating measure becomes available. Severe incident: one month after the 72-hour notificationThe measure becoming available / the 72-hour notificationSameAs above
EU AI Act Art. 55 (GPAI)Providers of general-purpose AI models with systemic riskSerious incident, per Art. 55 obligations"Without undue delay" — the Regulation sets no hour count. A 72-hour figure circulates; it appears to come from the GPAI Code of Practice, not the Regulation †AwarenessThe AI Office (Commission enforcement powers over GPAI since 2 Aug 2026)Art. 99: provider/deployer obligations tier up to €15m or 3%; incorrect or misleading information to authorities €7.5m/1%
EU AI Act Art. 73 (high-risk)Providers of high-risk AI systems; deployers inform the providerSerious incident under Art. 3(49) once a causal link, or reasonable likelihood of one, is establishedNOT YET IN FORCE. Deferred by Regulation (EU) 2026/1744 to 2 Dec 2027 (standalone Annex III) and 2 Aug 2028 (AI embedded in Annex I regulated products) †. When live: 15 days generally; 2 days for widespread infringement or serious and irreversible disruption of critical infrastructure; 10 days for deathEstablishing the causal link / becoming awareMarket surveillance authority of the Member State where the incident occurredArt. 99 tiers as above

#C.2 The matrix — United States, federal

RegimeApplies toTriggerDeadlineClock starts atNotify whomPenalty exposure
SEC Item 1.05, Form 8-KSEC reporting companies (6-K analogue for foreign private issuers)The registrant determines a cybersecurity incident is materialFour business days. The determination itself must be made "without unreasonable delay" after discoveryThe materiality determinationnot discoveryFiled publicly with the SECExchange Act §13(a) reporting violations, Rule 13a-15 disclosure controls, §10(b)/Rule 10b-5 if the disclosure is materially false or misleading
SEC Item 1.05 delaySameDelay permitted only where the U.S. Attorney General determines disclosure poses a substantial risk to national security or public safety and notifies the Commission in writingOrdinary law-enforcement convenience does not open this door
SEC Item 106, Reg S-KSameAnnual filingWith the 10-KFiscal year endFiled publiclyProcesses for assessing, identifying and managing material cyber risk; material or reasonably likely material effects; board oversight and management's role. Inline XBRL tagging since FYs ending on/after 15 Dec 2024
CIRCIA — covered incidentCovered entities across the 16 critical infrastructure sectors (CISA estimated >300,000 under the NPRM)A covered cyber incident — substantial loss of C/I/A, serious impact on operational safety and resiliency, disruption of business or industrial operations, or unauthorized access via a third party/supply chain or nation-state actorNOT IN FORCE. Statutory clock will be 72 hours; reporting to CISA is voluntary todayWill run from the entity reasonably believing the incident occurredCISA (web form / CIRCIA portal)Once live: Request for Information → subpoena → DOJ referral; 18 U.S.C. §1001 false-statements exposure; contract and suspension/debarment consequences for federal contractors
CIRCIA — ransom paymentSameA ransom payment is disbursed — including where the underlying incident is not itself reportableNOT IN FORCE. Statutory clock will be 24 hoursWill run from disbursement of the paymentCISAAs above
HIPAA — individualsCovered entities and business associatesDiscovery of a breach of unsecured PHI. Breach is presumed unless a four-factor risk assessment shows low probability of compromiseWithout unreasonable delay, no later than 60 calendar daysDiscovery — the first day the breach is known, or would have been known by reasonable diligence, to any workforce member other than the person who committed itAffected individualsTiered civil money penalties (unknowing → willful neglect uncorrected), inflation-adjusted, plus resolution agreements and multi-year corrective action plans; state AGs may sue under HITECH
