Skip to content
The Cyber Security Place

Governance

Compliance in 2026: four clocks, four starting guns

This used to be an annual event with a checklist and a visitor. It is now a stopwatch that started before anybody in the building knew it had — and the difficult part was never the paperwork.

Last reviewed August 25, 2026

A single incident can start four European reporting clocks that each count from a different moment. DORA requires an initial notification within 4 hours of classifying an incident as major, capped at 24 hours from detection.NIS2 requires an early warning at 24 hours from awareness, a notification at 72, and a final report at one month. The Cyber Resilience Act imposes the same 24/72 pattern on manufacturers from September 2026, counted from learning of active exploitation.GDPR stays at 72 hours from awareness of a personal data breach. The hours cluster, which makes the regimes look coordinated; they are not, because each counts from a different observation. The binding activity is therefore classification rather than reporting, and deciding an event is not notifiable is itself a regulated act you must evidence. Under NIS2 the management body is personally accountable.

One incident, which clocks start?

The question anybody actually has at three in the morning takes two inputs: what has happened, and what kind of organisation you are. Neither axis answers it alone.

Worked exampleOne incident, which clocks start

Ransomware encrypts production systems, and personal data was copied on the way out

An essential entity

  • GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
  • NIS2counting from becoming aware of the significant incident24h early warning, 72h notification, 1 month final report

A financial entity

  • GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
  • DORAcounting from classifying the incident as major4h initial (24h cap from detection), +72h intermediate, 1 month final

A product manufacturer

  • GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay

The worst case for reporting: every axis is engaged at once, and the clocks start before the scope is known.

What each regime asks for, in full

GDPR
  • 72 hours — notify the supervisory authority, or record why you decided not to
  • Without undue delay — tell the individuals, if the risk to them is high
NIS2
  • 24 hours — early warning, stating whether it looks malicious or cross-border
  • 72 hours — incident notification with an initial assessment and severity
  • 1 month — final report with root cause and the measures applied
DORA
  • 4 hours from classification, and never later than 24 hours from detection — initial notification
  • 72 hours after that notification — intermediate report, even if nothing has changed
  • 1 month — final report with root cause and remediation
Cyber Resilience Act
  • 24 hours — early warning to the coordinator and the agency
  • 72 hours — notification with corrective measures taken or planned
  • 14 days after a fix is available — final report

Deadlines as the texts stood in August 2026, and a description of shape rather than legal advice: which clocks exist, and what each one counts from. That second half is where organisations are caught out, because the regimes do not share a starting gun. Sector rules, national transpositions and contractual terms add more.

Across a row, one event produces different duties. Down a column, one organisation owes different things by what happened. Neither is surprising once stated, and almost nobody has the combination written down — which is why the first hour of a real incident goes on finding out instead of acting.

The cell that repays attention is the last one, where nothing starts. It is the cell most people assume needs no preparation, and it is the one most likely to be examined afterwards. Concluding that an event is not notifiable is a regulated act: every regime here obliges an assessment, and what a supervisor demands later is not the filing you did not send but the reasoning you did not record.

The starting gun nobody agrees on

Laid on one axis the deadlines look almost coordinated. The labels on the left are what makes them anything but.

DORAfrom classification as major4h76hNIS2from awareness24h72hCyber Resilience Actfrom awareness of exploitation24h72hGDPRfrom awareness of the breach72h24 hours72 hours

A pair of uprights, at twenty-four and seventy-two hours, snags nearly every marker on the diagram. That convergence is genuine, and it persuades people that one incident timeline will satisfy everybody. It will not, because the markers are measured from four different origins.

Privacy law counts from awareness of a personal data breach. The essential entities regime counts from awareness of a significant incident, an unlike threshold crossed at an unlike moment. The financial regime counts from the moment an incident is classified as major, which may be hours after both. And the product-maker duty counts from learning that a vulnerability is being exploited, which often means hearing it from a stranger's blog post.

So there is no single hour zero. You are running four overlapping timers, each started by a separate observation, several of which nobody recorded making — and reconstructing when they began is the first thing a supervisor asks about.

Why is classification the hard part?

