Every notification clock this book covers, in one table — who it binds, what starts it, when it expires, who receives it, and what it costs to miss.
Who needs this: Legal Liaison, Incident Commander, DPO, Communications Lead, CISO, Compliance | Read time: 15 min | Maps to: CSF 2.0 RESPOND (RS.CO), GOVERN (GV.OC-03) | Verified as of: 5 September 2026 | Owns: the reference table; Chapter 15 owns the process and the privilege guidance, Playbook 14.7 owns the determination sequence
This is a reference, not a chapter. Chapter 15 tells you how to run the notification track; this tells you what the clocks actually say. Read the two together, print this one, and keep it in the incident binder — because at hour six of a real incident nobody is going to read prose.
Four warnings before the table.
This is not legal advice, and it is not a compliance opinion. This appendix summarises notification obligations across a dozen regimes to help you build a response process. It is a starting point for a conversation with counsel, not a substitute for one. Deadlines change, national transpositions differ, sector rules layer on top, and the facts of your incident determine which clocks actually run. Confirm the ones that apply to your footprint with a lawyer — and do that before the incident, not on the day a clock is already running.
The deadline is the easy part. Almost every clock below runs from a subjective state — "aware," "determines," "reasonably believes," "discovers." Those states arise at different moments, they diverge by days, and the only evidence of when each one arose is your contemporaneous log. Column five is the column that gets organizations fined.
A regime is not a row. NIS2 is twenty-seven national laws in a trench coat, and four Member States were referred to the Court of Justice on 8 July 2026 for not having written theirs yet (EC, ). Where a row says "EU," you still need a per-country portal, threshold and language.
Cells marked † are second-hand. They are drawn from law-firm or survey reporting rather than from the operative legal text, and the verification notes at the end of section C.8 say exactly what is unconfirmed about each. Do not put a † figure in front of a regulator or a board without checking it first.
| Regime | Applies to | Trigger | Deadline | Clock starts at | Notify whom | Penalty exposure |
|---|---|---|---|---|---|---|
| GDPR Art. 33 | Controllers processing personal data in GDPR scope (processors owe a separate duty to the controller) | Personal data breach that is not "unlikely to result in a risk" to rights and freedoms | Without undue delay, not later than 72 hours; if later, reasons for the delay are a required element | Controller becomes aware — a reasonable degree of certainty that a security incident compromised personal data | Competent supervisory authority (lead SA under one-stop-shop) | Art. 83(4): up to €10m or 2% of global turnover, higher applies. Late notification is a standalone infringement |
| GDPR Art. 34 | Same | Breach likely to result in a high risk to rights and freedoms | Without undue delay (no fixed hour count) | Same awareness point | Affected data subjects directly; public communication permitted where individual notice is disproportionate effort | As above. Exemptions: data rendered unintelligible (e.g. strong encryption), or subsequent measures eliminate the high risk |
| NIS2 — early warning | Essential and important entities in Annex I/II sectors, as transposed by each Member State | Becoming aware of a significant incident (severe operational disruption or financial loss, or considerable damage to others) | 24 hours | Becoming aware | National CSIRT or competent authority | Art. 34 floors: essential ≥ €10m or 2%; important ≥ €7m or 1.4% †. Member States may exceed. Management bodies personally liable and temporarily barrable |
| NIS2 — incident notification | Same | Same incident | 72 hours | Becoming aware (not from the early warning) | Same | As above |
| NIS2 — final report | Same | Same incident | One month after the incident notification; if still ongoing at one month, a progress report then and a final report one month after the incident is handled | The 72-hour incident notification | Same | As above |
| DORA — initial | ~20 categories of financial entity plus designated critical ICT third-party providers | Classification of an ICT-related incident as major under the RTS criteria | 4 hours from classification as major, and in any event no later than 24 hours from becoming aware | Two-part: classification, capped by awareness | National competent authority (single designated addressee; significant credit institutions file nationally, NCA transmits to the ECB) | No harmonized EU ceiling for financial entities — Art. 50 leaves amounts to Member States and they diverge widely †. The 1% of average daily worldwide turnover periodic penalty applies only to designated critical ICT third-party providers under Art. 35 |
