Law / Frameworks / NIST CSF 2.0 / Respond
NIST CSF 2.0, RespondRS.CO-02
Internal and external stakeholders are notified of incidentsNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.CO-02
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 89
- laws
- 71
- places
- 0
- with court rulings behind them
- 6
- not yet in force
- 4
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations4.3 Incident Reporting
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Vulnerability and incident reporting
77 laws, 65 places| Place | Law | What it asks, as read here |
|---|---|---|
| Llei 22/2022, Incident Handling and Notification Obligation |
Notify the CSIRT-AD, without delay and in any event within 72 hours of becoming aware of it, of any incident that has or may have significant effects on your essential or important service, including information on any cross-border effects; where you cannot yet establish that effect, you may omit it if you send a justificatory report within 72 hours of the notification explaining why. Where appropriate, notify the recipients of your service, without undue delay, that a significant incident is likely to affect them and what measures or remedies they can take in response. |
|
| Lei de Protecção das Redes e Sistemas Informáticos, Incident-Management Planning, Alert Dissemination and CERT Coordination Duties |
On an attack, computer theft or any computer incident, disseminate alerts and warnings; the text does not state to whom or within what deadline (Article 15(2)). |
|
| Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations |
Notify your competent Computer-Notfallteam (CERT), or, absent one, the national CERT or GovCERT, without delay of a security incident affecting the service you provide. Include in the notification every relevant detail known at the time, including the suspected or actual cause, the affected information technology, and the type of entity or facility affected; report later developments in follow-up and final notifications. |
|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations from , in 2 days |
Notify your competent sector-specific CSIRT, or, absent one, the national CSIRT, of every significant cybersecurity incident: an early warning within 24 hours of becoming aware, stating whether it is suspected to result from unlawful and culpable acts or to have cross-border effects. Follow with a fuller notification within 72 hours of becoming aware, updating the early warning with an initial evaluation of the incident's severity and impact and any indicators of compromise. |
|
| Cyber Security Act, Computer Emergency Response Team, Duty to Report a Cyber Incident |
Without delay after a cyber incident occurs, inform the National Computer Emergency Response Team the National Cyber Security Agency maintains; the Act names no fixed number of hours or days for this notification. |
|
| Loi du 26 avril 2024, Significant-Incident Notification Obligations |
Notify the national CSIRT of any significant incident without undue delay, following the arrangements set out in the protocol between the CSIRT and the National Crisis Centre. Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious action and whether it may have a cross-border impact. +1 more |
|
| Cybersecurity Act, Incident and Cyber-Threat Reporting Obligations (Zakon za kibersigurnost, ZKS) |
Notify СЕРИКС of every significant incident on this clock: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours (24 hours if you are a trust service provider), an interim report on request, and a final report no later than one month after the incident notification (or, if unresolved by then, an interim report followed by a final report within one month of resolution). State in your early warning, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it could have a cross-border effect; update that assessment with an initial severity and impact evaluation in your 72-hour notification; and cover in your final report the incident's scope and impact, its likely cause, your mitigation measures, and any cross-border effect. +1 more |
|
| Data Security Law, Risk Monitoring and Incident Reporting Duty |
On an actual data-security incident, immediately take disposal measures, promptly notify affected users as provided, and report the incident to the competent authority; the statute states no numeric deadline, only immediacy and promptness. |
|
| National Cybersecurity Incident Reporting Measures |
Where the incident involves critical information infrastructure, report to your sector's protection-work department and to the public security organ within 1 hour of discovering or becoming aware of the incident. Where you are a department of a central or state organ, or a directly affiliated unit of one, report to your own department's cyberspace affairs unit within 2 hours of discovering or becoming aware of the incident. +2 more |
|
| Zakon o kibernetičkoj sigurnosti and Uredba o kibernetičkoj sigurnosti, Incident and Cyber-Threat Reporting Obligations |
Notify the competent CSIRT of every significant incident on this clock, set by the Cybersecurity Regulation rather than the Act itself: an early warning without delay and no later than 24 hours after becoming aware of it (24 hours also for a trust service provider's initial notification), an initial notification no later than 72 hours otherwise, an interim report if the CSIRT requests one, and a final report no later than 30 days after your initial notification, or, if the incident is still unresolved at that point, a progress report instead, repeated every 30 days once the incident has run past 60 days, followed by a final report within 30 days of your last progress report. Notify the recipients of your service, without delay and no later than 72 hours after you become aware of a significant incident likely to affect them, in a clear and easily verifiable way, and separately notify them of a serious cyber threat and of any protective measures or remedies they can take. |