Because reporting is a form and classification is a judgement, and only one of those can be done wrong in a way that matters.

Every deadline here begins with a word applied to an unfolding situation:significant, major, likely to result in a risk,actively exploited. The published criteria are detailed and written for the state of knowledge at the end of an investigation — not for hour two, when what you have is an alert, a suspicion and a phone ringing.

The banking rulebook makes this explicit where its siblings do not, and it is the most useful thing to notice on the whole page. Its four hours run from classification, so the countdown is triggered not by the emergency but by a verdict inside your own organisation. That looks generous and is the opposite. It means the question a supervisor asks afterwards is not whether the submission left within four hours but when you should have classified — and an organisation with no written procedure has no answer that is better than the one the supervisor supplies.

Which points at the cheapest preparation available in this field. A one-page classification procedure, agreed in advance, naming who decides, against which criteria, logging the verdict and the minute it was reached. It costs an afternoon, it is impossible to produce against a live countdown, and it converts the worst question into a document you can hand over.

What auditors actually ask for

A stubborn gulf separates what people expect an inspection to probe from what it probes, and closing it saves a great deal of wasted preparation.

An assessor is establishing whether a safeguard exists, behaves as advertised, and can be shown to have behaved so throughout the period. That third limb yields most findings. A safeguard that works flawlessly yet leaves no trace fails, while a mediocre one with a spotless dossier passes — which sounds like an accusation and merely describes what an inspection can achieve from outside.

Evidence is therefore a design requirement, not an afterthought. A review held in a meeting and minuted nowhere did not happen. Arrange that the ordinary running of a control emits its own trace — a ticket, a signed log, an automated export — because anything reconstructed later costs several times more and convinces less.

The second thing an assessor is doing is following scope. Almost every disappointing certificate is a scope problem, not a rigour problem: the statement covers one product line, one data centre, one legal entity, and the customer reading the logo assumes it covers the organisation. Read the scope of anybody else's certificate before trusting it, and expect yours to be read the same way.

Does compliance make anything safer?

It lifts the baseline and reveals nothing about the summit, and most of the argument about it comes from people insisting on only one half of that sentence.

The case against is easy to make and largely true. Frameworks encode what was known when they were drafted, are assessed against evidence instead of outcomes, and consume budget that could have bought controls. Companies holding impeccable certificates are breached regularly, and the certificate neither prevented it nor predicted it.

The case for is quieter and rests on what happens to the businesses nobody writes about. Compulsory minimums are why a mid-sized foundry keeps offsite copies, an equipment register and somebody whose remit covers patching. Nothing else was going to produce that, because the funding argument was never winnable on merit against a competing proposal with revenue attached. Legislation drags up the tail of the curve, and the tail is where most of the damage accumulates.

The failure mode is not the framework; it is the belief that finishing it constitutes finishing.

The same control, in five formats

Ask where a compliance budget vanishes and the reply is seldom safeguards. It vanishes into re-describing safeguards that already exist, for audiences who refuse to accept one another's descriptions.

A mid-sized supplier into regulated sectors holds a general information security certification, a payment card assessment, a service organisation report, whatever its own regulator demands, and a queue of customer questionnaires. Underneath sit one set of access reviews, backups, patching and joiner-leaver handling. The controls overlap heavily; the evidence formats overlap not at all.

So the access recertification gets produced five times a year in five shapes, every round lands as a disruption, and eventually somebody hires a squad whose sole occupation is transliteration. None of that makes anybody safer by a single increment, and it is a large fraction of what the word now denotes in practice.

The structural remedy is one internal safeguard catalogue that every framework maps onto, with proof produced once in a neutral shape. It is a hefty undertaking, wholly unglamorous, and the sole remedy that shrinks the bill instead of shuffling it. Organisations that have done it describe the year's second inspection as an export, not an expedition, which is the whole return.

A decade that ran the other way

This section carried 518 reports, and its year-by-year shape is the inverse of nearly every other subject covered here.

Reports in this section, by year
201620172018201920202021
32851106965157

Nearly every technical topic crested around 2019 and receded once novelty drained away. This one did the opposite: it starts later than the others and rises to its highest volume at the end of the period, which is not a fashion cycle. It is the silhouette of a topic acquiring teeth.

