| SEC Item 1.05 | 4 business days from materiality determination |
in force |
| NYDFS Part 500 | 72h incident notice; 24h extortion-payment notice |
in force |
| EU NIS2 | 24h early warning; 72h notification; 1-month final |
per national law |
| EU DORA | 4h/24h initial; 72h intermediate; 1-month final |
in force |
| EU CRA | 24h early warning; 72h notification; 14-day final |
from 2026-09-11 |
| GDPR | 72h to the supervisory authority |
in force |
| Australia ransomware payment | 72h from payment |
in force |
| Singapore CII | 2h for essential-service disruption (amended Act) |
in force |
| FTC Safeguards | 30 days to the FTC, 500+ consumers |
in force |
| NY hospitals (405.46) | 72h to NYS DOH |
in force |
| India CERT-In directions | 6h |
in force since 2022 |
| US CIRCIA | 72h incident; 24h ransom payment (statutory) |
pending final rule |
| UK CS&R Bill | 24h initial; 72h full |
pending |
| Australia SOCI Act (Part 2B) | 12h significant impact (written follow-up 84h); 72h relevant impact; to ASD/ACSC |
in force |
| UK NIS Regulations 2018 | without undue delay and no later than 72h after awareness, to the competent authority (reg 11(3)) |
in force |
| South Korea PIPA | 72h to notify data subjects and report to PIPC (1,000+ subjects, sensitive data, or external unauthorised access); trigger widened to 'possibility of a breach' by the 2026 amendment |
in force; amendment effective 2026-09-11 |
| Japan APPI | preliminary report to PPC promptly (PPC guideline: within 3-5 days); final report 30 days (60 days where the cause is malicious) |
in force since 2022-04-01 |