Show the other 67 laws
| Resolución 105/2021, Reglamento sobre el Modelo de Actuación Nacional para la Respuesta a Incidentes de Ciberseguridad |
Report a cybersecurity incident immediately to your immediate superior and to the Cuban Computer Incident Response Team (CuCERT), inside the Ministry of Communications' Oficina de Seguridad para las Redes Informáticas (OSRI), using the incident-report form the Reglamento's Annex III sets out. If you hold a private data network, ensure that a cybersecurity event or incident affecting it is recorded, classified and reported to CuCERT. +1 more |
|
| Security of Networks and Information Systems Law, Incident Notification Obligations |
Notify the Digital Security Authority without undue delay, and in any event within six (6) hours of becoming aware of a significant incident, with an early warning stating, where applicable, whether the incident is suspected to result from unlawful or malicious acts and whether it may have a cross-border impact. Follow with an incident notification within 72 hours of becoming aware, updating the early warning and giving an initial assessment of the incident's severity and impact, including any indicators of compromise where available. +2 more |
|
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification |
If you are in the higher-obligations regime, notify NÚKIB no later than 24 hours after detecting a qualifying cybersecurity incident, with an initial report giving your identifying details, basic incident data, and whether you believe the incident was caused by an unlawful intervention or could have a cross-border impact. If you are in the lower-obligations regime, notify the Národní CERT on the same 24-hour clock instead, for a qualifying incident with significant impact on your service's provision. +2 more |
|
| Mandatory Reporting of Attacks and Intrusions to ARTCI |
Inform ARTCI immediately of any attack, intrusion or other disruption likely to impede your information system's proper functioning. |
|
| Digital Code, Livre II: Trust Service Provider Security-Incident Notification |
Notify the Autorité Nationale de Certification Électronique, and where applicable other bodies concerned, within twenty four hours of becoming aware of it, of every breach of security or loss of integrity having a significant impact on the trust service provided or on the personal data it stores. Where the breach or loss of integrity is liable to harm a user of the service, notify that user as well, within twenty four hours. |
|
| Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty |
Inform the Agence Nationale de Cybersécurité of every attack, intrusion or other penetration liable to impair the operation of another information system or network, so as to let the Agency take the measures necessary to address it, including isolating the affected system. |
|
| NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties |
Notify your competent authority and Denmark's CSIRT of every significant incident, one that has caused or can cause serious operational disruption or financial loss for you, or has affected or can affect another person through significant physical or non-physical harm. Send an early warning without undue delay, and no later than 24 hours after becoming aware of the significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect. +3 more |
|
| Digital Code, Book VII: National Health Data System Security Incident Reporting |
Report a serious information-system security incident to the cybersecurity authority without delay, if you access data in Djibouti's national health data system as a health professional, health establishment, health-insurance financing body, or other body accessing that system. |
|
| Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident |
Submit an initial report to RIA without delay and no later than 24 hours after becoming aware of a cyber incident that has, or could reasonably be expected to have, a significant effect on your system's security or your service's continuity, unless you are a security authority. Follow with an incident report no later than 72 hours after becoming aware of the significant incident, updating the initial report, unless you are a qualified trust service provider, in which case you report in a single stage within 24 hours instead. +1 more |
|
| Computer Crime Proclamation, Duty to Report Computer Crime and Illegal Content |
Immediately notify the Information Network Security Agency (now the Information Network Security Administration) and report the crime to the police, and take appropriate measures. |
|
| Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT from , in 10 months |
Notify the National Computer Emergency Response Center of a cyber incident within 48 hours of becoming aware of it, using the system the Administration establishes, and implement the mandatory recommendations or directions the Center provides within the time it sets. |
|
| Cyber Resilience Act, Manufacturer Reporting Obligations |
