When a serious incident lands, the hardest part often isn't the response — it's the paperwork racing a stopwatch. Different regimes start different clocks, in different formats, to different regulators, all at once. Here's how the major EU clocks line up.
A common misconception is that the deadline runs from when the incident happened. In practice it runs from awareness or classification of a qualifying event. Under GDPR that's becoming aware of a personal-data breach; under DORA and NIS2 it's classifying an incident as major or significant. That classification moment — call it T-zero — is when every applicable clock begins, which is why fast, accurate classification matters so much.
The real difficulty is that one incident can trip several clocks simultaneously. A ransomware event at a payments processor can be a DORA major incident, a NIS2 significant incident, and a GDPR personal-data breach at the same time. Three clocks, three formats, three recipients — and the four-hour DORA notification is running while your team is still confirming scope.
Handled manually, that means parallel drafting under time pressure, with real risk of a missed deadline or an inconsistent story across filings. The way out is to decide, once and in advance, which regimes bind you — and to let a system schedule and pre-draft each filing the moment an incident is classified.
This is exactly what Polestead's CIIC (Critical Incident Intelligence Center) does. It maps your business profile to the regimes that apply, and on classification it starts every clock at once, produces the next-step plan, and drafts each regulator-ready report in parallel — so the deadline is a schedule, not a scramble. See the CIIC page for detail, or book a demo.
Generally at awareness or classification of a qualifying incident, not when it began — GDPR on breach awareness, DORA/NIS2 on major/significant classification.
Yes — DORA, NIS2, and GDPR can all apply to one event. Each has its own clock and format, so they must be tracked and filed in parallel.
DORA ≈4h initial then intermediate/final; NIS2 24h/72h/1-month; GDPR 72h to the supervisory authority. Always verify national specifics.