| DORA — intermediate | Same | Same incident | 72 hours after the initial notification, plus an updated report without undue delay once regular activities are recovered | Submission of the initial notification | Same | As above |
| DORA — final | Same | Same incident | One month after the intermediate (or latest updated intermediate) report | The intermediate report | Same | As above |
| DORA — weekend relief | Same | Any of the above | Deadline falling on a weekend or bank holiday moves to noon the next working day — except for entities identified as significant/essential by the competent authority | — | — | — |
| CRA Art. 14 — early warning | Manufacturers of products with digital elements placed on the EU market, wherever established | Awareness of an actively exploited vulnerability in the product, or a severe incident affecting product security | 24 hours — applies from 11 September 2026 | Becoming aware (reasonable degree of certainty of active exploitation / severe incident) | Designated coordinator CSIRT and ENISA simultaneously, via the CRA Single Reporting Platform | Art. 64: breach of Annex I essential requirements or of Arts. 13–14 — up to €15m or 2.5% of global turnover †; other operator obligations €10m/2%; false or misleading information to a market surveillance authority €5m/1% |
| CRA Art. 14 — notification | Same | Same | 72 hours | Becoming aware | Same | As above |
| CRA Art. 14 — final report | Same | Same | Actively exploited vulnerability: 14 days after a corrective or mitigating measure becomes available. Severe incident: one month after the 72-hour notification | The measure becoming available / the 72-hour notification | Same | As above |
| EU AI Act Art. 55 (GPAI) | Providers of general-purpose AI models with systemic risk | Serious incident, per Art. 55 obligations | "Without undue delay" — the Regulation sets no hour count. A 72-hour figure circulates; it appears to come from the GPAI Code of Practice, not the Regulation † | Awareness | The AI Office (Commission enforcement powers over GPAI since 2 Aug 2026) | Art. 99: provider/deployer obligations tier up to €15m or 3%; incorrect or misleading information to authorities €7.5m/1% |
| EU AI Act Art. 73 (high-risk) | Providers of high-risk AI systems; deployers inform the provider | Serious incident under Art. 3(49) once a causal link, or reasonable likelihood of one, is established | NOT YET IN FORCE. Deferred by Regulation (EU) 2026/1744 to 2 Dec 2027 (standalone Annex III) and 2 Aug 2028 (AI embedded in Annex I regulated products) †. When live: 15 days generally; 2 days for widespread infringement or serious and irreversible disruption of critical infrastructure; 10 days for death | Establishing the causal link / becoming aware | Market surveillance authority of the Member State where the incident occurred | Art. 99 tiers as above |
| Regime | Applies to | Trigger | Deadline | Clock starts at | Notify whom | Penalty exposure |
|---|---|---|---|---|---|---|
| SEC Item 1.05, Form 8-K | SEC reporting companies (6-K analogue for foreign private issuers) | The registrant determines a cybersecurity incident is material | Four business days. The determination itself must be made "without unreasonable delay" after discovery | The materiality determination — not discovery | Filed publicly with the SEC | Exchange Act §13(a) reporting violations, Rule 13a-15 disclosure controls, §10(b)/Rule 10b-5 if the disclosure is materially false or misleading |
| SEC Item 1.05 delay | Same | — | Delay permitted only where the U.S. Attorney General determines disclosure poses a substantial risk to national security or public safety and notifies the Commission in writing | — | — | Ordinary law-enforcement convenience does not open this door |
| SEC Item 106, Reg S-K | Same | Annual filing | With the 10-K | Fiscal year end | Filed publicly | Processes for assessing, identifying and managing material cyber risk; material or reasonably likely material effects; board oversight and management's role. Inline XBRL tagging since FYs ending on/after 15 Dec 2024 |
| CIRCIA — covered incident | Covered entities across the 16 critical infrastructure sectors (CISA estimated >300,000 under the NPRM) | A covered cyber incident — substantial loss of C/I/A, serious impact on operational safety and resiliency, disruption of business or industrial operations, or unauthorized access via a third party/supply chain or nation-state actor | NOT IN FORCE. Statutory clock will be 72 hours; reporting to CISA is voluntary today | Will run from the entity reasonably believing the incident occurred | CISA (web form / CIRCIA portal) | Once live: Request for Information → subpoena → DOJ referral; 18 U.S.C. §1001 false-statements exposure; contract and suspension/debarment consequences for federal contractors |