Notify the CSIRT designated as coordinator for your main establishment and ENISA, through the single reporting platform, of any actively exploited vulnerability you become aware of in your product: an early warning within 24 hours of becoming aware, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available. Notify the same recipients of any severe incident affecting the security of your product on the same 24-hour early warning and 72-hour incident notification clock, followed by a final report within one month of the incident notification. +1 more |
|
| DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 |
Report a major ICT-related incident to the competent authority your sector's Union law designates under Article 46, the European Central Bank through your national supervisor if you are a credit institution classified as significant, using the templates referred to in Article 20, and submit an initial notification as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it. Where classification as major comes later than that, submit the initial notification within four hours of the classification instead. +1 more |
|
| NIS2 Directive, Reporting Obligations |
Notify your CSIRT, or the competent authority where applicable, of any incident with a significant impact on the provision of your services: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Where appropriate, notify, without undue delay, the recipients of your services who a significant incident is likely to adversely affect, and communicate to recipients potentially affected by a significant cyber threat any measures or remedies they can take. |
|
| Kyberturvallisuuslaki, Significant-Incident Reporting Obligations |
Notify your supervisory authority without delay of a significant incident, one that has caused or could cause a serious service disruption or considerable financial loss to you, or that has affected or could affect another person with considerable material or immaterial damage. File an early notification within 24 hours of detecting the significant incident, stating whether it is suspected to result from an unlawful or hostile act and the likelihood of cross-border effects, and a follow-up notification within 72 hours of detection, both clocks running from detection rather than from each other; if you are a trust service provider whose trust services are affected, file your follow-up notification within 24 hours instead of 72. +1 more |
|
| Loi n° 2018-133 du 26 février 2018 (transposition NIS1), Incident Notification |
Declare to ANSSI, without delay after becoming aware of it, an incident affecting the networks and information systems necessary to provide your service, where the incident has or is likely to have a significant impact on the continuity of the service (an operator of essential services) or on the provision of the service in the European Union (a digital service provider). |
|
| Projet de loi Résilience des Infrastructures Critiques et Cybersécurité, Incident Notification (NIS2) proposed |
Notify ANSSI without undue delay of any incident with an important impact on the provision of your services (one causing or liable to cause a severe operational disruption or financial loss for you, or considerable material, physical or non-material damage to another person), on a graduated clock: an initial notification within 24 hours of becoming aware of it, an intermediate notification within 72 hours updating the initial one and giving an initial assessment of severity and impact, a report on ANSSI's request, and a final report within one month (or, for an incident still being handled, a progress report at one month followed by a final report within one month of resolution). Where you are a trust-service provider or one of the domain-name and registry services Articles 8(4) and 9(3) name, notify within 24 hours rather than 72 for the intermediate notification. |
|
| Information and Communications Act, 2009, security of information and communications services (subscriber risk notification) |
Where a particular risk of a breach of the security of your services persists despite your safeguards, inform your subscribers of the risk and of the measures they may take to protect themselves. Identify in that notice any software or encryption technology available to the subscriber to protect the security of their communications. +1 more |
|
| BSI-Gesetz (BSIG), Incident Notification |
Notify the BSI's and the Bundesamt für Bevölkerungsschutz und Katastrophenhilfe's joint reporting office without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating whether the incident is suspected to be unlawful or malicious or to have cross-border effect. Follow with a full notification within 72 hours of becoming aware, confirming or updating the early warning and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise. +1 more |
|
| Cybersecurity Act, Duty to Report Cybersecurity Incident |
Report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team, or to the National Computer Emergency Response Team where the institution has no Sectoral team, within twenty-four hours after the incident is detected. |
|
| Law 5160/2024, Significant-Incident Reporting Obligations |
Notify the CSIRT of the National Cybersecurity Authority, without undue delay and in any case within 24 hours of becoming aware of a significant incident, with an early warning stating whether unlawful or malicious action is suspected and whether the incident may have cross-border effects. Follow within 72 hours of becoming aware of the significant incident with an incident notification updating the early warning and adding an initial assessment of its severity and effects. +1 more |
|
| Cybersecurity Act, Incident Notification and Cybersecurity Fine |
