Governance
Compliance in 2026: four clocks, four starting guns
This used to be an annual event with a checklist and a visitor. It is now a stopwatch that started before anybody in the building knew it had — and the difficult part was never the paperwork.
Last reviewed August 25, 2026
- The clocks look aligned and are not. They cluster at 24 and 72 hours but each counts from a different event.
- Classification is the binding activity. Every deadline starts from a judgement made early, with partial information, by somebody who will be asked to defend it.
- Deciding not to report is also regulated. The assessment is the act; what you must be able to show is the reasoning.
- The floor rose; the ceiling did not move. An organisation can be fully compliant and badly exposed, and both statements can be worth making.
One incident, which clocks start?
The question anybody actually has at three in the morning takes two inputs: what has happened, and what kind of organisation you are. Neither axis answers it alone.
| An essential entityEnergy, transport, health, water, digital infrastructure and the rest of the NIS2 list. | A financial entityBanks, insurers, investment firms and the other categories DORA names. | A product manufacturerAnyone placing a product with digital elements on the European market. | |
|---|---|---|---|
| Ransomware encrypts production systems, and personal data was copied on the way out | |||
| A vulnerability in a product you sell is being actively exploited in the wild | |||
| A six-hour outage stops customers reaching their accounts; nothing was taken | |||
| A supplier is breached and your customers' records are among what was exposed | |||
| An employee's credentials were stolen; no access to any system has been confirmed |
Ransomware encrypts production systems, and personal data was copied on the way out
An essential entity
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
- NIS2counting from becoming aware of the significant incident24h early warning, 72h notification, 1 month final report
A financial entity
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
- DORAcounting from classifying the incident as major4h initial (24h cap from detection), +72h intermediate, 1 month final
A product manufacturer
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
The worst case for reporting: every axis is engaged at once, and the clocks start before the scope is known.
A vulnerability in a product you sell is being actively exploited in the wild
An essential entity
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
A financial entity
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
A product manufacturer
- Cyber Resilience Actcounting from becoming aware of active exploitation24h early warning, 72h notification, 14 days after a fix
Nothing has happened to you. The obligation is triggered by what is happening to your customers.
A six-hour outage stops customers reaching their accounts; nothing was taken
An essential entity
- NIS2counting from becoming aware of the significant incident24h early warning, 72h notification, 1 month final report
A financial entity
- DORAcounting from classifying the incident as major4h initial (24h cap from detection), +72h intermediate, 1 month final
A product manufacturer
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
No attacker and no data loss, and the reporting duties are close to identical. Availability counts.
A supplier is breached and your customers' records are among what was exposed
An essential entity
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
- NIS2counting from becoming aware of the significant incident24h early warning, 72h notification, 1 month final report
A financial entity
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
- DORAcounting from classifying the incident as major4h initial (24h cap from detection), +72h intermediate, 1 month final
A product manufacturer
- GDPRcounting from becoming aware of the breach72h to the authority, then the individuals without undue delay
Somebody else's incident, your obligations. The clock runs from when you learn, not from when it happened.
An employee's credentials were stolen; no access to any system has been confirmed
An essential entity
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
A financial entity
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
A product manufacturer
No reporting clock starts. That is a conclusion you have to reach, record and be able to defend later. Every regime here obliges you to assess, and the assessment is the regulated act whether or not it ends in a notification.
The instructive cell. Nothing starts — and deciding that is itself the regulated act.
What each regime asks for, in full
- GDPR
- 72 hours — notify the supervisory authority, or record why you decided not to
- Without undue delay — tell the individuals, if the risk to them is high
- NIS2
- 24 hours — early warning, stating whether it looks malicious or cross-border
- 72 hours — incident notification with an initial assessment and severity
- 1 month — final report with root cause and the measures applied
- DORA
- 4 hours from classification, and never later than 24 hours from detection — initial notification
- 72 hours after that notification — intermediate report, even if nothing has changed
- 1 month — final report with root cause and remediation
- Cyber Resilience Act
- 24 hours — early warning to the coordinator and the agency
- 72 hours — notification with corrective measures taken or planned
- 14 days after a fix is available — final report
Deadlines as the texts stood in August 2026, and a description of shape rather than legal advice: which clocks exist, and what each one counts from. That second half is where organisations are caught out, because the regimes do not share a starting gun. Sector rules, national transpositions and contractual terms add more.