| CIRCIA — ransom payment | Same | A ransom payment is disbursed — including where the underlying incident is not itself reportable | NOT IN FORCE. Statutory clock will be 24 hours | Will run from disbursement of the payment | CISA | As above |
| HIPAA — individuals | Covered entities and business associates | Discovery of a breach of unsecured PHI. Breach is presumed unless a four-factor risk assessment shows low probability of compromise | Without unreasonable delay, no later than 60 calendar days | Discovery — the first day the breach is known, or would have been known by reasonable diligence, to any workforce member other than the person who committed it | Affected individuals | Tiered civil money penalties (unknowing → willful neglect uncorrected), inflation-adjusted, plus resolution agreements and multi-year corrective action plans; state AGs may sue under HITECH |
| HIPAA — HHS/OCR, 500+ | Same | 500 or more individuals affected | Contemporaneously with individual notice, no later than 60 calendar days | Discovery | HHS Office for Civil Rights, via the OCR breach portal | As above |
| HIPAA — HHS/OCR, under 500 | Same | Fewer than 500 individuals | Annual log, within 60 days after the end of the calendar year in which discovery occurred | End of the calendar year of discovery | HHS OCR | As above |
| HIPAA — media | Same | 500+ residents of a single state or jurisdiction — counted by residence, not by your location | Within 60 days of discovery | Discovery | Prominent media serving that state or jurisdiction | As above |
| HIPAA — BA to CE | Business associates | Discovery of a breach | Without unreasonable delay, no later than 60 days — your BAA has almost certainly shortened this to 5–15 days | Discovery | The covered entity | Contractual, plus direct HIPAA liability |
| FCC — agency notice | Telecommunications carriers, interconnected VoIP and TRS providers | Breach of CPNI or customer PII, inadvertent as well as intentional | As soon as practicable, no later than seven (7) business days | Reasonable determination that a breach occurred | The Commission and federal law enforcement (FBI and Secret Service) via the FCC central reporting facility. The 500-customer figure operates as the threshold for the full law-enforcement path † | FCC enforcement; amounts not stated in the sourced material. Rules upheld by the Sixth Circuit 13–14 August 2025 in Ohio Telecom Ass'n v. FCC; rehearing en banc litigated into July 2026 — contested but operative |
| FCC — customer notice | Same | Same | As soon as practicable after notifying the Commission and law enforcement, no later than 30 days. The old mandatory 7-day waiting period before customer notice was eliminated | Reasonable determination | Affected customers | Harm-based exception where no harm is reasonably likely (e.g. encrypted data). Law enforcement may direct delay for an initial period of up to 30 days, extendable |
| DFARS 252.204-7012 (CMMC estate) | Contractors and subcontractors handling CUI — flows down | A cyber incident affecting covered defense information or the contractor's ability to perform | 72 hours | Discovery | DoD at https://dibnet.dod.mil | Contract non-award or termination; False Claims Act liability via DOJ's Civil Cyber-Fraud Initiative for false compliance affirmations. Also requires 90-day media preservation and malicious-software submission |
| CMMC program | DoD contractors, phasing in | Solicitation and award requirements, not incident reporting | Phase 1: 10 Nov 2025 – 10 Nov 2026 — Level 1 and Level 2 self-assessment in selected solicitations at the Program Office's discretion, phasing DoD-wide over three years | Contract award | — | As above. The 32 CFR rule was effective 16 Dec 2024; the 48 CFR acquisition rule took effect 10 Nov 2025 |
| TSA Security Directives | TSA-designated pipeline and rail owner/operators | Identification of a cybersecurity incident | 24 hours — live today under the directives, ratified in a Federal Register notice of 17 January 2025 | Identification | CISA | TSA enforcement under the directive regime; amounts not stated in the sourced material. Directives also require a 24/7 Cybersecurity Coordinator, an IR plan and an annual assessment |
| PCI DSS v4.0.1 | Entities storing, processing or transmitting cardholder data, and those affecting its security | Suspected or confirmed compromise of cardholder data | PCI DSS itself sets no external clock. Req. 12.10.1 requires the IR plan to define notification of payment brands and acquirers; the brands' own programs govern timing — in practice immediately on suspected compromise | Per brand program | Acquirer and payment brands; a PFI forensic investigation may be compelled | Contractual, not regulatory: brand and acquirer fines, per-card assessments, forensic and reissuance costs, escalated merchant level, and at worst loss of card acceptance |
All 50 states plus DC, Puerto Rico, Guam and the US Virgin Islands. The shape is consistent even where the numbers are not.