Notify the national cybersecurity incident-handling centre (Nemzeti Kiberbiztonsági Intézet, the NKI) of a cyber threat, near-incident or cybersecurity incident affecting your electronic information system: an initial notification without undue delay and in any case within 24 hours of becoming aware, an event notification within 72 hours that updates that report and assesses the incident's severity and impact, and a final report no later than one month after the event notification. |
|
| Notification of Serious Incidents and Risk to the National Cybersecurity Incident-Response Team |
Notify Iceland's national cybersecurity incident-response team as soon as may be about a serious incident or risk threatening the security of a network or information system; the Act sets no fixed hour-based clock of its own for this notification. State in the notification the number of affected users, the incident's duration, its geographic spread and scale, any outsourcing arrangement relied on, and any possible cross-border contagion effect. |
|
| CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation |
Report a listed cyber security incident, including a targeted attack, a data breach, a data leak, unauthorised access to your IT systems, or an attack through a malicious or fake mobile app, to CERT-In within six hours of noticing it or being notified of it, by email, phone, or fax; current reporting formats and channels are published on CERT-In's own website. |
|
| Government Regulation on the Operation of Electronic Systems and Transactions, security-incident reporting duty |
Report the incident immediately, at the first opportunity, to law enforcement officials and the relevant Ministry or Agency; the Government Regulation states no numeric clock for this report, only immediacy. |
|
| European Union (NIS) Regulations 2018, Incident Notification |
Notify the State's CSIRT without delay and in any event not later than 72 hours after becoming aware of an incident with a significant impact on the continuity of your essential service, or a substantial impact on your digital service, including an incident affecting a third-party digital service provider you rely on. |
|
| National Cyber Security Bill, Incident Response Powers and Reporting Obligations proposed |
Notify the CSIRT without undue delay of any incident with a significant impact on the provision of your service: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, and a final report within one month. Where appropriate, notify the recipients of your service of the incident and of any measures they can take in response. |
|
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification |
Notify CSIRT Italia without unjustified delay, and in any event within 24 hours of becoming aware of a significant incident, with a pre-notification stating, where possible, whether the incident appears unlawful or malicious and whether it may have a cross-border impact. Follow with a full notification within 72 hours of becoming aware, updating the pre-notification and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise. +1 more |
|
| Cyber Security Law No. 16 of 2019, Article 8 private-sector incident-reporting and Center-cooperation duty |
Adhere to the policies, standards, and controls the Center issues for the institution's own sector, provide the Center the information it needs to do its work, and inform the Center of any incident that threatens cybersecurity or the security of cyberspace, taking every step necessary to prevent or avoid it. |
|
| Computer Misuse and Cybercrimes Act, Reporting of Cyber Threat |
Immediately inform the National Computer and Cybercrimes Co-ordination Committee, established under section 4 of the Act, of an attack, intrusion, or other disruption to the functioning of another computer system or network, within twenty-four hours of the attack, intrusion, or disruption. Include in the report a summary of how the breach occurred, an estimate of the number of people affected, an assessment of the risk of harm to them, and an explanation of any circumstance that would delay or prevent telling them. |
|
| Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident from a date not yet set |
When you are the subject of a cybersecurity incident or threat of one, gather information about it, assess the risk to your critical infrastructure, customers, suppliers and other stakeholders, take appropriate preventative, mitigating and remedial measures to limit that risk, and report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after you detect it, in the form or manner the CERT prescribes. |
|
| Law No. 08/L-173 on Cyber Security, Incident Reporting and Enforcement |
As an operator of essential services, notify the Agency for Cyber Security immediately, and no later than 24 hours after becoming aware, of a cyber incident with a significant impact on system security or service continuity, and notify affected persons or the public within a reasonable time where individual notice is impractical. As a digital service provider, notify the Agency for Cyber Security immediately upon becoming aware of a cyber incident with a significant impact on the digital service you provide. |
|
| Digital Code, digital resilience incident notification |
Notify the sectoral regulator with jurisdiction over your sector no later than 72 hours after you discover the incident; if you notify later than that, explain the reason for the delay in the notice. If you process data as a processor for a record owner, notify that record owner of an incident within the period your contract sets, and in any event no later than 48 hours after you discover it. +1 more |
|
