Guide

The incident clocks: DORA, NIS2, and GDPR side by side

Practitioner guide · 7 min read · Updated July 2026

When a serious incident lands, the hardest part often isn't the response — it's the paperwork racing a stopwatch. Different regimes start different clocks, in different formats, to different regulators, all at once. Here's how the major EU clocks line up.

When the clock starts

A common misconception is that the deadline runs from when the incident happened. In practice it runs from awareness or classification of a qualifying event. Under GDPR that's becoming aware of a personal-data breach; under DORA and NIS2 it's classifying an incident as major or significant. That classification moment — call it T-zero — is when every applicable clock begins, which is why fast, accurate classification matters so much.

Regime
Headline deadlines
Reported to
DORA
≈4h initial · intermediate · final
Competent financial authority
NIS2
24h warning · 72h notice · 1mo final
CSIRT / national authority
GDPR
72h notification
Supervisory authority (+ data subjects if high risk)
EU baseline; national transposition varies. Informational, not legal advice. Last verified July 2026.

The parallel-filing problem

The real difficulty is that one incident can trip several clocks simultaneously. A ransomware event at a payments processor can be a DORA major incident, a NIS2 significant incident, and a GDPR personal-data breach at the same time. Three clocks, three formats, three recipients — and the four-hour DORA notification is running while your team is still confirming scope.

Handled manually, that means parallel drafting under time pressure, with real risk of a missed deadline or an inconsistent story across filings. The way out is to decide, once and in advance, which regimes bind you — and to let a system schedule and pre-draft each filing the moment an incident is classified.

Running the clocks with CIIC

This is exactly what Polestead's CIIC (Critical Incident Intelligence Center) does. It maps your business profile to the regimes that apply, and on classification it starts every clock at once, produces the next-step plan, and drafts each regulator-ready report in parallel — so the deadline is a schedule, not a scramble. See the CIIC page for detail, or book a demo.

FAQ

Quick answers.

When does the clock start?+

Generally at awareness or classification of a qualifying incident, not when it began — GDPR on breach awareness, DORA/NIS2 on major/significant classification.

Can one incident trigger several regimes?+

Yes — DORA, NIS2, and GDPR can all apply to one event. Each has its own clock and format, so they must be tracked and filed in parallel.

What are the headline deadlines?+

DORA ≈4h initial then intermediate/final; NIS2 24h/72h/1-month; GDPR 72h to the supervisory authority. Always verify national specifics.