The reason is visible in the headlines. The opening surge is groundwork for a privacy statute carrying a fixed date and a sanction hefty enough to reach a boardroom. The later wave is everything that followed from discovering the penalties were real.

8 Ways to Strengthen Data Governance & Regulatory Compliance Pre EU GDPR - ITProPortal ran in January 12, 2017, in the middle of an eighteen-month period during which abundant readiness was sold and rather less of it performed. What that regime actually established, more than any specific requirement, was that a due date plus a slice of turnover shifts a company that a decade of exhortation could not.

The directive that became the current essential-entities regime appears earlier than most people remember — Cultivating a culture of information security - Information Age - Information Age, October 4, 2016 — and was covered then as a niche obligation for utilities. The 2026 version reaches vastly further and puts the duty on the board.

Personal liability arrived quietly

The most consequential change of the current cycle is not a control or a deadline. It is a switch of recipient.

The critical-services directive obliges management bodies to approve the risk measures, to oversee their implementation, and to undergo training themselves — and makes them accountable for failures. Earlier statutes addressed the corporate body, which meant the penalty was a number in an account and the conversation stayed inside the security function. Naming individuals alters who turns up to the meeting.

The practical effect for anybody running a security programme is that the perennial struggle for attention has been upended. For two decades the snag was that whoever held the purse was never obliged to grasp the exposure. They now are, by name, and a request for a decision has become a request they cannot decline to consider.

The corresponding trap is accountability without competence, which produces theatre: directors signing approvals for measures they cannot evaluate, and a paper trail that satisfies an audit while changing nothing. What works instead is directors asking questions they can follow up — what would we owe, to whom, within what hours, and who decides.

What happens when the deadlines conflict?

They collide less often than feared and more awkwardly than expected.

Genuine relief is built into the architecture. Where an entity reports the same incident under both the financial and the essential-entities regimes, the second obligation can be treated as satisfied when the competent authority receives the information through the established cooperation mechanisms. That is a true simplification, and narrower than people hope: it applies to those two, on that incident, through those channels, and data protection is not discharged by either of them.

The awkwardness lies in the tension between speed and accuracy. An early warning at twenty-four hours is filed with a description you know to be provisional, and the temptation is to wait for something defensible. Waiting is the wrong instinct: a late accurate filing is a breach, while an early inaccurate one is the process working as designed.

The genuinely difficult conflict is between the regulator and everybody else. The very hours when four filings fall due are the hours when customers, journalists and staff demand statements, and those audiences punish exactly the hedged provisional language the regulator expects. Deciding in advance who writes which of those, and that they are not the same document, is worth more than any template.

The four documents to write before anything happens

All four are cheap beforehand and effectively impossible to draft against a live countdown, which is the entire argument for writing them now.

A classification procedure. One page. Which criteria, applied by whom, with the decision and its timestamp recorded. It answers the question that decides everything else.

A roster of everyone you would have to alert. Every authority, with the current portal, the current contact and the current format. These change, and discovering that at hour three is a bad time.

Skeleton disclosures with the gaps showing. Written calmly, they take an hour. Written during an incident by somebody who has never filed one, they take the hours you did not have.

A named decision-maker and a named deputy. With authority to classify at three in the morning without convening anybody. The commonest cause of a missed due date is not ignorance of it; it is that nobody in the room believed themselves entitled to decide.

What does a company of ninety people actually have to do?

The current wave of regulation catches employers who have never had a compliance function, and most of the published guidance is written for organisations that have three.

The reach is the part people miss. Cut-offs pegged to headcount and turnover sweep in mid-sized manufacturers, regional utilities, waste operators, food distributors and managed service providers, many of whom first discover they qualify when a customer posts a questionnaire. No register exists to consult and no letter arrives; coverage is something you conclude about yourself and must afterwards justify.

What follows is proportionate in the texts and intimidating in the trade press. Duties are framed as risk-appropriate measures, which for ninety people means the ordinary list — backups that have been restored from, an inventory, patching with an owner, access removed when staff leave, an incident procedure somebody has read — plus the reporting duties above and a board that can show it approved the arrangements.