| Nacionālās kiberdrošības likums, Incident Notification |
Immediately take all action necessary to contain a detected cyber incident, immediately inform the competent cyber incident prevention institution (in practice CERT.LV for most private-sector and civilian public-sector subjects), and follow its instructions. For a significant cyber incident, electronically submit an early warning to the competent institution without delay and no later than within 24 hours of becoming aware of it. +2 more |
|
| Cyber-Sicherheitsgesetz (CSG), Incident Notification |
Notify the Stabsstelle Cyber-Sicherheit (Cyber Security Office) without delay, and in any event within 24 hours of becoming aware of a significant security incident, with an early warning stating, where relevant, whether the incident is suspected to result from unlawful or malicious acts or to have cross-border effect. Follow with a full notification within 72 hours of becoming aware, updating the early warning where relevant and giving an initial assessment of the incident's severity and impact and, where available, indicators of compromise. |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification |
Notify NKSC of a significant cyber incident without delay and in any event within 24 hours of becoming aware of it. Follow within 72 hours of becoming aware with the incident's severity and impact assessment and any evidence of compromise; report a minor incident within 72 hours without a separate 24-hour early warning. +1 more |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification |
Notify the competent authority, without undue delay, of any incident with a significant impact on the provision of your services: treat an incident as significant where it has caused or is capable of causing severe operational disruption or financial loss to you, or considerable material, physical or moral damage to another person. Submit an early warning within 24 hours of becoming aware of the significant incident, stating whether it is suspected to result from unlawful or malicious acts or could have cross-border effect. +3 more |
|
| Cybersecurity Act 2025, Cybersecurity Incident Reporting Obligations |
Immediately notify the Director and the CSIRT-MH (the Cyber Security Incident Response Team of the Marshall Islands) of a significant cybersecurity incident affecting your critical information infrastructure, of a significant incident on any interconnected computer system under your control, or of any other incident type the Director specifies by written order. Submit an early warning within twenty-four hours of becoming aware of the incident, a fuller notification with an initial severity and impact assessment within seventy-two hours, and a final report within thirty days of that notification, or, for an ongoing incident, a thirty-day progress report followed by a final report within thirty days of the incident's resolution. |
|
| FSM Cybersecurity Act 2025 (Bill), Critical Information Infrastructure Incident Reporting Clock proposed |
Notify the Secretary of Justice and the CERT-FSM of a significant cybersecurity incident affecting your critical information infrastructure or an interconnected system: an early warning within 24 hours of becoming aware of it, a fuller notification within 72 hours, and a final report within 30 days of that notification. |
|
| Law on Cyber Security, Cyber-Attack Notification Duty for Other Legal Persons |
On a cyber-attack or violation against your systems, notify the relevant center against cyber-attacks and violations, the Public center for a legal person outside the state information network and outside critical information infrastructure, and obtain assistance where necessary; the text states no numeric clock for this notice. |
|
| Law on Information Security, Cyber Threat and Incident Reporting |
Where a cyber threat or incident has no effect on the continuity of your service, report it once a month to the Cybersecurity Agency (Article 29). Where a cyber threat or incident could significantly affect the continuity of your service, submit an initial notification to the Cybersecurity Agency within 24 hours of becoming aware of it, on the prescribed form (Article 30). |
|
| Loi n° 05-20 relative à la cybersécurité, Digital Service Provider and Platform Operator Incident and Vulnerability Notification Duties |
Inform your clients of a vulnerability in your information systems, or of a breach that could affect them. When you detect an event that could affect the security of a client's information systems, inform the national cybersecurity authority of it without delay. +1 more |
|
| Cyberbeveiligingswet, Significant-Incident Reporting Obligations |
Give your CSIRT and competent authority an early warning without delay, or within 24 hours of becoming aware of a significant incident if immediate reporting is not possible, stating whether the incident is suspected to result from unlawful or malicious action and whether it may have cross-border effects. Follow with a notification, without delay or within 72 hours, updating the early warning with an initial assessment of the incident's severity and effects. +1 more |
|
| New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent |
Notify the Superintendent electronically, in the form set forth on the Department's website, as promptly as possible but no later than 72 hours after you determine that a Cybersecurity Incident has occurred at your organization, an affiliate, or a third-party service provider: an event that requires notice to a government or supervisory body, that has a reasonable likelihood of materially harming a material part of your normal operations, or that results in the deployment of ransomware within a material part of your information systems. Where you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules. |
