Law / Frameworks / NIST CSF 2.0 / Respond
NIST CSF 2.0, RespondRS.CO-03
Information is shared with designated internal and external stakeholdersNIST Cybersecurity Framework, version 2.0, February 2024 (NIST CSWP 29), RS.CO-03
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 36
- laws
- 34
- places
- 0
- with court rulings behind them
- 4
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI 600-1GAI-RISK-09 Information Security
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations4.3 Incident Reporting
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkGV.MT-P4 Policies, processes, and procedures for communicating progress on managing privacy...
A law in force is unmarked; the rest wear their state: not yet in force
Vulnerability and incident reporting
34 laws, 32 places| Place | Law | What it asks, as read here |
|---|---|---|
| Llei 22/2022, Incident Handling and Notification Obligation |
Notify the competent authority, through the CSIRT-AD and without delay, of a significant cyber threat to your essential or important service that you believe could result in a significant incident, once the threshold for that duty is further specified by regulation. |
|
| Netz- und Informationssystemsicherheitsgesetz (NISG), Incident Notification Obligations |
Include in the notification every relevant detail known at the time, including the suspected or actual cause, the affected information technology, and the type of entity or facility affected; report later developments in follow-up and final notifications. |
|
| Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026), Significant-Incident Reporting Obligations from , in 2 days |
Submit an interim report on request, and a final report no later than one month after the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have resolved it. |
|
| Loi du 26 avril 2024, Significant-Incident Notification Obligations |
Submit an interim report if the national CSIRT or the competent sectoral authority asks for one, and a final report no later than one month after the incident notification, describing the incident in detail, its severity and impact, the likely threat or root cause, the mitigation measures applied and in progress, and any cross-border impact. |
|
| Security of Networks and Information Systems Law, Incident Notification Obligations |
Submit an intermediate report on the Authority's request, and a final report within one month of the incident notification (or, for an incident still ongoing at that point, a progress report every fifteen days, and a final report within fifteen days of restoring the affected network or information system's normal operation). |
|
| Cybersecurity Act (Zákon o kybernetické bezpečnosti), Incident Notification |
Submit an interim report on request, and a final report no later than 30 days after the 72-hour report, or, if the incident is still ongoing at that point, a progress report followed by a final report within 30 days of resolution. |
|
| Digital Code, Livre IV: General Cyberattack Cooperation and Incident-Reporting Duty |
Cooperate in detecting cyberattacks in accordance with the applicable legal and regulatory provisions. |
|
| NIS 2-loven, Significant-Incident Reporting and Recipient-Notice Duties |
Submit an interim report if your CSIRT asks for one, and a final report no later than one month after your notification, describing the incident in detail, its severity and impact, the likely threat or root cause, mitigating measures applied and under way, and any cross-border effects. If the incident is still ongoing at that point, submit a status report instead and the final report within one month of the incident being handled. |
|
| Küberturvalisuse seadus (KüTS), Duty to Notify of a Cyber Incident |
Submit an interim report if RIA asks for one, and a final report within one month of the incident report, or, if the incident is still unresolved at that point, treat that report as interim and submit a further final report within one month of resolution. |
|
| Critical Infrastructure Cybersecurity Proclamation, Cyber Incident Reporting to National CERT from , in 10 months |
Provide the National Computer Emergency Response Center the information it requests and cooperate appropriately with its activities when it is responding to a cyberattack. |
Show the other 24 laws
| DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301 |
Submit an intermediate report within 72 hours of the initial notification, and update it without undue delay whenever the incident's status changes significantly or you recover normal activity. Submit a final report no later than one month after the intermediate report, or your latest updated one, once you know the root cause and the actual impact figures. +1 more |
|
| Kyberturvallisuuslaki, Significant-Incident Reporting Obligations |
Provide an interim report on the authority's request, or within one month of your follow-up notification if the incident is long-running, and a final report within one month of the follow-up notification, or within one month of the incident's resolution if it is still ongoing at that point, describing the incident, its likely root cause, mitigation measures taken, and any cross-border effects. |
|
| BSI-Gesetz (BSIG), Incident Notification |
Submit an intermediate report on the BSI's request, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it. |
|
| Law 5160/2024, Significant-Incident Reporting Obligations |
Submit an interim report if the National Cybersecurity Authority requests one. Submit a final report no later than one month after the 72-hour notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border impact; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of its resolution. |
|
| Cybersecurity Act, Incident Notification and Cybersecurity Fine |
Submit an interim status report if the centre asks for one, and, if the incident is still ongoing when the final report is due, a report on the results achieved so far followed by a final report within one month of the incident's resolution. |
|
| CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation |
Enable logs of all your ICT systems and retain them securely, within Indian jurisdiction, on a rolling 180-day basis, and provide them to CERT-In together with an incident report or when CERT-In orders or directs you to. |
|
| European Union (NIS) Regulations 2018, Incident Notification |
Notify the CSIRT again once the incident has been resolved. |
|
| Decreto Legislativo 4 settembre 2024, n. 138 (Decreto NIS2), Incident Notification |
Submit an intermediate report on CSIRT Italia's request, and a final report within one month of the notification (or, for an incident still ongoing at that point, a monthly progress report and a final report within one month of the incident's resolution). |
|
| Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident from a date not yet set |