HIPAA — HHS/OCR, 500+Same500 or more individuals affectedContemporaneously with individual notice, no later than 60 calendar daysDiscoveryHHS Office for Civil Rights, via the OCR breach portalAs above
HIPAA — HHS/OCR, under 500SameFewer than 500 individualsAnnual log, within 60 days after the end of the calendar year in which discovery occurredEnd of the calendar year of discoveryHHS OCRAs above
HIPAA — mediaSame500+ residents of a single state or jurisdiction — counted by residence, not by your locationWithin 60 days of discoveryDiscoveryProminent media serving that state or jurisdictionAs above
HIPAA — BA to CEBusiness associatesDiscovery of a breachWithout unreasonable delay, no later than 60 daysyour BAA has almost certainly shortened this to 5–15 daysDiscoveryThe covered entityContractual, plus direct HIPAA liability
FCC — agency noticeTelecommunications carriers, interconnected VoIP and TRS providersBreach of CPNI or customer PII, inadvertent as well as intentionalAs soon as practicable, no later than seven (7) business daysReasonable determination that a breach occurredThe Commission and federal law enforcement (FBI and Secret Service) via the FCC central reporting facility. The 500-customer figure operates as the threshold for the full law-enforcement path †FCC enforcement; amounts not stated in the sourced material. Rules upheld by the Sixth Circuit 13–14 August 2025 in Ohio Telecom Ass'n v. FCC; rehearing en banc litigated into July 2026 — contested but operative
FCC — customer noticeSameSameAs soon as practicable after notifying the Commission and law enforcement, no later than 30 days. The old mandatory 7-day waiting period before customer notice was eliminatedReasonable determinationAffected customersHarm-based exception where no harm is reasonably likely (e.g. encrypted data). Law enforcement may direct delay for an initial period of up to 30 days, extendable
DFARS 252.204-7012 (CMMC estate)Contractors and subcontractors handling CUI — flows downA cyber incident affecting covered defense information or the contractor's ability to perform72 hoursDiscoveryDoD at https://dibnet.dod.milContract non-award or termination; False Claims Act liability via DOJ's Civil Cyber-Fraud Initiative for false compliance affirmations. Also requires 90-day media preservation and malicious-software submission
CMMC programDoD contractors, phasing inSolicitation and award requirements, not incident reportingPhase 1: 10 Nov 2025 – 10 Nov 2026 — Level 1 and Level 2 self-assessment in selected solicitations at the Program Office's discretion, phasing DoD-wide over three yearsContract awardAs above. The 32 CFR rule was effective 16 Dec 2024; the 48 CFR acquisition rule took effect 10 Nov 2025
TSA Security DirectivesTSA-designated pipeline and rail owner/operatorsIdentification of a cybersecurity incident24 hours — live today under the directives, ratified in a Federal Register notice of 17 January 2025IdentificationCISATSA enforcement under the directive regime; amounts not stated in the sourced material. Directives also require a 24/7 Cybersecurity Coordinator, an IR plan and an annual assessment
PCI DSS v4.0.1Entities storing, processing or transmitting cardholder data, and those affecting its securitySuspected or confirmed compromise of cardholder dataPCI DSS itself sets no external clock. Req. 12.10.1 requires the IR plan to define notification of payment brands and acquirers; the brands' own programs govern timing — in practice immediately on suspected compromisePer brand programAcquirer and payment brands; a PFI forensic investigation may be compelledContractual, not regulatory: brand and acquirer fines, per-card assessments, forensic and reissuance costs, escalated merchant level, and at worst loss of card acceptance

#C.3 The matrix — US state breach notification

All 50 states plus DC, Puerto Rico, Guam and the US Virgin Islands. The shape is consistent even where the numbers are not.