|
| Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, Reporting of Cyber Threats to the National CERT |
Immediately inform the National Computer Emergency Response Team (CERT) Coordination Center of any attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network. Report the incident to the National CERT within 7 days of its occurrence. Failing to do so is itself an offence, punishable by denial of internet services and a mandatory fine of N2,000,000 payable into the National Cyber Security Fund. |
|
| Ustawa o krajowym systemie cyberbezpieczeństwa (KSC), Zgłaszanie Incydentów Poważnych from , in 6 months |
Notify the competent sectoral CSIRT without delay, and in any event within 24 hours of detecting a significant incident, with an early warning. Follow with a fuller notification within 72 hours of detection, a periodic report on the CSIRT's request, and a final report no later than one month after the 72-hour notification. +1 more |
|
| Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations |
Notify the competent cybersecurity authority of any significant incident, weighing the number and share of users affected, the incident's duration, the severity of the service disruption and its economic and social impact. Submit an initial notification without undue delay and within 24 hours of concluding that a significant incident exists or may exist, and, where necessary, update it within 72 hours with an initial assessment of the incident's severity and impact; if the incident resolves within two hours of detection, submit only the end-of-impact notification below. |
|
| Ordonanța de urgență nr. 155/2024, Incident Notification |
Report to the national cybersecurity-incident-response team, without undue delay, any incident with a significant impact on the provision of your services, through the Platforma națională pentru raportarea incidentelor de securitate cibernetică (PNRISC). Submit an early warning within 24 hours of becoming aware of a significant incident, stating whether it is suspected unlawful, malicious, or cross-border in impact; follow with a fuller incident report within 72 hours giving an initial severity and impact assessment and any known indicators of compromise; submit an interim report if the CSIRT requests one; and submit a final report within one month of the 72-hour report, or a progress report followed by a final report if the incident is still ongoing at that point. +2 more |
|
| Law on Information Security, Incident Reporting Obligations |
Notify the single incident-reporting system, through the Ministry's or the Office for Information Security's website, of an incident that may significantly disrupt information security, without delay and at the latest within 24 hours of becoming aware of it. If you operate a banking or financial-market ICT system, send that notification to the National Bank of Serbia, and also to the Securities Commission if it supervises you; if you provide an electronic-communications or postal service, send it to the Regulatory Body for Electronic Communications and Postal Services instead. +2 more |
|
| Cyber Security and Crime Act, 2021, Reporting of Cyber Security Incidents |
Immediately inform the National Computer Security Incidence Response Team of an attack, intrusion, or other disruption liable to hinder the functioning of another computer system or network. Report the incident to the Team within 7 days of its occurrence even if you already gave the immediate notice section 53(1) requires; failing to do so, without reasonable excuse, is itself an offence distinct from any liability for the disruption reported. |
|
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification |
Report without undue delay, and no later than 24 hours after becoming aware of it, an early warning of a significant cyber security incident, stating in particular whether it may have been caused by unlawful conduct or may have a cross-border effect. No later than 72 hours after becoming aware of it, report a notification updating and completing the early warning, in particular an initial assessment of the incident's severity and impact. +1 more |
|
| Zakon o informacijski varnosti (ZInfV-1), Significant-Incident Notification Obligations |
Give your competent CSIRT group an early warning without delay, at latest within 24 hours of detecting a significant incident, stating whether it is suspected to result from an unlawful or malicious act and whether it may have a cross-border effect. Follow with a full notification without delay, at latest within 72 hours, updating the early warning with an initial assessment of the incident's severity and impact and any available threat indicators, then an interim report if the CSIRT group asks for one, and a final report at latest one month after the 72-hour notification, or a progress report and a final report within one month of resolution if the incident is still ongoing at that point. +1 more |
|
| Information and Communications Network Act, Report on Computer Security Incidents |
Immediately report a computer security incident to the Minister of Science and ICT or to the Korea Internet and Security Agency upon discovering it; a report already made for the same incident under another statute satisfies this duty and need not be repeated. |
|
| Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad, Incident Reporting Obligations proposed |