| Regime | Applies to | Trigger | Deadline | Clock starts at | Notify whom | Penalty exposure |
|---|---|---|---|---|---|---|
| General shape | Any entity holding personal information on residents of that state | Unauthorized acquisition (in most states, not merely access) of usually-unencrypted, usually-computerized personal information — name plus SSN, driver's license or financial account, with most states now adding medical, health-insurance, biometric and online-account credentials | Varies: 30, 45 or 60 days, or "the most expedient time, without unreasonable delay" | Usually discovery; some states run from confirmation of the breach | Individuals; above a threshold (typically 500 or 1,000 residents) the state AG and the consumer reporting agencies. Substitute notice permitted above cost/volume thresholds | State AG enforcement; penalty structure varies by state and is not summarized in the sourced material. Most states carry an encryption safe harbour and a risk-of-harm exception |
| Puerto Rico (Act 111) | Entities holding PR residents' data | As above | 10 days — non-extendable, and the shortest in the US. DACO makes a public announcement within 24 hours | Detection | DACO (Departamento de Asuntos del Consumidor) | As above |
| Vermont | Entities holding VT residents' data | As above | 14 business days to the AG; 45 days to individuals | Discovery | AG, then individuals | As above † |
| California (SB 446) | Entities holding CA residents' data | As above | 30 calendar days to residents; sample notice to the AG within 15 calendar days of notifying consumers where >500 California residents are affected. Approved 3 Oct 2025, operative for 2026 | Discovery | Residents, then the AG | As above |
| New York (S2659B / S2376B) | Entities holding NY residents' data | As above; "private information" now includes medical and health-insurance information (from 21 Mar 2025) | Hard 30 days to individuals (from 21 Dec 2024), replacing "most expedient time possible"; vendors must notify the data owner within 30 days | Discovery | Individuals, AG, and — added by S2659B — DFS | As above |
| Texas | Entities holding TX residents' data | As above | 30 days to individuals; 30 days to the AG at 250+ residents — one of the lowest AG thresholds in the country | Discovery | Individuals and AG | As above |
| Colorado, Florida, Maine, Washington | Residents of those states | As above | 30 days † | Discovery † | Individuals; AG above threshold | As above † |
| Federal-compliance deeming | HIPAA covered entities, GLBA-regulated entities | — | Many states deem compliance with the federal rule as satisfying the state rule — but not all, and frequently not for the AG notice | — | — | Check state by state; do not assume the deeming clause covers the regulator leg |
| Regime | Applies to | Trigger | Deadline | Clock starts at | Notify whom | Penalty exposure |
|---|---|---|---|---|---|---|
| UK GDPR / DPA 2018 | Controllers in UK scope | Personal data breach, unless unlikely to result in a risk to rights and freedoms | 72 hours; reasons required if late. Data subjects without undue delay where high risk | Becoming aware | ICO online form, or the 24-hour helpline | Higher tier £17.5m or 4% of global turnover; Art. 33/34 failures sit in the lower £8.7m / 2% tier |
| NIS Regulations 2018 | Operators of essential services and relevant digital service providers | Incident with a significant or substantial impact on service continuity | 72 hours | Becoming aware | Relevant competent authority; the ICO is the competent authority for RDSPs | Not stated in the sourced material |
| PECR | Telecoms and ISPs | Personal data breach | 72 hours — moved from 24 hours on 20 August 2025, aligning with UK GDPR | Becoming aware | ICO | Not stated in the sourced material |