Across a row, one event produces different duties. Down a column, one organisation owes different things by what happened. Neither is surprising once stated, and almost nobody has the combination written down — which is why the first hour of a real incident goes on finding out instead of acting.
The cell that repays attention is the last one, where nothing starts. It is the cell most people assume needs no preparation, and it is the one most likely to be examined afterwards. Concluding that an event is not notifiable is a regulated act: every regime here obliges an assessment, and what a supervisor demands later is not the filing you did not send but the reasoning you did not record.
The starting gun nobody agrees on
Laid on one axis the deadlines look almost coordinated. The labels on the left are what makes them anything but.
A pair of uprights, at twenty-four and seventy-two hours, snags nearly every marker on the diagram. That convergence is genuine, and it persuades people that one incident timeline will satisfy everybody. It will not, because the markers are measured from four different origins.
Privacy law counts from awareness of a personal data breach. The essential entities regime counts from awareness of a significant incident, an unlike threshold crossed at an unlike moment. The financial regime counts from the moment an incident is classified as major, which may be hours after both. And the product-maker duty counts from learning that a vulnerability is being exploited, which often means hearing it from a stranger's blog post.
So there is no single hour zero. You are running four overlapping timers, each started by a separate observation, several of which nobody recorded making — and reconstructing when they began is the first thing a supervisor asks about.
Why is classification the hard part?
Because reporting is a form and classification is a judgement, and only one of those can be done wrong in a way that matters.
Every deadline here begins with a word applied to an unfolding situation:significant, major, likely to result in a risk,actively exploited. The published criteria are detailed and written for the state of knowledge at the end of an investigation — not for hour two, when what you have is an alert, a suspicion and a phone ringing.
The banking rulebook makes this explicit where its siblings do not, and it is the most useful thing to notice on the whole page. Its four hours run from classification, so the countdown is triggered not by the emergency but by a verdict inside your own organisation. That looks generous and is the opposite. It means the question a supervisor asks afterwards is not whether the submission left within four hours but when you should have classified — and an organisation with no written procedure has no answer that is better than the one the supervisor supplies.
Which points at the cheapest preparation available in this field. A one-page classification procedure, agreed in advance, naming who decides, against which criteria, logging the verdict and the minute it was reached. It costs an afternoon, it is impossible to produce against a live countdown, and it converts the worst question into a document you can hand over.
What auditors actually ask for
A stubborn gulf separates what people expect an inspection to probe from what it probes, and closing it saves a great deal of wasted preparation.
An assessor is establishing whether a safeguard exists, behaves as advertised, and can be shown to have behaved so throughout the period. That third limb yields most findings. A safeguard that works flawlessly yet leaves no trace fails, while a mediocre one with a spotless dossier passes — which sounds like an accusation and merely describes what an inspection can achieve from outside.
Evidence is therefore a design requirement, not an afterthought. A review held in a meeting and minuted nowhere did not happen. Arrange that the ordinary running of a control emits its own trace — a ticket, a signed log, an automated export — because anything reconstructed later costs several times more and convinces less.
The second thing an assessor is doing is following scope. Almost every disappointing certificate is a scope problem, not a rigour problem: the statement covers one product line, one data centre, one legal entity, and the customer reading the logo assumes it covers the organisation. Read the scope of anybody else's certificate before trusting it, and expect yours to be read the same way.
Does compliance make anything safer?
It lifts the baseline and reveals nothing about the summit, and most of the argument about it comes from people insisting on only one half of that sentence.
The case against is easy to make and largely true. Frameworks encode what was known when they were drafted, are assessed against evidence instead of outcomes, and consume budget that could have bought controls. Companies holding impeccable certificates are breached regularly, and the certificate neither prevented it nor predicted it.
The case for is quieter and rests on what happens to the businesses nobody writes about. Compulsory minimums are why a mid-sized foundry keeps offsite copies, an equipment register and somebody whose remit covers patching. Nothing else was going to produce that, because the funding argument was never winnable on merit against a competing proposal with revenue attached. Legislation drags up the tail of the curve, and the tail is where most of the damage accumulates.
The failure mode is not the framework; it is the belief that finishing it constitutes finishing.