Two failure modes are common: buying a certificate as a substitute for doing the work, and being so daunted by guidance drafted for multinationals that nothing happens at all. The proportionate reading is duller and correct. Write the four documents, do the ordinary list properly, and be able to describe both. That is a few weeks of effort, not a programme — worth saying plainly, because almost nobody selling into this space has an incentive to.

Where to start on a Monday

Three exercises, none of which needs a consultant, and each of which typically unearths something awkward inside an hour.

Set down which statutes bite on you and what each counts from. Not the deadlines — the starting events. Most teams keep the hours somewhere and have never noted the origins alongside, which is where the time actually goes.

Take an actual episode from last year and re-run the clocks against it. When would each one have started, given what was known when? The distance between that answer and what was actually lodged is your exposure, generally wider than the security desk expects and narrower than counsel dreads.

Ask who is allowed to classify at three in the morning. Should the reply run past a sentence, or invoke a committee, you have your finding.

After those three the harder work is prioritisable: consolidating evidence so one control satisfies several assessments, separating external communications from regulatory ones, and booking the board session about their own accountability. Do the first three and you know what you would owe, and to whom, before you need to.

Common questions

How many incident reporting deadlines can one event trigger?

Commonly three or four in Europe alone. A ransomware attack on a financial entity that also copies personal data starts a DORA clock, a GDPR clock and, depending on sector, a NIS2 clock, on differing thresholds, separate recipients and unlike triggers.

What are the NIS2 deadlines?

An early warning within 24 hours of becoming aware of a significant incident, a fuller notification with an initial assessment within 72 hours, and a final report with root cause and remedial measures within one month.

What are the DORA deadlines?

For a major ICT-related incident: an initial notification within 4 hours of classifying it as major and never later than 24 hours from detection, an intermediate report 72 hours after that notification even if nothing has changed, and a final report within one month.

Why is DORA's four hours so much shorter?

Because it counts from a different moment. The four hours run from classification rather than from awareness, with an outer cap of 24 hours from detection. In practice that makes classification the binding activity, not reporting.

Does reporting under one regime satisfy another?

Sometimes, and never assume it. Where an entity reports the same incident under both DORA and NIS2, the NIS2 obligation can be treated as met if the competent authority receives the information through the established cooperation mechanisms. GDPR is separate and is not discharged by either.

What does the Cyber Resilience Act add?

A duty on manufacturers rather than operators. From September 2026, an actively exploited vulnerability in a product with digital elements requires an early warning within 24 hours, a notification within 72, and a final report once a fix is available.

What is the hardest part of incident reporting?

Classification. Every clock starts from a judgement — significant, major, likely to result in risk — that has to be made early, with partial information, by somebody who will be asked to defend it later. The reporting itself is a form.

What happens if we decide not to report?

That decision is regulated too. Each regime obliges an assessment, and the assessment is the act whether or not it ends in a notification. An organisation that cannot show its reasoning is in a worse position than one that reported unnecessarily.

Are directors personally liable now?

Under NIS2, management bodies must approve the risk measures, oversee their implementation and undergo training, and can be held personally accountable for failures. That is a change of addressee, not of subject matter.

Does compliance make an organisation safer?

It raises the floor and does not describe the ceiling. Frameworks encode what was known when they were written and are audited against evidence instead of outcomes, so a firm can be entirely compliant and badly exposed. The floor is still worth having.

Is certification worth the cost?

As a commercial instrument, frequently: it shortens sales cycles and is increasingly a condition of contract. As a security measure it delivers what the scope statement says and no more, and the scope is where most of the disappointment lives.

What should exist before an incident happens?

A written classification procedure, a named person who can make the call at three in the morning, up-to-date addresses for every watchdog, and pre-agreed notification templates. All four are cheap in advance and impossible to draft against a four-hour countdown.

Compliance and regulation coverage

518 reports, newest first. Most cited sources: helpnetsecurity.com (106), infosecurity-magazine.com (40), itproportal.com (30), forbes.com (27), information-age.com (19), cisomag.eccouncil.org (18).