| Cyber Security and Resilience Bill | Would add medium and large data centres (Ofcom) and medium and large managed service providers (Information Commission), plus load controllers and designated critical suppliers | — | NOT LAW. Would introduce 24-hour initial notification / 72-hour full report to the regulator with simultaneous NCSC notification, plus a customer-notification duty on data centres and digital/MSP providers | — | Regulator plus NCSC | Reported at £10m/2% standard and £17m/4% higher tier with daily fines up to £100k † — figures unconfirmed. Treat as a 2027–28 readiness item, not a live clock |
| Regime | Applies to | Trigger | Deadline | Clock starts at | Notify whom | Penalty exposure |
|---|---|---|---|---|---|---|
| NYDFS Part 500 §500.17(a) | NYDFS covered entities | A cybersecurity incident at the covered entity, its affiliates, or a third-party service provider | As promptly as possible, no later than 72 hours | Determining that a cybersecurity incident has occurred | The Superintendent, with a continuing duty to report material changes and provide requested information | NYDFS enforcement under the Banking, Insurance and Financial Services Laws; each day of non-compliance and each failed requirement can be treated as a separate violation |
| NYDFS §500.17(c) | Same | Making an extortion payment | 24 hours from the payment, plus a 30-day written description of why payment was necessary, alternatives considered, diligence on alternatives, and sanctions/OFAC diligence | Making the payment | The Superintendent | As above |
| NYDFS §500.17(b) | Same | Annual cycle | 15 April each year — certification of material compliance, or written acknowledgement of non-compliance with a remediation plan | Calendar year end | The Superintendent, signed by the highest-ranking executive and the CISO; supporting documentation retained 5 years | As above. The final Second Amendment phase took effect 1 Nov 2025 (MFA for any individual accessing any information system; documented asset inventory), first certified against on 15 April 2026 |
| Australia — ransomware payment reporting | A "reporting business entity": carrying on business in Australia with annual turnover ≥ AUD 3m, or a responsible entity for a SOCI critical infrastructure asset regardless of turnover | Making, or another entity making on your behalf, a ransomware or cyber extortion payment — any benefit, no minimum threshold | 72 hours. In force since 30 May 2025 | Making the payment, or becoming aware that it was made on your behalf | Australian Signals Directorate via the ACSC portal (Home Affairs is joint recipient) | Civil penalty up to 60 penalty units (~AUD 19,800) — deliberately modest; the policy aim is visibility, not deterrence |
| Australia — SOCI Act Part 2B | Responsible entities for critical infrastructure assets | Mandatory cyber incident reporting | 12 hours for a critical incident (significant impact on the availability of an essential service); 72 hours for a relevant incident † | Awareness † | ASD / ACSC | Not stated in the sourced material. 12 hours would be the tightest clock in this appendix — verify before encoding |
Work these in parallel, not in sequence. With 12- and 24-hour clocks in play, a serial process fails by construction — you will still be establishing fact 3 when clock 1 expires.
Before anything else, two housekeeping actions that everything downstream depends on. Start a written timeline immediately, recording to the minute what was known, by whom, at each point. Engage counsel before the first substantive assessment so privilege attaches to the investigation, and appoint one named notification owner distinct from the Incident Commander.