RegimeApplies toTriggerDeadlineClock starts atNotify whomPenalty exposure
General shapeAny entity holding personal information on residents of that stateUnauthorized acquisition (in most states, not merely access) of usually-unencrypted, usually-computerized personal information — name plus SSN, driver's license or financial account, with most states now adding medical, health-insurance, biometric and online-account credentialsVaries: 30, 45 or 60 days, or "the most expedient time, without unreasonable delay"Usually discovery; some states run from confirmation of the breachIndividuals; above a threshold (typically 500 or 1,000 residents) the state AG and the consumer reporting agencies. Substitute notice permitted above cost/volume thresholdsState AG enforcement; penalty structure varies by state and is not summarized in the sourced material. Most states carry an encryption safe harbour and a risk-of-harm exception
Puerto Rico (Act 111)Entities holding PR residents' dataAs above10 daysnon-extendable, and the shortest in the US. DACO makes a public announcement within 24 hoursDetectionDACO (Departamento de Asuntos del Consumidor)As above
VermontEntities holding VT residents' dataAs above14 business days to the AG; 45 days to individualsDiscoveryAG, then individualsAs above †
California (SB 446)Entities holding CA residents' dataAs above30 calendar days to residents; sample notice to the AG within 15 calendar days of notifying consumers where >500 California residents are affected. Approved 3 Oct 2025, operative for 2026DiscoveryResidents, then the AGAs above
New York (S2659B / S2376B)Entities holding NY residents' dataAs above; "private information" now includes medical and health-insurance information (from 21 Mar 2025)Hard 30 days to individuals (from 21 Dec 2024), replacing "most expedient time possible"; vendors must notify the data owner within 30 daysDiscoveryIndividuals, AG, and — added by S2659B — DFSAs above
TexasEntities holding TX residents' dataAs above30 days to individuals; 30 days to the AG at 250+ residents — one of the lowest AG thresholds in the countryDiscoveryIndividuals and AGAs above
Colorado, Florida, Maine, WashingtonResidents of those statesAs above30 daysDiscovery †Individuals; AG above thresholdAs above †
Federal-compliance deemingHIPAA covered entities, GLBA-regulated entitiesMany states deem compliance with the federal rule as satisfying the state rule — but not all, and frequently not for the AG noticeCheck state by state; do not assume the deeming clause covers the regulator leg

#C.4 The matrix — United Kingdom

RegimeApplies toTriggerDeadlineClock starts atNotify whomPenalty exposure
UK GDPR / DPA 2018Controllers in UK scopePersonal data breach, unless unlikely to result in a risk to rights and freedoms72 hours; reasons required if late. Data subjects without undue delay where high riskBecoming awareICO online form, or the 24-hour helplineHigher tier £17.5m or 4% of global turnover; Art. 33/34 failures sit in the lower £8.7m / 2% tier
NIS Regulations 2018Operators of essential services and relevant digital service providersIncident with a significant or substantial impact on service continuity72 hoursBecoming awareRelevant competent authority; the ICO is the competent authority for RDSPsNot stated in the sourced material
PECRTelecoms and ISPsPersonal data breach72 hours — moved from 24 hours on 20 August 2025, aligning with UK GDPRBecoming awareICONot stated in the sourced material
Cyber Security and Resilience BillWould add medium and large data centres (Ofcom) and medium and large managed service providers (Information Commission), plus load controllers and designated critical suppliersNOT LAW. Would introduce 24-hour initial notification / 72-hour full report to the regulator with simultaneous NCSC notification, plus a customer-notification duty on data centres and digital/MSP providersRegulator plus NCSCReported at £10m/2% standard and £17m/4% higher tier with daily fines up to £100k † — figures unconfirmed. Treat as a 2027–28 readiness item, not a live clock