The same control, in five formats
Ask where a compliance budget vanishes and the reply is seldom safeguards. It vanishes into re-describing safeguards that already exist, for audiences who refuse to accept one another's descriptions.
A mid-sized supplier into regulated sectors holds a general information security certification, a payment card assessment, a service organisation report, whatever its own regulator demands, and a queue of customer questionnaires. Underneath sit one set of access reviews, backups, patching and joiner-leaver handling. The controls overlap heavily; the evidence formats overlap not at all.
So the access recertification gets produced five times a year in five shapes, every round lands as a disruption, and eventually somebody hires a squad whose sole occupation is transliteration. None of that makes anybody safer by a single increment, and it is a large fraction of what the word now denotes in practice.
The structural remedy is one internal safeguard catalogue that every framework maps onto, with proof produced once in a neutral shape. It is a hefty undertaking, wholly unglamorous, and the sole remedy that shrinks the bill instead of shuffling it. Organisations that have done it describe the year's second inspection as an export, not an expedition, which is the whole return.
A decade that ran the other way
This section carried 518 reports, and its year-by-year shape is the inverse of nearly every other subject covered here.
| 2016 | 2017 | 2018 | 2019 | 2020 | 2021 |
|---|---|---|---|---|---|
| 32 | 85 | 110 | 69 | 65 | 157 |
Nearly every technical topic crested around 2019 and receded once novelty drained away. This one did the opposite: it starts later than the others and rises to its highest volume at the end of the period, which is not a fashion cycle. It is the silhouette of a topic acquiring teeth.
The reason is visible in the headlines. The opening surge is groundwork for a privacy statute carrying a fixed date and a sanction hefty enough to reach a boardroom. The later wave is everything that followed from discovering the penalties were real.
8 Ways to Strengthen Data Governance & Regulatory Compliance Pre EU GDPR - ITProPortal ran in January 12, 2017, in the middle of an eighteen-month period during which abundant readiness was sold and rather less of it performed. What that regime actually established, more than any specific requirement, was that a due date plus a slice of turnover shifts a company that a decade of exhortation could not.
The directive that became the current essential-entities regime appears earlier than most people remember — Cultivating a culture of information security - Information Age - Information Age, October 4, 2016 — and was covered then as a niche obligation for utilities. The 2026 version reaches vastly further and puts the duty on the board.
Personal liability arrived quietly
The most consequential change of the current cycle is not a control or a deadline. It is a switch of recipient.
The critical-services directive obliges management bodies to approve the risk measures, to oversee their implementation, and to undergo training themselves — and makes them accountable for failures. Earlier statutes addressed the corporate body, which meant the penalty was a number in an account and the conversation stayed inside the security function. Naming individuals alters who turns up to the meeting.
The practical effect for anybody running a security programme is that the perennial struggle for attention has been upended. For two decades the snag was that whoever held the purse was never obliged to grasp the exposure. They now are, by name, and a request for a decision has become a request they cannot decline to consider.
The corresponding trap is accountability without competence, which produces theatre: directors signing approvals for measures they cannot evaluate, and a paper trail that satisfies an audit while changing nothing. What works instead is directors asking questions they can follow up — what would we owe, to whom, within what hours, and who decides.
What happens when the deadlines conflict?
They collide less often than feared and more awkwardly than expected.
Genuine relief is built into the architecture. Where an entity reports the same incident under both the financial and the essential-entities regimes, the second obligation can be treated as satisfied when the competent authority receives the information through the established cooperation mechanisms. That is a true simplification, and narrower than people hope: it applies to those two, on that incident, through those channels, and data protection is not discharged by either of them.
The awkwardness lies in the tension between speed and accuracy. An early warning at twenty-four hours is filed with a description you know to be provisional, and the temptation is to wait for something defensible. Waiting is the wrong instinct: a late accurate filing is a breach, while an early inaccurate one is the process working as designed.
The genuinely difficult conflict is between the regulator and everybody else. The very hours when four filings fall due are the hours when customers, journalists and staff demand statements, and those audiences punish exactly the hedged provisional language the regulator expects. Deciding in advance who writes which of those, and that they are not the same document, is worth more than any template.
The four documents to write before anything happens
All four are cheap beforehand and effectively impossible to draft against a live countdown, which is the entire argument for writing them now.
A classification procedure. One page. Which criteria, applied by whom, with the decision and its timestamp recorded. It answers the question that decides everything else.