| # | Fact to establish | Why it decides a clock | Clocks it can start |
|---|---|---|---|
| 1 | Do we have a reasonable degree of certainty that a security incident occurred? | This is the "awareness" state most EU clocks run from. Record the moment it arose and who held it | GDPR, UK GDPR, NIS2, DORA 24h cap, CRA |
| 2 | Does it involve personal data, and whose? | Splits the personal-data path from the operational-disruption path | GDPR 33/34, UK GDPR, US state laws |
| 3 | Is any of it PHI, cardholder data, or CUI? | Each pulls in a separate regime with its own recipient | HIPAA, PCI brand programs, DFARS §7012 |
| 4 | Where do the affected individuals reside? | US state law counts by residency, not by your location. This is what surfaces the 10-day Puerto Rico and 14-business-day Vermont carve-outs | All state laws; HIPAA media notice |
| 5 | Which of our regulated legal entities and services is affected? | NIS2, DORA and NYDFS bind entities, not incidents. Map to the entity, then to its Member State or regulator | NIS2, DORA, NYDFS, TSA, UK NIS |
| 6 | Is one of our products, in customers' hands, implicated — and is a vulnerability in it being actively exploited? | Entirely separate trigger from a compromise of your estate, and tighter | CRA Art. 14 (from 11 Sept 2026) |
| 7 | Is there an extortion demand, and has or will a payment be made? | The payment clocks are triggered by a business decision, not by the attack, and they are the tightest in the book | NYDFS 24h, Australia 72h, CIRCIA 24h once live |
| 8 | Are we a public company, and what does the disclosure committee need to reach a materiality view? | Item 1.05 runs from determination, but the determination cannot be deferred indefinitely | SEC Item 1.05 |
| 9 | Is an AI system involved, and is it a GPAI model with systemic risk or an Annex III high-risk system? | One duty is live today; the other is not | AI Act Art. 55 (live); Art. 73 (deferred) |
| 10 | Are we the processor, business associate or vendor here — or the customer? | Contractual clocks are usually shorter than statutory ones, and they are the ones actually missed | BAAs, MSAs, insurer notice, DFARS flow-down |
Capture four distinct timestamps per incident, because one "incident start" field cannot carry all of them: (a) awareness — GDPR, NIS2, CRA; (b) reasonable belief — CIRCIA; (c) determination that an incident occurred — NYDFS; (d) determination of materiality — SEC. They diverge by days, and the gap between them is the first thing an investigator will ask you to explain.
Then fire the sub-24-hour tier, tightest first: SOCI critical (12h) † → DORA initial (4h from classification, 24h hard cap) → CRA early warning (24h, from 11 Sept 2026) → NIS2 early warning (24h) → TSA (24h) → NYDFS extortion payment (24h from disbursement).
Actionable takeaway: file incomplete rather than late. GDPR, NIS2, DORA, CRA and the AI Act all expressly contemplate phased or incomplete initial reports. A 24-hour early warning that says "we are investigating, cause unknown, cross-border impact possible" is compliant. Silence is not.
| Conflict | What happens | What to do |
|---|---|---|
| Speed vs. accuracy | The 24-hour early warnings fall due long before forensics can support a four-business-day SEC narrative or a characterized GDPR Art. 33 report. Anything you tell a CSIRT at hour 24 can be quoted back at you in securities litigation | Maintain two templates: a regulator-facing factual early warning explicitly framed as preliminary and subject to change, and a separate disclosure-committee record. No technical team files a regulatory early warning without disclosure-counsel review of the wording |
| Awareness vs. determination | GDPR, NIS2 and CRA run from awareness; SEC from materiality determination; CIRCIA from reasonable belief; NYDFS from determination that an incident occurred | Four timestamp fields, populated by the Scribe, reviewed by the Legal Liaison |
| Disclosure vs. investigation | You can be legally required to disclose on Form 8-K while the FBI is asking you to hold customer notice. SEC delay needs an Attorney General national-security determination — a narrow door not available for law-enforcement convenience. FCC, HIPAA and most state laws do permit law-enforcement-directed delay | Escalate to counsel the moment law enforcement is engaged. Do not let the FBI relationship silently override a securities obligation |
| NIS2 fragmentation | "The NIS2 72-hour deadline" is not one deadline. Portals, thresholds, languages and registration duties differ, and some Member States impose shorter national timelines or additional recipients | A per-country contact-and-portal matrix maintained by local counsel, refreshed quarterly |
| Triple reporting for one event | Ransomware on an EU bank that exfiltrates customer PII and involves a payment can trigger DORA 4h/24h, NIS2 24h, GDPR 72h, national CSIRT rules, NYDFS 72h plus 24h payment, SEC 8-K, multiple state AGs, and Australian reporting if there are AU operations | Assume duplication. The EU Digital Omnibus single-entry-point proposal exists precisely to fix this and is not law |
| Contractual clocks beat regulatory ones | BAAs routinely compress HIPAA's 60 days to 5–15. Cyber policies require notice "as soon as practicable" and can deny coverage for late notice. Customer MSAs increasingly demand 24–48 hours. DFARS §7012 flows down to subcontractors | These are the deadlines you actually miss. Inventory them into the playbook alongside the statutes, with the same clock discipline |
| HIPAA vs. state law | 60 days is not a safe harbour; more stringent state laws are not preempted | Run the state clock, not the federal one |
Nothing in this section is a live obligation. Everything in it could become one.