#C.5 The matrix — sector-specific and Australia

RegimeApplies toTriggerDeadlineClock starts atNotify whomPenalty exposure
NYDFS Part 500 §500.17(a)NYDFS covered entitiesA cybersecurity incident at the covered entity, its affiliates, or a third-party service providerAs promptly as possible, no later than 72 hoursDetermining that a cybersecurity incident has occurredThe Superintendent, with a continuing duty to report material changes and provide requested informationNYDFS enforcement under the Banking, Insurance and Financial Services Laws; each day of non-compliance and each failed requirement can be treated as a separate violation
NYDFS §500.17(c)SameMaking an extortion payment24 hours from the payment, plus a 30-day written description of why payment was necessary, alternatives considered, diligence on alternatives, and sanctions/OFAC diligenceMaking the paymentThe SuperintendentAs above
NYDFS §500.17(b)SameAnnual cycle15 April each year — certification of material compliance, or written acknowledgement of non-compliance with a remediation planCalendar year endThe Superintendent, signed by the highest-ranking executive and the CISO; supporting documentation retained 5 yearsAs above. The final Second Amendment phase took effect 1 Nov 2025 (MFA for any individual accessing any information system; documented asset inventory), first certified against on 15 April 2026
Australia — ransomware payment reportingA "reporting business entity": carrying on business in Australia with annual turnover ≥ AUD 3m, or a responsible entity for a SOCI critical infrastructure asset regardless of turnoverMaking, or another entity making on your behalf, a ransomware or cyber extortion payment — any benefit, no minimum threshold72 hours. In force since 30 May 2025Making the payment, or becoming aware that it was made on your behalfAustralian Signals Directorate via the ACSC portal (Home Affairs is joint recipient)Civil penalty up to 60 penalty units (~AUD 19,800) — deliberately modest; the policy aim is visibility, not deterrence
Australia — SOCI Act Part 2BResponsible entities for critical infrastructure assetsMandatory cyber incident reporting12 hours for a critical incident (significant impact on the availability of an essential service); 72 hours for a relevant incident †Awareness †ASD / ACSCNot stated in the sourced material. 12 hours would be the tightest clock in this appendix — verify before encoding

#C.6 First 24 hours — the facts that decide which clocks are running

Work these in parallel, not in sequence. With 12- and 24-hour clocks in play, a serial process fails by construction — you will still be establishing fact 3 when clock 1 expires.

Before anything else, two housekeeping actions that everything downstream depends on. Start a written timeline immediately, recording to the minute what was known, by whom, at each point. Engage counsel before the first substantive assessment so privilege attaches to the investigation, and appoint one named notification owner distinct from the Incident Commander.

#Fact to establishWhy it decides a clockClocks it can start
1Do we have a reasonable degree of certainty that a security incident occurred?This is the "awareness" state most EU clocks run from. Record the moment it arose and who held itGDPR, UK GDPR, NIS2, DORA 24h cap, CRA
2Does it involve personal data, and whose?Splits the personal-data path from the operational-disruption pathGDPR 33/34, UK GDPR, US state laws
3Is any of it PHI, cardholder data, or CUI?Each pulls in a separate regime with its own recipientHIPAA, PCI brand programs, DFARS §7012
4Where do the affected individuals reside?US state law counts by residency, not by your location. This is what surfaces the 10-day Puerto Rico and 14-business-day Vermont carve-outsAll state laws; HIPAA media notice
5Which of our regulated legal entities and services is affected?NIS2, DORA and NYDFS bind entities, not incidents. Map to the entity, then to its Member State or regulatorNIS2, DORA, NYDFS, TSA, UK NIS
6Is one of our products, in customers' hands, implicated — and is a vulnerability in it being actively exploited?Entirely separate trigger from a compromise of your estate, and tighterCRA Art. 14 (from 11 Sept 2026)
7Is there an extortion demand, and has or will a payment be made?The payment clocks are triggered by a business decision, not by the attack, and they are the tightest in the bookNYDFS 24h, Australia 72h, CIRCIA 24h once live
8Are we a public company, and what does the disclosure committee need to reach a materiality view?Item 1.05 runs from determination, but the determination cannot be deferred indefinitelySEC Item 1.05
9Is an AI system involved, and is it a GPAI model with systemic risk or an Annex III high-risk system?One duty is live today; the other is notAI Act Art. 55 (live); Art. 73 (deferred)
10Are we the processor, business associate or vendor here — or the customer?Contractual clocks are usually shorter than statutory ones, and they are the ones actually missedBAAs, MSAs, insurer notice, DFARS flow-down

Capture four distinct timestamps per incident, because one "incident start" field cannot carry all of them: (a) awareness — GDPR, NIS2, CRA; (b) reasonable belief — CIRCIA; (c) determination that an incident occurred — NYDFS; (d) determination of materiality — SEC. They diverge by days, and the gap between them is the first thing an investigator will ask you to explain.