A roster of everyone you would have to alert. Every authority, with the current portal, the current contact and the current format. These change, and discovering that at hour three is a bad time.
Skeleton disclosures with the gaps showing. Written calmly, they take an hour. Written during an incident by somebody who has never filed one, they take the hours you did not have.
A named decision-maker and a named deputy. With authority to classify at three in the morning without convening anybody. The commonest cause of a missed due date is not ignorance of it; it is that nobody in the room believed themselves entitled to decide.
What does a company of ninety people actually have to do?
The current wave of regulation catches employers who have never had a compliance function, and most of the published guidance is written for organisations that have three.
The reach is the part people miss. Cut-offs pegged to headcount and turnover sweep in mid-sized manufacturers, regional utilities, waste operators, food distributors and managed service providers, many of whom first discover they qualify when a customer posts a questionnaire. No register exists to consult and no letter arrives; coverage is something you conclude about yourself and must afterwards justify.
What follows is proportionate in the texts and intimidating in the trade press. Duties are framed as risk-appropriate measures, which for ninety people means the ordinary list — backups that have been restored from, an inventory, patching with an owner, access removed when staff leave, an incident procedure somebody has read — plus the reporting duties above and a board that can show it approved the arrangements.
Two failure modes are common: buying a certificate as a substitute for doing the work, and being so daunted by guidance drafted for multinationals that nothing happens at all. The proportionate reading is duller and correct. Write the four documents, do the ordinary list properly, and be able to describe both. That is a few weeks of effort, not a programme — worth saying plainly, because almost nobody selling into this space has an incentive to.
Where to start on a Monday
Three exercises, none of which needs a consultant, and each of which typically unearths something awkward inside an hour.
Set down which statutes bite on you and what each counts from. Not the deadlines — the starting events. Most teams keep the hours somewhere and have never noted the origins alongside, which is where the time actually goes.
Take an actual episode from last year and re-run the clocks against it. When would each one have started, given what was known when? The distance between that answer and what was actually lodged is your exposure, generally wider than the security desk expects and narrower than counsel dreads.
Ask who is allowed to classify at three in the morning. Should the reply run past a sentence, or invoke a committee, you have your finding.
After those three the harder work is prioritisable: consolidating evidence so one control satisfies several assessments, separating external communications from regulatory ones, and booking the board session about their own accountability. Do the first three and you know what you would owe, and to whom, before you need to.
Common questions
How many incident reporting deadlines can one event trigger?
Commonly three or four in Europe alone. A ransomware attack on a financial entity that also copies personal data starts a DORA clock, a GDPR clock and, depending on sector, a NIS2 clock, on differing thresholds, separate recipients and unlike triggers.
What are the NIS2 deadlines?
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification with an initial assessment within 72 hours, and a final report with root cause and remedial measures within one month.
What are the DORA deadlines?
For a major ICT-related incident: an initial notification within 4 hours of classifying it as major and never later than 24 hours from detection, an intermediate report 72 hours after that notification even if nothing has changed, and a final report within one month.
Why is DORA's four hours so much shorter?
Because it counts from a different moment. The four hours run from classification rather than from awareness, with an outer cap of 24 hours from detection. In practice that makes classification the binding activity, not reporting.
Does reporting under one regime satisfy another?
Sometimes, and never assume it. Where an entity reports the same incident under both DORA and NIS2, the NIS2 obligation can be treated as met if the competent authority receives the information through the established cooperation mechanisms. GDPR is separate and is not discharged by either.
What does the Cyber Resilience Act add?
A duty on manufacturers rather than operators. From September 2026, an actively exploited vulnerability in a product with digital elements requires an early warning within 24 hours, a notification within 72, and a final report once a fix is available.
What is the hardest part of incident reporting?
Classification. Every clock starts from a judgement — significant, major, likely to result in risk — that has to be made early, with partial information, by somebody who will be asked to defend it later. The reporting itself is a form.
What happens if we decide not to report?
That decision is regulated too. Each regime obliges an assessment, and the assessment is the act whether or not it ends in a notification. An organisation that cannot show its reasoning is in a worse position than one that reported unnecessarily.
Are directors personally liable now?
Under NIS2, management bodies must approve the risk measures, oversee their implementation and undergo training, and can be held personally accountable for failures. That is a change of addressee, not of subject matter.