| Item | Status | What to monitor |
|---|---|---|
| CIRCIA final rule | Not published. CISA missed the statutory Oct 2025 deadline, targeted May 2026, slipped again; the July 2026 Unified Agenda preview sets a September 2026 target. Town halls held 15–18 June 2026. Reporting is voluntary today | The Federal Register public inspection desk — this could land within days of this book going to press. Build the 72h/24h capability now; the clocks are statutory, short, and will not wait for you |
| SEC Item 1.05 | In force. Rescission has been requested, not proposed and not adopted. Chair Atkins launched a Reg S-K review on 13 Jan 2026 (comments due 13 Apr 2026); rescission or reform of Item 1.05 was reportedly among the most frequently requested changes † | SEC rulemaking activity listings. Keep the four-business-day machinery intact |
| GDPR 96-hour proposal | The Digital Omnibus proposes moving Art. 33 to 96 hours, raising the threshold to high risk, and routing notice through a single ENISA-operated entry point. Pending in the European Parliament; committee amendments recorded 27 July 2026; adoption not expected before late 2026, may slip to 2027 | Keep 72 hours in the playbook until it is in the Official Journal |
| NIS2 transposition | Incomplete. Ireland, Spain, France and the Netherlands referred to the CJEU on 8 July 2026. The Netherlands' Cyberbeveiligingswet in force ~15 Aug 2026; Ireland expects to notify by end-2026; France and Spain still legislating | Per-country status via the ECSO tracker and the Commission's infringement register. Where a state has not transposed, the directive is not directly effective against private entities — but the old NIS1 national law may still catch you |
| EU AI Act Art. 73 | Deferred by Regulation (EU) 2026/1744 (in force 27 July 2026) to 2 Dec 2027 / 2 Aug 2028 †. Art. 5 prohibited practices, GPAI obligations including Art. 55 incident reporting, and Art. 50 transparency remain live | The operative amending article of Reg. 2026/1744 for the precise scope of the deferral, and the Commission's draft guidance and reporting template for serious AI incidents |
| UK Cyber Security and Resilience Bill | In the Lords. Commons stages cleared; Lords Second Reading 14 July 2026; Grand Committee began 1 September 2026. Royal Assent expected late 2026, but substantive effect comes via secondary legislation after a 2026 implementation consultation — realistically 2027–2028 | Bill stages and the implementation consultation. Do not encode the 24/72 duty as live |
| HIPAA Security Rule overhaul | NPRM published 6 Jan 2025, >4,000 comments, not finalized. Unified Agenda now targets July 2027, pushed back from spring 2026. 100+ hospital and provider groups have asked HHS to withdraw it | The Unified Agenda. OCR enforces the existing Security Rule; nothing in the NPRM is enforceable today |
| TSA surface cyber rule | "Enhancing Surface Cyber Risk Management" NPRM published 7 Nov 2024, comments closed 5 Feb 2025. Final rule not issued. The Security Directives remain the operative law | Federal Register. The 24-hour directive clock is live today regardless |
| FCC breach rules | In effect and contested. Sixth Circuit upheld them 13–14 Aug 2025; rehearing en banc litigated through July 2026 | Sixth Circuit docket. Comply in the meantime |
| PCI DSS next version | v4.0.1 is the only active version. A Request for Comments reportedly ran 3 June – 20 July 2026 following a Dec 2025 RFC cycle † | PCI SSC document library. Plan for v4.0.1 through 2026–27 |
This appendix has a half-life, and it is shorter than the book's. Four of the ten watchlist rows could move inside a single quarter, and one of them — CIRCIA — was targeted at the very month this was verified.
Treat it as an asset with an owner, the same way you treat a detection rule. Concretely:
The regulators are not going to slow down to let your documentation catch up. Date it, own it, re-check it — and never let a table older than a quarter be the thing standing between you and a filing deadline.