Then fire the sub-24-hour tier, tightest first: SOCI critical (12h) † → DORA initial (4h from classification, 24h hard cap) → CRA early warning (24h, from 11 Sept 2026) → NIS2 early warning (24h) → TSA (24h) → NYDFS extortion payment (24h from disbursement).

Actionable takeaway: file incomplete rather than late. GDPR, NIS2, DORA, CRA and the AI Act all expressly contemplate phased or incomplete initial reports. A 24-hour early warning that says "we are investigating, cause unknown, cross-border impact possible" is compliant. Silence is not.


#C.7 When two regimes want different things

ConflictWhat happensWhat to do
Speed vs. accuracyThe 24-hour early warnings fall due long before forensics can support a four-business-day SEC narrative or a characterized GDPR Art. 33 report. Anything you tell a CSIRT at hour 24 can be quoted back at you in securities litigationMaintain two templates: a regulator-facing factual early warning explicitly framed as preliminary and subject to change, and a separate disclosure-committee record. No technical team files a regulatory early warning without disclosure-counsel review of the wording
Awareness vs. determinationGDPR, NIS2 and CRA run from awareness; SEC from materiality determination; CIRCIA from reasonable belief; NYDFS from determination that an incident occurredFour timestamp fields, populated by the Scribe, reviewed by the Legal Liaison
Disclosure vs. investigationYou can be legally required to disclose on Form 8-K while the FBI is asking you to hold customer notice. SEC delay needs an Attorney General national-security determination — a narrow door not available for law-enforcement convenience. FCC, HIPAA and most state laws do permit law-enforcement-directed delayEscalate to counsel the moment law enforcement is engaged. Do not let the FBI relationship silently override a securities obligation
NIS2 fragmentation"The NIS2 72-hour deadline" is not one deadline. Portals, thresholds, languages and registration duties differ, and some Member States impose shorter national timelines or additional recipientsA per-country contact-and-portal matrix maintained by local counsel, refreshed quarterly
Triple reporting for one eventRansomware on an EU bank that exfiltrates customer PII and involves a payment can trigger DORA 4h/24h, NIS2 24h, GDPR 72h, national CSIRT rules, NYDFS 72h plus 24h payment, SEC 8-K, multiple state AGs, and Australian reporting if there are AU operationsAssume duplication. The EU Digital Omnibus single-entry-point proposal exists precisely to fix this and is not law
Contractual clocks beat regulatory onesBAAs routinely compress HIPAA's 60 days to 5–15. Cyber policies require notice "as soon as practicable" and can deny coverage for late notice. Customer MSAs increasingly demand 24–48 hours. DFARS §7012 flows down to subcontractorsThese are the deadlines you actually miss. Inventory them into the playbook alongside the statutes, with the same clock discipline
HIPAA vs. state law60 days is not a safe harbour; more stringent state laws are not preemptedRun the state clock, not the federal one

#C.8 Status watchlist — genuinely in flux as of 5 September 2026

Nothing in this section is a live obligation. Everything in it could become one.

