Breach & incident deadline calculator

Enter the moment you became aware of a data breach or cyber incident, tick the laws that apply, and get every reporting deadline: GDPR, NIS2, DORA, the Cyber Resilience Act and eIDAS. Exact times in your time zone and in UTC, live countdowns, what each report must contain, and a calendar file with reminders.

Rules checked against EUR-Lex as of 1 October 2026
1. When did you become aware?

The moment you had a reasonable degree of certainty that a breach or significant incident occurred.

2. Which regimes apply?

Tick all that apply. One incident can trigger several reporting duties at once. Each item explains when it applies.

Your result appears here as you fill in the form.

How the deadlines are calculated

Every clock starts from one timestamp: when your organisation became aware. Hour-based periods are added as real elapsed hours, so a 72-hour period that crosses the end of summer time ends at a different clock time than it started. Month-based periods end on the same calendar date and clock time one month later (31 January plus one month is 28 or 29 February). Where a report counts from an earlier report, the tool assumes you send that earlier report exactly at its deadline, unless you enter when you actually sent it.

RegimeReportDeadlineLegal basis
GDPRNotify the supervisory authority72 h after awareness, "where feasible"Art. 33(1) GDPR
GDPRInform data subjects (high risk)Without undue delayArt. 34 GDPR
NIS2Early warning24 h after awarenessArt. 23(4)(a) NIS2
NIS2Incident notification72 h after awareness (24 h for trust service providers)Art. 23(4)(b) and second subparagraph
NIS2Final report1 month after the incident notificationArt. 23(4)(d)-(e)
DORAInitial notification4 h after classification as major, at most 24 h after awarenessRTS 2025/301 Art. 5(1)(a), 5(2)
DORAIntermediate report72 h after the initial notificationRTS 2025/301 Art. 5(1)(b)
DORAFinal report1 month after the latest intermediate reportRTS 2025/301 Art. 5(1)(c)
CRAVulnerability: early warning / notification / final24 h / 72 h / 14 days after a fix is availableArt. 14(2) CRA
CRASevere incident: early warning / notification / final24 h / 72 h / 1 month after the notificationArt. 14(4) CRA
eIDASNotify the supervisory body24 h (qualified TSPs: "of the incident"; others: of becoming aware)Arts. 24(2)(fb), 19a eIDAS

When does the clock start?

All of these laws count from awareness, not from the moment the attacker got in. The EDPB's Guidelines 9/2022 on personal data breach notification describe awareness as having a reasonable degree of certainty that a security incident has compromised personal data. For NIS2, recital 31 of Implementing Regulation (EU) 2024/2690 uses the same idea: you are aware once an initial assessment gives you reasonable certainty that a significant incident occurred. Two practical consequences:

  • A suspicious alert obliges you to assess it promptly. Parking it for a week does not delay the clock; regulators look at when you should have known.
  • Write down the awareness moment and who decided it. That timestamp is the first thing an authority asks about when a notification is late.

The one exception in this tool is eIDAS for qualified trust service providers: Article 24(2)(fb) says "within 24 hours of the incident". If the incident started before you noticed, enter its start time.

Weekends, public holidays and time zones

GDPR, NIS2, CRA and eIDAS clocks do not stop. Under Regulation (EEC, Euratom) No 1182/71, periods include Saturdays, Sundays and public holidays (Art. 3(3)), and the rule that pushes a deadline to the next working day applies only to periods "expressed otherwise than in hours" (Art. 3(4)). The tool therefore shows the deadline as computed and flags it when it lands on a weekend. National NIS2 laws transpose the same 24 h / 72 h / one-month structure; check your national act for any procedural detail.

DORA is the exception. Delegated Regulation (EU) 2025/301, Article 5(4), allows a report whose deadline falls on a weekend day or a bank holiday in your Member State to be submitted by noon on the next working day. Article 5(5) takes that relief away for the initial notification and the intermediate report of credit institutions, central counterparties, trading venue operators and entities that are essential or important under NIS2. The calculator applies the weekend part automatically; bank holidays differ per Member State, so check those yourself.

Time zones: deadlines are shown in the zone you pick and in UTC. If you enter a time that occurs twice when summer time ends (for example 02:30 on 25 October 2026 in Amsterdam), the tool takes the earlier one, which gives the earlier, safer deadline.

One incident, several reports

A ransomware attack on a managed service provider that encrypts customer databases can trigger a GDPR notification to the data protection authority, a NIS2 early warning to the CSIRT, and notices to customers, each with its own recipient, form and clock. Some countries offer a single reporting portal (the Netherlands routes Cyberbeveiligingswet reports through MijnNCSC), but a NIS2 report does not replace the GDPR notification. Start with the shortest clock and reuse the facts for the later reports.

PSD2 incident reporting moved to DORA

Banks, payment institutions, e-money institutions and account information service providers no longer report major payment incidents under PSD2. Since DORA applies (17 January 2025), Article 23 DORA brings operational or security payment-related incidents into the DORA reporting chain, and Directive (EU) 2022/2556 added Article 96(7) to PSD2 so that the old PSD2 reporting no longer applies to them. Tick DORA for those incidents.

What is changing

The Commission's Digital Omnibus proposal (November 2025) would create a single EU entry point for incident reports, raise the GDPR threshold for notifying the authority to "high risk" and extend the deadline to 96 hours. As of 1 October 2026 that proposal is still going through the legislative procedure, so the current rules above apply. The CRA reporting duties in Article 14 have applied since 11 September 2026 through ENISA's Single Reporting Platform.

This calculator helps you plan; it is not legal advice. Sector rules, national laws and your contracts can set shorter deadlines.

Primary sources

Questions

Does the GDPR 72-hour deadline pause over the weekend?

No. Article 33 GDPR sets a period in hours, and under Regulation 1182/71 periods include Saturdays, Sundays and public holidays. The rule that moves a deadline to the next working day applies only to periods expressed otherwise than in hours. A breach discovered on Friday at 16:00 must be notified by Monday at 16:00, or the late notification must explain the delay.

When does the clock start?

When you become aware: once you have a reasonable degree of certainty that a breach or significant incident has occurred, after a short initial assessment. The EDPB Guidelines 9/2022 say this for GDPR, and recital 31 of Implementing Regulation (EU) 2024/2690 says the same for NIS2. A suspicion starts a duty to investigate promptly, not yet the reporting clock.

Do DORA reports get extra time at the weekend?

Partly. Article 5(4) of Delegated Regulation (EU) 2025/301 lets a financial entity submit by noon of the next working day when a deadline falls on a weekend day or bank holiday. Article 5(5) excludes the initial notification and intermediate report of credit institutions, central counterparties, trading venue operators and NIS2 essential or important entities.

Is PSD2 major incident reporting still separate?

No for banks, payment institutions, e-money institutions and account information service providers: since 17 January 2025 their operational or security payment-related incidents are reported under DORA (Article 23 DORA), and Directive (EU) 2022/2556 switched off the PSD2 Article 96 reporting for them.

Is the 72-hour GDPR deadline changing to 96 hours?

Not yet. The Commission's Digital Omnibus proposal of November 2025 would move GDPR breach notification to a single EU entry point, limit it to high-risk breaches and allow 96 hours. As of 1 October 2026 it is still in the legislative procedure, so Article 33 with 72 hours applies.