Expect a duty, once enacted, to notify the competent authority of a significant incident affecting the provision of your service, whether on your own networks or a third-party provider's. Expect a duty to communicate to the recipients of your service, as soon as possible, a significant cyberthreat that could affect them and any mitigating measures they can take. |
|
| Real Decreto-ley 12/2018, Incident Notification Obligation |
Notify the competent authority, through your reference CSIRT, without undue delay, of an incident that may have a significant disruptive effect on the provision of your service, whether on your own networks or a third-party provider's. For a CRITICO-severity incident under the national notification instruction, notify immediately, follow up with an interim notification within 24 to 48 hours, and file a final notification within 20 days; for a MUY ALTO-severity incident, notify immediately, follow up within 72 hours, and file a final notification within 40 days; an ALTO-severity incident requires only an immediate initial notification. |
|
| Cybersäkerhetslag, Incident Notification |
Inform the authority the government designates (in practice the CSIRT-enhet at Försvarets radioanstalt) of a significant incident as soon as you can, and no later than 24 hours after becoming aware of it. Follow with a formal incident notification to the same authority as soon as you can; if you provide a trust service, no later than 24 hours after becoming aware, and otherwise no later than 72 hours after becoming aware. +2 more |
|
| Cyber Security Management Act, Cyber Security Incident Reporting |
Notify the central competent authority in charge of the relevant sector as soon as the agency becomes aware of a cyber security incident. |
|
| Cybersecurity Act 2025, Duty to Report a Cybersecurity Incident from a date not yet set |
Within 24 hours of becoming aware of it, report to the Computer Emergency Response Team (CERT) a cybersecurity incident relating to the information systems of your designated critical infrastructure, an incident relating to any information system interconnected with or communicating with those systems, or any other cybersecurity incident or occurrence the Minister CPR has designated as requiring notification. File that report in the form the Minister CPR prescribes. |
|
| Cybersecurity Incident Reporting and Emergency Response |
Immediately inform the national contact point or your emergency response center of any cybersecurity incident or attack, and comply with the emergency measures either one orders. |
|
| Cybersecurity Law, Reporting and Cooperation Duties |
Report a detected vulnerability or cyber incident in the area of service provided to the Cybersecurity Directorate without delay; the Law's own text sets no numeric reporting clock. |
|
| Law on the Basic Principles of Ensuring Cybersecurity, CERT-UA Incident Notification Duty |
Inform CERT-UA immediately (невідкладно, without delay; the statute states no fixed hour clock) of a cybersecurity incident affecting your critical infrastructure object's communication or technological systems. |
|
| Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers |
If your organization is a banking organization, notify your primary federal banking regulator, the OCC, the Federal Reserve Board, or the FDIC, whichever supervises it, about a notification incident, as soon as possible and no later than 36 hours after your organization determines that a notification incident has occurred. A notification incident is the subset of computer-security incidents that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, your ability to serve customers, a business line, or an operation whose failure would threaten the financial stability of the United States, so a computer-security incident that falls short of that threshold does not by itself start this clock. If your organization is a bank service provider, notify at least one bank-designated point of contact at each affected banking organization customer as soon as possible after your organization determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services provided to that banking organization for a period of four hours or more. This duty carries a standard, as soon as possible, rather than a fixed number of hours to notify by, and that disruption threshold is what engages the duty rather than a period to notify within. |
|
| Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) from a date not yet set |
Once the final rule takes effect, report a covered cyber incident to the Agency not later than 72 hours after your organization reasonably believes that the covered cyber incident has occurred. Once the final rule takes effect, report a ransom payment to the Agency not later than 24 hours after your organization makes the payment, even where the underlying ransomware attack is not itself a covered cyber incident. |
|
| Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) |
Rapidly report a cyber incident to the Department of Defense within 72 hours of discovering it, at the Department's DIBNet portal (dibnet.dod.mil), using a DoD-approved medium assurance certificate that you must obtain before you need to file a report. |
|
| SEC Cybersecurity Risk Management, Governance, and Incident Disclosure (Regulation S-K Item 106; Form 8-K Item 1.05) |
If your organization is an SEC reporting company, determine, without unreasonable delay after you discover a cybersecurity incident, whether the incident is material, and if it is, file a Form 8-K under Item 1.05 within four business days after you make that determination. |
|