ItemStatusWhat to monitor
CIRCIA final ruleNot published. CISA missed the statutory Oct 2025 deadline, targeted May 2026, slipped again; the July 2026 Unified Agenda preview sets a September 2026 target. Town halls held 15–18 June 2026. Reporting is voluntary todayThe Federal Register public inspection desk — this could land within days of this book going to press. Build the 72h/24h capability now; the clocks are statutory, short, and will not wait for you
SEC Item 1.05In force. Rescission has been requested, not proposed and not adopted. Chair Atkins launched a Reg S-K review on 13 Jan 2026 (comments due 13 Apr 2026); rescission or reform of Item 1.05 was reportedly among the most frequently requested changes †SEC rulemaking activity listings. Keep the four-business-day machinery intact
GDPR 96-hour proposalThe Digital Omnibus proposes moving Art. 33 to 96 hours, raising the threshold to high risk, and routing notice through a single ENISA-operated entry point. Pending in the European Parliament; committee amendments recorded 27 July 2026; adoption not expected before late 2026, may slip to 2027Keep 72 hours in the playbook until it is in the Official Journal
NIS2 transpositionIncomplete. Ireland, Spain, France and the Netherlands referred to the CJEU on 8 July 2026. The Netherlands' Cyberbeveiligingswet in force ~15 Aug 2026; Ireland expects to notify by end-2026; France and Spain still legislatingPer-country status via the ECSO tracker and the Commission's infringement register. Where a state has not transposed, the directive is not directly effective against private entities — but the old NIS1 national law may still catch you
EU AI Act Art. 73Deferred by Regulation (EU) 2026/1744 (in force 27 July 2026) to 2 Dec 2027 / 2 Aug 2028 †. Art. 5 prohibited practices, GPAI obligations including Art. 55 incident reporting, and Art. 50 transparency remain liveThe operative amending article of Reg. 2026/1744 for the precise scope of the deferral, and the Commission's draft guidance and reporting template for serious AI incidents
UK Cyber Security and Resilience BillIn the Lords. Commons stages cleared; Lords Second Reading 14 July 2026; Grand Committee began 1 September 2026. Royal Assent expected late 2026, but substantive effect comes via secondary legislation after a 2026 implementation consultation — realistically 2027–2028Bill stages and the implementation consultation. Do not encode the 24/72 duty as live
HIPAA Security Rule overhaulNPRM published 6 Jan 2025, >4,000 comments, not finalized. Unified Agenda now targets July 2027, pushed back from spring 2026. 100+ hospital and provider groups have asked HHS to withdraw itThe Unified Agenda. OCR enforces the existing Security Rule; nothing in the NPRM is enforceable today
TSA surface cyber rule"Enhancing Surface Cyber Risk Management" NPRM published 7 Nov 2024, comments closed 5 Feb 2025. Final rule not issued. The Security Directives remain the operative lawFederal Register. The 24-hour directive clock is live today regardless
FCC breach rulesIn effect and contested. Sixth Circuit upheld them 13–14 Aug 2025; rehearing en banc litigated through July 2026Sixth Circuit docket. Comply in the meantime
PCI DSS next versionv4.0.1 is the only active version. A Request for Comments reportedly ran 3 June – 20 July 2026 following a Dec 2025 RFC cycle †PCI SSC document library. Plan for v4.0.1 through 2026–27

#Cells marked † — what is unconfirmed


#C.9 Keeping this table alive

This appendix has a half-life, and it is shorter than the book's. Four of the ten watchlist rows could move inside a single quarter, and one of them — CIRCIA — was targeted at the very month this was verified.

Treat it as an asset with an owner, the same way you treat a detection rule. Concretely:

  1. Name an owner. The Legal Liaison role owns this table. Not "Legal." A role, on a page, with a named backup.
  2. Re-verify quarterly, and additionally within five business days of any incident that touched a regime here — you will have just learned something the table did not say.
  3. Verify against primary sources, in this order of preference: the Official Journal / EUR-Lex, the Federal Register and eCFR, the regulator's own guidance page, then law-firm commentary. Everything in the verification notes at the end of C.8 exists because that ladder was climbed and the top rung was out of reach.
  4. Version the file and record the verification date in the header, as this one does. A matrix with no date on it is worse than no matrix, because someone will trust it.
  5. Maintain the per-country NIS2 annex separately, refreshed by local counsel, because it will drift faster than anything else here.
  6. Inventory your contractual clocks into the same table. Your BAAs, MSAs, insurer notice conditions and DFARS flow-downs are not law, and they will still be the first deadlines you miss.