Provide any further information the National CERT or a Sectoral CERT requests about the incident, and allow either CERT to access your network and information infrastructure to analyse the incident, detect other threats, identify vulnerabilities, and advise on preventative, mitigating or remedial measures. |
|
| Nacionālās kiberdrošības likums, Incident Notification |
Within one month of the initial report, submit a final report on the incident's resolution, or, if it is still unresolved at that point, a progress report followed by a final report once you have resolved it; submit an intermediate report if the competent institution requests one. |
|
| Cyber-Sicherheitsgesetz (CSG), Incident Notification |
Submit an intermediate report on the Stabsstelle Cyber-Sicherheit's request, and a final report within one month of the 72-hour notification, describing the incident's severity and impact in detail, the likely threat or root cause, and the mitigation measures taken. |
|
| Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification |
Submit a final report within one month of the incident's registration, and an interim report on NKSC's request. |
|
| Loi du 5 mai 2026 relative à la cybersécurité (NIS2), Incident Notification |
Submit an intermediate report if a CSIRT or the competent authority requests one, and a final report within one month of the 72-hour notification, or, if the incident is still ongoing at that point, a progress report followed by a final report once you have finished handling it. |
|
| Law on Information Security, Cyber Threat and Incident Reporting |
For an incident the Agency rates medium, submit a first report within 72 hours of your initial notification, a further report without delay on any new development, continuing reports every 72 hours while the incident lasts, and a final report within 30 days of resolving it (Article 33). For an incident the Agency rates high, follow the same reporting sequence on a tighter clock: continuing reports every 24 hours while the incident lasts (Article 34). |
|
| Cyberbeveiligingswet, Significant-Incident Reporting Obligations |
Submit an interim report if your CSIRT or competent authority asks for one. Submit a final report no later than one month after your notification, describing the incident in detail, its severity and effects, the likely threat or root cause, mitigating measures applied, and any cross-border effects; if the incident is still ongoing at that point, submit a progress report instead and the final report within one month of resolution. |
|
| New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent |
Promptly provide the Superintendent any information requested about a reported incident, and continue updating the Superintendent with material changes or new information previously unavailable; the regulation states no separate numbered clock for either duty. Where you make an extortion payment in connection with a cybersecurity event, notify the Superintendent of the payment within 24 hours of making it, and within 30 days of the payment provide a written description of why the payment was necessary, the alternatives you considered, and the diligence you performed, including under Office of Foreign Assets Control rules. |
|
| Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations |
Submit a final report within 30 working days of your end-of-impact notification, describing the incident, its impact, the mitigating measures you took and any residual impact still present, and submit an interim report if the competent authority asks for one. |
|
| Law on Information Security, Incident Reporting Obligations |
While the incident continues, submit a status report to the single incident-reporting system every three days for a medium-level incident, or every 24 hours for a high or very high-level incident. Submit a final report within 15 days after the incident ends, covering its type, cause, duration, scope of impact, any cross-border effect, and the steps you took to remedy it. +1 more |
|
| Zákon o kybernetickej bezpečnosti (Cybersecurity Act), Incident and Vulnerability Notification |
On the CSIRT unit's request, report updated or other requested information about how the incident is progressing. No later than one month after the 72-hour notification, report a final report describing the incident, its severity and impact, the threat type or probable root cause, the mitigating measures taken and under way, and any cross-border impact. +1 more |
|
| Cybersäkerhetslag, Incident Notification |
On the authority's request, submit an interim report with relevant status updates on the significant incident. No later than one month after your incident notification, submit a final report; if the significant incident is still ongoing at that point, submit a progress report instead and a final report within one month after you have resolved it. |
|
| Cybersecurity Law, Reporting and Cooperation Duties |
Provide the Cybersecurity Directorate promptly with any data, information, document, hardware, software, or other contribution it requests in connection with its duties. |
|
| Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) from a date not yet set |
Once the final rule takes effect, promptly submit an update to a previously submitted covered cyber incident report whenever substantial new or different information becomes available or a ransom payment is later made, continuing until your organization notifies the Agency that the incident has concluded and been fully mitigated and resolved, and preserve data relevant to the incident or payment under the procedures the final rule establishes. |
|
| Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) |
Submit any malicious software you isolate in connection with a reported incident to the Department of Defense Cyber Crime Center, following that Center's instructions, and never send it to the contracting officer. |
|
| Law on Cybersecurity, cybersecurity incident notification duty |
If you investigate the incident yourself because you hold the resources and technical means to do so, report the results to the State Security Service. |
Sector security regimes
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Law No. 25/2024, On Cybersecurity |
Report a significant or substantial cybersecurity incident to AKSK and the relevant CSIRTs, and inform the public or affected users where the incident reaches them; cooperate with AKSK and other operators in sharing cybersecurity threat, vulnerability and incident information. AKSK's own incident categorisation and log retention regulations set the reporting clock and severity thresholds that apply to your designated category. |
|
| BRH Circulaire 126, Information Security Rules for Financial Institutions |
Keep your security committee systematically informed of incidents capable of compromising information security and of the measures taken to address them. |
Full text of the NIST Cybersecurity Framework, public domain (a US government work). Every control of the framework.