| Law on Cybersecurity, cybersecurity incident notification duty |
Notify the State Security Service of any cybersecurity incident or cybercrime affecting your information systems or resources as soon as it occurs; the statute sets no numeric deadline or severity threshold. |
|
| Cybersecurity Law, Incident Response and Reporting Duties |
As the manager of an information system, connect its cybersecurity monitoring to the National Cybersecurity Centre of the Ministry of Public Security, or to the Ministry of National Defence's centre for a military system, and report a cybersecurity incident to that specialised force. As an enterprise providing a service on a telecommunications network, the Internet, or another value-added service in cyberspace in Vietnam, warn users of the cybersecurity risks in the service and give guidance on preventive measures, and keep an emergency response plan ready to address cybersecurity weaknesses, risks and incidents. +1 more |
Sector security regimes
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 25/2024, On Cybersecurity |
Report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs, and inform the public or affected users where the incident reaches them; cooperate with AKSK and other operators in sharing cybersecurity threat, vulnerability and incident information. AKSK's own incident categorisation and log retention regulations set the reporting clock and severity thresholds that apply to your designated category. |
|
| Digital Code, Livre II: Trust Service Provider Security Risk-Management Duty |
Prevent and limit the consequences of security incidents, inform the parties concerned of the harmful effects of such incidents, and ensure the continuity of your services in the event of technical failures or cessation of activity. |
|
| Digital Code, Book II: Electronic Communications Network and Service Security |
Where a particular risk of a security breach exists, inform your users of the risk without delay, of any available remedy, and of its cost. As soon as you become aware of a security breach or integrity loss with a significant impact on your network's or service's operation, notify the cybersecurity authority and the telecoms regulator by registered letter with acknowledgement of receipt. No numeric clock is stated for this notice, unlike the 24-hour clock this jurisdiction's Digital Code sets for a trust service provider or the 72-hour clock it sets for a personal-data breach. |
|
| Cybersecurity Act, Risk-Management Measures |
Report a cyber threat, near-incident or cybersecurity incident affecting your electronic information system to the competent cybersecurity incident-handling centre without delay, on the notification clock this jurisdiction's companion incident-notification row sets out. |
|
| Banque du Liban Basic Circular No. 144 (Prevention of Electronic Criminal Acts) |
On learning that a customer has fallen victim to a financially-natured electronic crime, notify Lebanon's Special Investigation Commission of the relevant technical information and direct the customer to file a judicial complaint. |
|
| National Cybersecurity Law (2025) |
As a designated Critical Information Infrastructure operator, meet the cybersecurity standards the National Communications Authority sets and comply with its incident reporting obligations; the located text does not state a reporting clock, a reporting threshold, or a penalty for a missed report. |
Product security requirements
5 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produits |
Inform consumers of every vulnerability detected in that test, together with the solution recommended to remedy it. |
|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Maintain a public, Portuguese-language support page listing known vulnerabilities in your products together with their mitigations, and keep making corrected software or firmware available. |
|
| Cybersecurity Law, Network Product and Service Security Duties |
On discovering a security defect, vulnerability, or other risk in your product or service, immediately take remedial measures, notify affected users as provided, and report the defect or vulnerability to the competent authority; the statute states no numeric clock for this notice, only immediacy. |
|
| Digital Code, Livre IV: ICT Product and Service Vendor Security Certification |
Inform consumers of every vulnerability detected in your information and communication technology products and services, and of the solutions you have deployed to remedy them. |
|
| Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience Act |
Report an actively exploited vulnerability in your product with digital elements, or a severe incident affecting its security, to Finland's CSIRT unit under the Regulation's own Article 14 clock; this Act only directs the report to that unit and does not restate the duty or its deadline. |
Security baseline statutes
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program |
To claim the defense against a tort claim alleging that a failure to implement reasonable information security controls resulted in a data breach of personal information or restricted information, create, maintain, and comply with a written cybersecurity program containing administrative, technical, operational, and physical safeguards, designed to continually evaluate and mitigate reasonably anticipated threats, evaluate the maximum probable loss from a data breach at least annually, and communicate to affected parties the extent of any risk and steps to reduce damages once a breach is known to have occurred. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.