Law / Frameworks / NIST CSF 2.0 / Respond

NIST CSF 2.0, RespondRS.CO-03

Information is shared with designated internal and external stakeholdersNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.CO-03

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

36
laws
34
places
0
with court rulings behind them
4
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Albania
  • Andorra
  • Austria
  • Belgium
  • Cyprus
  • Czech Republic
  • Democratic Republic of the Congo
  • Denmark
  • Estonia
  • Ethiopia
  • European Union
  • Finland
  • Germany
  • Greece
  • Haiti
  • Hungary
  • India
  • Ireland
  • Italy
  • Kiribati
  • Latvia
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Montenegro
  • Netherlands
  • New York
  • Portugal
  • Serbia
  • Slovakia
  • Sweden
  • Turkey
  • United States
  • Uzbekistan

Vulnerability and incident reporting

34 laws, 32 places
PlaceLawWhat it asks, as read here
Andorra Llei 22/2022, Incident Handling and Notification Obligation

Notify the competent authority, through the CSIRT-AD and without delay, of a significant cyber threat to your essential or important service that you believe could result in a significant incident, once the threshold for that duty is further specified by regulation.

Austria Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations

Include in the notification every relevant detail known at the time, including the suspected or actual cause, the affected information technology, and the type of entity or facility affected; report later developments in follow-up and final notifications.

Austria Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations from , in 2 days

Submit an interim report on request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have resolved it.

Belgium Loi du 26 avril 2024, Significant-Incident Notification Obligations

Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact.

Cyprus Security of Networks and Information Systems Law, Incident Notification Obligations

Submit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation).

Czech Republic Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification

Submit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution.

Democratic Republic of the Congo Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty

Cooperate in detecting cyberattacks in accordance with the applicable legal and regulatory provisions.

Denmark NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties

Submit an interim report if your CSIRT asks for one, and a final report no later than one month after your notification, describing the incident in detail, its severity and impact, the likely threat or root cause, mitigating measures applied and under way, and any cross-border effects. If the incident is still ongoing at that point, submit a status report instead and the final report within one month of the incident being handled.

Estonia Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident

Submit an interim report if RIA asks for one, and a final report within one month of the incident report, or, if the incident is still unresolved at that point, treat that report as interim and submit a further final report within one month of resolution.

Ethiopia Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT from , in 10 months

Provide the National Computer Emergency Response Center the information it requests and cooperate appropriately with its activities when it is responding to a cyberattack.

Show the other 24 laws
European Union DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301

Submit an intermediate report within 72 hours of the initial notification, and update it without undue delay whenever the incident's status changes significantly or you recover normal activity.

Submit a final report no later than one month after the intermediate report, or your latest updated one, once you know the root cause and the actual impact figures.

+1 more
Finland Kyberturvallisuuslaki, Significant-Incident Reporting Obligations

Provide an interim report on the authority's request, or within one month of your follow-up notification if the incident is long-running, and a final report within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken, and any cross-border effects.

Germany BSI-Gesetz (BSIG), Incident Notification

Submit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.

Greece Law 5160/2024, Significant-Incident Reporting Obligations

Submit an interim report if the National Cybersecurity Authority requests one.

Submit a final report no later than one month after the 72-hour notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border impact; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of its resolution.

Hungary Cybersecurity Act, Incident Notification and Cybersecurity Fine

Submit an interim status report if the centre asks for one, and, if the incident is still ongoing when the final report is due, a report on the results achieved so far followed by a final report within one month of the incident's resolution.

India CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation

Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to.

Ireland European Union (NIS) Regulations 2018, Incident Notification

Notify the CSIRT again once the incident has been resolved.

Italy Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification

Submit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution).

Kiribati Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident from a date not yet set

Provide any further information the National CERT or a Sectoral CERT requests about the incident, and allow either CERT to access your network and information infrastructure to analyse the incident, detect other threats, identify vulnerabilities, and advise on preventative, mitigating or remedial measures.

Latvia Nacionālās kiberdrošības likums, Incident Notification

Within one month of the initial report, submit a final report on the incident's resolution, or, if it is still unresolved at that point, a progress report followed by a final report once you have resolved it; submit an intermediate report if the competent institution requests one.

Liechtenstein Cyber-Sicherheitsgesetz (CSG), Incident Notification

Submit an intermediate report on the Stabsstelle Cyber-Sicherheit's request, and a final report within one month of the 72-hour notification, describing the incident's severity and impact in detail, the likely threat or root cause, and the mitigation measures taken.

Lithuania Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification

Submit a final report within one month of the incident's registration, and an interim report on NKSC's request.

Luxembourg Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification

Submit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it.

Montenegro Law on Information Security, Cyber Threat and Incident Reporting

For an incident the Agency rates medium, submit a first report within 72 hours of your initial notification, a further report without delay on any new development, continuing reports every 72 hours while the incident lasts, and a final report within 30 days of resolving it (Article 33).

For an incident the Agency rates high, follow the same reporting sequence on a tighter clock: continuing reports every 24 hours while the incident lasts (Article 34).

Netherlands Cyberbeveiligingswet, Significant-Incident Reporting Obligations

Submit an interim report if your CSIRT or competent authority asks for one.

Submit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution.

New York New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent

Promptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty.

Where you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules.

Portugal Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations

Submit a final report within 30 working days of your end-of-impact notification, describing the incident, its impact, the mitigating measures you took and any residual impact still present, and submit an interim report if the competent authority asks for one.

Serbia Law on Information Security, Incident Reporting Obligations

While the incident continues, submit a status report to the single incident-reporting system every three days for a medium-level incident, or every 24 hours for a high or very high-level incident.

Submit a final report within 15 days after the incident ends, covering its type, cause, duration, scope of impact, any cross-border effect, and the steps you took to remedy it.

+1 more
Slovakia Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification

On the CSIRT unit's request, report updated or other requested information about how the incident is progressing.

No later than one month after the 72-hour notification, report a final report describing the incident, its severity and impact, the threat type or probable root cause, the mitigating measures taken and under way, and any cross-border impact.

+1 more
Sweden Cybersäkerhetslag, Incident Notification

On the authority's request, submit an interim report with relevant status updates on the significant incident.

No later than one month after your incident notification, submit a final report; if the significant incident is still ongoing at that point, submit a progress report instead and a final report within one month after you have resolved it.

Turkey Cybersecurity Law, Reporting and Cooperation Duties

Provide the Cybersecurity Directorate promptly with any data, information, document, hardware, software, or other contribution it requests in connection with its duties.

United States Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) from a date not yet set

Once the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes.

United States Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012)

Submit any malicious software you isolate in connection with a reported incident to the Department of Defense Cyber Crime Center, following that Center's instructions, and never send it to the contracting officer.

Uzbekistan Law on Cybersecurity, cybersecurity incident notification duty

If you investigate the incident yourself because you hold the resources and technical means to do so, report the results to the State Security Service.

Sector security regimes

2 laws, 2 places
PlaceLawWhat it asks, as read here
Albania Law No. 25/2024, On Cybersecurity

Report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs, and inform the public or affected users where the incident reaches them; cooperate with AKSK and other operators in sharing cybersecurity threat, vulnerability and incident information. AKSK's own incident categorisation and log retention regulations set the reporting clock and severity thresholds that apply to your designated category.

Haiti BRH Circulaire 126, Information Security Rules for Financial Institutions

Keep your security committee systematically informed of incidents capable of compromising information security and of the measures taken to address them.

Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.