US and EU cyber incident reporting deadlines
us_eu_incident_reporting_deadlinesIncident-reporting clocks under SEC Form 8-K/6-K, NYDFS Part 500, the US bank 36-hour rule, HIPAA, the FTC Safeguards Rule, NIS2, DORA, GDPR and the EU Cyber Resilience Act, each from its own trigger. Give aware_at (and decided_at for materiality/classification clocks) for wall-clock due times.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| sec | Yes | SEC status. | |
| dora | Yes | DORA status. | |
| gdpr | Yes | GDPR role for the personal data involved. | |
| nis2 | Yes | An essential or important entity under NIS2. | |
| hipaa | Yes | HIPAA role. | |
| nydfs | Yes | Regulated by the New York DFS (23 NYCRR 500). | |
| us_bank | Yes | A US banking organisation under the 36-hour computer-security incident rule. | |
| aware_at | No | Optional. When the entity became aware, ISO 8601 with offset. | |
| decided_at | No | Optional. When materiality/reportability/major classification was determined, ISO 8601 with offset. | |
| ftc_safeguards | Yes | A non-bank financial institution under the FTC Safeguards Rule. | |
| cra_manufacturer | Yes | A manufacturer of products with digital elements under the EU CRA. | |
| bank_service_provider | Yes | A bank service provider under the same rule. |