How the deadlines are calculated
Every clock starts from one timestamp: when your organisation became aware. Hour-based periods are added as real elapsed hours, so a 72-hour period that crosses the end of summer time ends at a different clock time than it started. Month-based periods end on the same calendar date and clock time one month later (31 January plus one month is 28 or 29 February). Where a report counts from an earlier report, the tool assumes you send that earlier report exactly at its deadline, unless you enter when you actually sent it.
| Regime | Report | Deadline | Legal basis |
|---|---|---|---|
| GDPR | Notify the supervisory authority | 72 h after awareness, "where feasible" | Art. 33(1) GDPR |
| GDPR | Inform data subjects (high risk) | Without undue delay | Art. 34 GDPR |
| NIS2 | Early warning | 24 h after awareness | Art. 23(4)(a) NIS2 |
| NIS2 | Incident notification | 72 h after awareness (24 h for trust service providers) | Art. 23(4)(b) and second subparagraph |
| NIS2 | Final report | 1 month after the incident notification | Art. 23(4)(d)-(e) |
| DORA | Initial notification | 4 h after classification as major, at most 24 h after awareness | RTS 2025/301 Art. 5(1)(a), 5(2) |
| DORA | Intermediate report | 72 h after the initial notification | RTS 2025/301 Art. 5(1)(b) |
| DORA | Final report | 1 month after the latest intermediate report | RTS 2025/301 Art. 5(1)(c) |
| CRA | Vulnerability: early warning / notification / final | 24 h / 72 h / 14 days after a fix is available | Art. 14(2) CRA |
| CRA | Severe incident: early warning / notification / final | 24 h / 72 h / 1 month after the notification | Art. 14(4) CRA |
| eIDAS | Notify the supervisory body | 24 h (qualified TSPs: "of the incident"; others: of becoming aware) | Arts. 24(2)(fb), 19a eIDAS |
When does the clock start?
All of these laws count from awareness, not from the moment the attacker got in. The EDPB's Guidelines 9/2022 on personal data breach notification describe awareness as having a reasonable degree of certainty that a security incident has compromised personal data. For NIS2, recital 31 of Implementing Regulation (EU) 2024/2690 uses the same idea: you are aware once an initial assessment gives you reasonable certainty that a significant incident occurred. Two practical consequences:
- A suspicious alert obliges you to assess it promptly. Parking it for a week does not delay the clock; regulators look at when you should have known.
- Write down the awareness moment and who decided it. That timestamp is the first thing an authority asks about when a notification is late.
The one exception in this tool is eIDAS for qualified trust service providers: Article 24(2)(fb) says "within 24 hours of the incident". If the incident started before you noticed, enter its start time.
Weekends, public holidays and time zones
GDPR, NIS2, CRA and eIDAS clocks do not stop. Under Regulation (EEC, Euratom) No 1182/71, periods include Saturdays, Sundays and public holidays (Art. 3(3)), and the rule that pushes a deadline to the next working day applies only to periods "expressed otherwise than in hours" (Art. 3(4)). The tool therefore shows the deadline as computed and flags it when it lands on a weekend. National NIS2 laws transpose the same 24 h / 72 h / one-month structure; check your national act for any procedural detail.
DORA is the exception. Delegated Regulation (EU) 2025/301, Article 5(4), allows a report whose deadline falls on a weekend day or a bank holiday in your Member State to be submitted by noon on the next working day. Article 5(5) takes that relief away for the initial notification and the intermediate report of credit institutions, central counterparties, trading venue operators and entities that are essential or important under NIS2. The calculator applies the weekend part automatically; bank holidays differ per Member State, so check those yourself.
Time zones: deadlines are shown in the zone you pick and in UTC. If you enter a time that occurs twice when summer time ends (for example 02:30 on 25 October 2026 in Amsterdam), the tool takes the earlier one, which gives the earlier, safer deadline.
One incident, several reports
A ransomware attack on a managed service provider that encrypts customer databases can trigger a GDPR notification to the data protection authority, a NIS2 early warning to the CSIRT, and notices to customers, each with its own recipient, form and clock. Some countries offer a single reporting portal (the Netherlands routes Cyberbeveiligingswet reports through MijnNCSC), but a NIS2 report does not replace the GDPR notification. Start with the shortest clock and reuse the facts for the later reports.
PSD2 incident reporting moved to DORA
Banks, payment institutions, e-money institutions and account information service providers no longer report major payment incidents under PSD2. Since DORA applies (17 January 2025), Article 23 DORA brings operational or security payment-related incidents into the DORA reporting chain, and Directive (EU) 2022/2556 added Article 96(7) to PSD2 so that the old PSD2 reporting no longer applies to them. Tick DORA for those incidents.
What is changing
The Commission's Digital Omnibus proposal (November 2025) would create a single EU entry point for incident reports, raise the GDPR threshold for notifying the authority to "high risk" and extend the deadline to 96 hours. As of 1 October 2026 that proposal is still going through the legislative procedure, so the current rules above apply. The CRA reporting duties in Article 14 have applied since 11 September 2026 through ENISA's Single Reporting Platform.
This calculator helps you plan; it is not legal advice. Sector rules, national laws and your contracts can set shorter deadlines.
Primary sources
- Regulation (EU) 2016/679 (GDPR), Arts. 33-34
- Directive (EU) 2022/2555 (NIS2), Art. 23
- Regulation (EU) 2022/2554 (DORA), Arts. 19 and 23; Delegated Regulation (EU) 2025/301, Art. 5
- Regulation (EU) 2024/2847 (Cyber Resilience Act), Arts. 14 and 71
- Regulation (EU) 2024/1183 (eIDAS amendments), Arts. 19a and 24(2)(fb)
- Regulation No 1182/71 on periods, dates and time limits, Art. 3