Does compliance make an organisation safer?
It raises the floor and does not describe the ceiling. Frameworks encode what was known when they were written and are audited against evidence instead of outcomes, so a firm can be entirely compliant and badly exposed. The floor is still worth having.
Is certification worth the cost?
As a commercial instrument, frequently: it shortens sales cycles and is increasingly a condition of contract. As a security measure it delivers what the scope statement says and no more, and the scope is where most of the disappointment lives.
What should exist before an incident happens?
A written classification procedure, a named person who can make the call at three in the morning, up-to-date addresses for every watchdog, and pre-agreed notification templates. All four are cheap in advance and impossible to draft against a four-hour countdown.
Compliance and regulation coverage
518 reports, newest first. Most cited sources: helpnetsecurity.com (106), infosecurity-magazine.com (40), itproportal.com (30), forbes.com (27), information-age.com (19), cisomag.eccouncil.org (18).
- Businesses are underestimating risk in the digital age
November 17, 2021 · itproportal.com
- 8 cybersecurity predictions for 2022 and beyond
November 17, 2021 · itworldcanada.com
- Infrastructure Spending Bill Includes Billions for Cybersecurity
November 16, 2021 · channelfutures.com
- Not Just A CISO Problem: Five Ways Cybersecurity Threats Are Becoming A Central Concern For Go-To-Market Organizations
November 12, 2021 · forbes.com
- 2022 Cybersecurity Predictions From RSA Conference’s Advisory Board
November 11, 2021 · securityboulevard.com
- In a quantum future, our economy needs to be protected. A cybersecurity expert explains why
November 11, 2021 · weforum.org
- Securing ‘Digital India’ With a Zero Trust Approach
November 10, 2021 · cisomag.eccouncil.org
- Scammers Force Victims to Use Crypto ATMs and QR Codes: FBI
November 9, 2021 · cisomag.eccouncil.org
- How Can Pensions Best Protect Against Cybersecurity Threats?
November 9, 2021 · ai-cio.com
- SA businesses take action to stave off cyber attacks
November 8, 2021 · indaily.com.au
- How to Stay Updated with Cybersecurity Breakthroughs
November 8, 2021 · techbullion.com
- Cybersecurity threat landscape growing in sophistication, complexity and impact
November 2, 2021 · helpnetsecurity.com
- Weaponized social media cyber attacks predicted in US and elsewhere in 2022
November 2, 2021 · techhq.com
- Navigating the cybersecurity implications of remote work
November 1, 2021 · crainscleveland.com
- API attacks are both underdetected and underreported
October 29, 2021 · helpnetsecurity.com
- McAfee and FireEye Release 2022 Threat Predictions for Enterprises
October 29, 2021 · cisomag.eccouncil.org
- Tech support scams are the number 1 phishing threat
October 28, 2021 · securitybrief.asia
- Most firms think remote employees pose more risk than office workers
October 28, 2021 · itproportal.com
- Why the time has come to embrace the Zero-Trust model of cybersecurity
October 28, 2021 · weforum.org
- Anyone can be the victim of a ransomware attack
October 27, 2021 · komonews.com
- COVID: Proof of vaccination phishing scam hits the web
October 26, 2021 · securitybrief.asia
- Increased risk tolerances are making digital transformation programs vulnerable
October 26, 2021 · helpnetsecurity.com
- Ransomware Rise Pushes Organizations to Prepare for Attack
October 25, 2021 · darkreading.com
- Stolen data spreading even faster on the dark web
October 25, 2021 · securitybrief.asia
- Supply chain attacks are a bigger risk than ever
October 22, 2021 · itproportal.com
- Why Every Business Needs a Cybersecurity Incident Response Team
October 22, 2021 · cisomag.eccouncil.org
- Increased activity surrounding stolen data on the dark web
October 21, 2021 · helpnetsecurity.com
- Why Cyber Compliance And Cybersecurity Are Not The Same
October 21, 2021 · forbes.com
- Cyber Security Month in the WFH Era: Three Key Steps to Secure Hybrid Teams
October 20, 2021 · itsecuritycentral.teramind.co
- Organizations lack basic cybersecurity practices to combat the growing tide of ransomware
October 20, 2021 · helpnetsecurity.com