Incident reporting is the measure that is easiest to describe and hardest to execute. The reason is simple: every other measure gets done in working hours, and this one at three in the morning, while you are simultaneously trying to stop what is happening.
Three deadlines under the Act
| Deadline | What is sent | Content |
|---|---|---|
| 24 hours | Early warning | That a significant incident has occurred, an initial view on whether it results from an unlawful act and whether it may have cross-border impact. |
| 72 hours | Incident notification | Updated assessment, indicators of compromise, severity and impact. |
| 30 days | Final report | Detailed description, threat type and root cause, measures applied and planned, cross-border effect. |
The deadlines run from becoming aware of the incident, not from when it occurred and not from when the investigation concludes. That distinction decides whether you are within the deadline.
Enter the moment of awareness in the deadline calculator and get all five dates at once, including the parallel GDPR notification. It runs in your browser and needs no sign-up.
The 24-hour deadline is not a deadline for explaining what happened. It is a deadline for reporting that something happened. Teams that wait to understand the incident before sending the early warning routinely miss the first deadline, and have gained nothing in return.
The fourth deadline, running alongside
If the incident also involves a personal data breach, a separate 72-hour deadline for notifying the data protection authority runs alongside the ones under the Act, under Article 33 GDPR. It is a separate notification, to a different authority, with different content.
The two do not cancel each other out and they do not run in sequence. Ransomware that halted production and simultaneously exfiltrated an HR database creates both obligations in the same hour.
What has to be ready beforehand, not afterwards
- A significance criterion. Someone has to be able to say within the hour whether this is a significant incident. If that question is being asked for the first time during the incident, the clock is already running.
- A named person and a deputy. Incidents do not confine themselves to working days. If only one person can send the notification, you have an availability risk inside the measure itself.
- Prepared forms. An early warning template with fields to fill in, not a document to be written.
- Contact details for the competent CSIRT and credentials for the reporting channel, verified before they are needed.
- A decision path for the parallel notification. Who assesses whether a personal data breach is involved, and who then notifies the data protection authority.
- Records. Time of awareness, who decided what, and when each item was sent. That is your evidence of being within the deadline.
The exercise is worth more than the plan
An incident response plan that has never been tested documents intent, not capability. A two-hour tabletop exercise with a scenario and real measurement of the time to a prepared early warning will reveal more than another round of editing the document. In practice it usually reveals that nobody is sure who makes the significance call.
Incident reporting sits under measure 11 of Annex II, but the evidence base overlaps with measure 12 (business continuity and cyber crisis management). If the incident response plan and the continuity plan are written as two unconnected documents, the work is being done twice.
Sources
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.