The regulators are not going to slow down to let your documentation catch up. Date it, own it, re-check it — and never let a table older than a quarter be the thing standing between you and a filing deadline.


#Sources

  1. Art. 33 GDPR
  2. EDPB Guidelines 9/2022 v2.0 on personal data breach notification (PDF)
  3. Directive (EU) 2022/2555 (NIS2), EUR-Lex
  4. NIS2 Article 34 — penalties
  5. European Commission — Commission calls on 23 Member States to fully transpose NIS2
  6. Regulation (EU) 2022/2554 (DORA), EUR-Lex
  7. Commission Delegated Regulation (EU) 2025/301 — major incident reporting RTS
  8. DLA Piper — divergence in administrative penalties under DORA
  9. European Commission — CRA reporting obligations
  10. Regulation (EU) 2024/2847 (Cyber Resilience Act), EUR-Lex
  11. CRA Article 64 — penalties
  12. DLA Piper — the CRA's 24-hour rule
  13. EU AI Act Article 73
  14. EU AI Act Article 55
  15. EU AI Act Article 99 — penalties
  16. Gibson Dunn — AI Act Omnibus and postponed high-risk deadlines
  17. European Commission — draft guidance and template for serious AI incident reporting
  18. Bird & Bird — Digital Omnibus and a single EU incident reporting regime
  19. SEC press release 2023-139 — cybersecurity disclosure rules
  20. SEC small-entity compliance guide — cybersecurity risk management and incident disclosure
  21. SEC rulemaking activity, 2026
  22. Sidley — SEC Chair Atkins announces Regulation S-K reform initiative
  23. CISA — CIRCIA
  24. CIRCIA NPRM, 89 FR (4 April 2024)
  25. Hunton — CISA plans to finalize CIRCIA regulations in September 2026
  26. HHS — HIPAA Breach Notification Rule
  27. HHS OCR breach portal
  28. HIPAA Journal — Security Rule update postponed
  29. PCI SSC — adopting the future-dated requirements of PCI DSS v4.x
  30. PCI SSC — responding to a data breach
  31. PCI SSC document library
  32. Privacy Rights Clearinghouse — Data Breach Notification Laws 50-State Survey, 2026 edition
  33. California SB 446 — leginfo.ca.gov
  34. Hunton — New York data breach notification law updated
  35. Perkins Coie — 2025 breach notification law update
  36. ICO — personal data breaches: a guide
  37. ICO — 72 hours: how to respond to a personal data breach
  38. ICO — NIS incident reporting
  39. UK Parliament — Cyber Security and Resilience Bill (Bill 4035)
  40. gov.uk — summary of the Cyber Security and Resilience Bill
  41. 23 NYCRR 500.17 (Cornell LII)
  42. NYDFS — how to report an extortion payment (PDF)
  43. Federal Register — FCC Data Breach Reporting Requirements, 89 FR (12 February 2024)
  44. FCC Report and Order FCC 23-111 (PDF)
  45. Cooley — Sixth Circuit upholds FCC data breach reporting rules
  46. Federal Register — TSA Enhancing Surface Cyber Risk Management NPRM
  47. Federal Register — Ratification of Security Directives (17 January 2025)
  48. Federal Register — 48 CFR CMMC final rule (10 September 2025)
  49. DoD CIO — CMMC
  50. Australian Government Home Affairs — ransomware payment reporting factsheet (PDF)
  51. cyber.gov.au — report a ransomware payment
This page is one chapter of The 2026 InfoSec Playbook, a free field manual by Daniel Ramos. Checklist statuses and the live coverage model are in the full manual. Free, in full, no email wall.